Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.445exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.497GitHub PoC 13.627VulnCheck XDB 8.198Nuclei 4.217Metasploit 3.463✓ só verificadosrecentespopularesrisco
13.627 exploits
GitHub PoC
Zita Site Builder <= 1.0.2 - Missing Authorization to Arbitrary Plugin Installation
WordPress Zita Site Builder plugin <= 1.0.2 - Arbitrary Plugin Installation and Activation vulnerability
48RISCO
abrir ↗GitHub PoC★ 4
v3153/CVE-2024-50379-POC
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RISCO
abrir ↗GitHub PoC★ 1
Adobe ColdFusion 8 - Remote Command Execution (RCE)
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RISCO
abrir ↗GitHub PoC★ 2
dustblessnotdust/CVE-2024-53677-S2-067-thread
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir ↗GitHub PoC★ 3
A Docker-based environment to reproduce the CVE-2024-53677 vulnerability in Apache Struts 2.
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir ↗GitHub PoC★ 3
yangyanglo/CVE-2024-53677
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir ↗GitHub PoC★ 6
Proof of concept (POC) for CVE-2024-45337
Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
48RISCO
abrir ↗GitHub PoC★ 1
An example project that showcases golang code vulnerable to CVE-2024-45337
Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
48RISCO
abrir ↗GitHub PoC
DS.DownloadList <= 1.3 - Unauthenticated PHP Object Injection
WordPress DS.DownloadList plugin <= 1.3 - PHP Object Injection vulnerability
48RISCO
abrir ↗GitHub PoC
redspy-sec/CVE-2021-41773
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗GitHub PoC★ 14
A short scraper looking for a POC of CVE-2024-49112
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC★ 21
LLfam/CVE-2024-1086
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISCO
abrir ↗GitHub PoC
t0mmy4/CVE-2019-12725-modified-exp
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISCO
abrir ↗GitHub PoC★ 1
The EXP/POC of CVE-2019-12725
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISCO
abrir ↗GitHub PoC
Rahul-Thakur7/CVE-2023-21554
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
85RISCO
abrir ↗GitHub PoC★ 4
Automated Exploit Tool for Grafana CVE-2021-43798: Scanning common files that contain juicy informations and extracting SSH keys from compromised users.
Grafana path traversal
100RISCO
abrir ↗GitHub PoC
Super Backup & Clone - Migrate for WordPress <= 2.3.3 - Unauthenticated Arbitrary File Upload
Super Backup & Clone - Migrate for WordPress <= 2.3.3 - Unauthenticated Arbitrary File Upload
48RISCO
abrir ↗GitHub PoC★ 8
CVE-2024-55875 | GHSA-7mj5-hjjj-8rgw | http4k first CVE
http4k has a potential XXE (XML External Entity Injection) vulnerability
48RISCO
abrir ↗GitHub PoC
CVE to CTF FP
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir ↗GitHub PoC★ 4
666asd/CVE-2024-23653
BuildKit interactive containers API does not validate entitlements check
48RISCO
abrir ↗GitHub PoC
tlavi00/CVE-2018-7750
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x
28RISCO
abrir ↗GitHub PoC
Improved version of PikaChu CVE
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISCO
abrir ↗GitHub PoC★ 96
A critical vulnerability, CVE-2024-53677, has been identified in the popular Apache Struts framework, potentially allowing attackers to execute arbitrary code remotely. This vulnerability arises from flaws in the file upload logic, which can be exploited to perform path traversal and malicious file uploads.
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir ↗GitHub PoC
Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
60RISCO
abrir ↗GitHub PoC★ 9
s2-067(CVE-2024-53677)
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir ↗GitHub PoC★ 13
CVE-2023-40028 affects Ghost, an open source content management system, where versions prior to 5.59.1 allow authenticated users to upload files that are symlinks. This can be exploited to perform an arbitrary file read of any file on the host operating system.
Arbitrary file read via symlinks in Ghost
45RISCO
abrir ↗GitHub PoC★ 4
exploit CVE-2024-38475(mod_rewrite weakness with filesystem path matching)
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.