Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.338exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.721GitHub PoC 14.491VulnCheck XDB 8.829Nuclei 4.350Metasploit 3.489✓ só verificadosrecentespopularesrisco
78.295 exploits
GitHub PoC
Rust implementation of CVE-2018-16763 with some extra features.
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir ↗GitHub PoC
1nteger-c/CVE-2019-8605
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.1
76RISCO
abrir ↗Metasploit600
Lucee Administrator imgProcess.cfm Arbitrary File Write
Remote Code Exploit in Lucee Admin
78RISCO
abrir ↗VulnCheck XDB
local
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.1
76RISCO
abrir ↗GitHub PoC★ 18
Exploit script for CVE-2020-7961
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISCO
abrir ↗VulnCheck XDB
initial-access
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform an
100RISCO
abrir ↗GitHub PoC
CVE-2020-17519 EXP
Apache Flink directory traversal attack: reading remote files through the REST API
100RISCO
abrir ↗VulnCheck XDB
infoleak
Apache Flink directory traversal attack: reading remote files through the REST API
100RISCO
abrir ↗Exploit-DB
Laravel 8.4.2 debug mode - Remote code execution
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir ↗Exploit-DB
Nagios XI 5.7.X - Remote Code Execution RCE (Authenticated)
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature
60RISCO
abrir ↗GitHub PoC★ 82
PoC for CVE-2020-6207 (Missing Authentication Check in SAP Solution Manager)
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform an
100RISCO
abrir ↗VulnCheck XDB
initial-access
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISCO
abrir ↗GitHub PoC★ 289
Exploit for CVE-2021-3129
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir ↗Metasploit600
Unauthenticated remote code execution in Ignition
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir ↗GitHub PoC
Starry-lord/CVE-2018-0114
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISCO
abrir ↗VulnCheck XDB
initial-access
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISCO
abrir ↗GitHub PoC★ 1
CVE-2017-12615 任意文件写入exp,写入webshell
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISCO
abrir ↗Metasploit600
Microsoft Exchange Server DlpUtils AddTenantDlpPolicy RCE
Microsoft Exchange Server Remote Code Execution Vulnerability
48RISCO
abrir ↗Metasploit600
Microsoft Exchange Server DlpUtils AddTenantDlpPolicy RCE
Microsoft Exchange Remote Code Execution Vulnerability
65RISCO
abrir ↗GitHub PoC
AnasTaoutaou/CVE-2019-5420
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISCO
abrir ↗VulnCheck XDB
initial-access
Apache Flink directory traversal attack: remote file writing through the REST API
50RISCO
abrir ↗VulnCheck XDB
initial-access
Apache Flink directory traversal attack: remote file writing through the REST API
50RISCO
abrir ↗VulnCheck XDB
infoleak
Apache Flink directory traversal attack: reading remote files through the REST API
100RISCO
abrir ↗GitHub PoC★ 8
[CVE-2020-17519] Apache Flink RESTful API Arbitrary File Read
Apache Flink directory traversal attack: reading remote files through the REST API
100RISCO
abrir ↗GitHub PoC★ 5
ElmouradiAmine/CVE-2020-7048
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any
53RISCO
abrir ↗GitHub PoC
CVE-2020-17519
Apache Flink directory traversal attack: reading remote files through the REST API
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Flink 1.11.0 - Unauthenticated Arbitrary File Read (Metasploit)
Apache Flink directory traversal attack: reading remote files through the REST API
100RISCO
abrir ↗VulnCheck XDB
infoleak
Apache Flink directory traversal attack: reading remote files through the REST API
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.