Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.445exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
13.627 exploits
GitHub PoC2
Relais 2FA <= 1.0 - Authentication Bypass
CVE-2024-10245CRITICAL17 nov 2024
Relais 2FA <= 1.0 - Authentication Bypass
48RISCO
abrir
GitHub PoC1
jesicatjan/WordPress-NotificationX-CVE-2024-1698
CVE-2024-1698CRITICAL16 nov 2024
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RISCO
abrir
GitHub PoC2
WordPress WP Time Capsule Plugin Arbitrary File Upload Vulnerability
CVE-2024-8856CRITICAL16 nov 2024
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RISCO
abrir
GitHub PoC9
CVE-2024-10914 is a critical command injection vulnerability affecting several legacy D-Link Network Attached Storage (NAS) devices.
CVE-2024-10914CRITICAL16 nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir
GitHub PoC3
PoC for Windows' IPv6 CVE-2024-38063
CVE-2024-38063CRITICAL16 nov 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC1
这是一个D-Link rce漏洞 检测程序
CVE-2024-10914CRITICAL15 nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir
GitHub PoC
p33d/Palo-Alto-Expedition-Remote-Code-Execution-Exploit-CVE-2024-5910-CVE-2024-9464
CVE-2024-5910CRITICALsob ataque15 nov 2024
Expedition: Missing Authentication Leads to Admin Account Takeover
100RISCO
abrir
GitHub PoC1
CVE-2024-54761 PoC
CVE-2024-54761MEDIUM15 nov 2024
BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.
33RISCO
abrir
GitHub PoC
这是安徽大学 “漏洞分析实验”(大三秋冬)期中作业归档。完整文档位于https://testgames.me/2024/11/10/cve-2021-44228/
CVE-2021-44228CRITICALsob ataqueransomware15 nov 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC12
Proof of concept for CVE-2024-54756, a vulnerability I found in GZDoom's ZScript scripting engine.
CVE-2024-54756CRITICAL15 nov 2024
A remote code execution (RCE) vulnerability in the ZScript function of ZDoom Team GZDoom v4.13.1 allows attackers to exe
48RISCO
abrir
GitHub PoC1
common-user-management is a robust Spring Boot application featuring user management services designed to control user access dynamically. There is a critical security vulnerability in the application endpoint /api/v1/customer/profile-picture. This endpoint allows file uploads without proper validation or restrictions leads to (RCE)
CVE-2024-52302HIGH14 nov 2024
common-user-management Unrestricted File Upload Leading to Remote Code Execution (RCE)
41RISCO
abrir
GitHub PoC2
Bash script to automate Local File Inclusion (LFI) attacks on aiohttp server version 3.9.1.
CVE-2024-23334MEDIUM14 nov 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISCO
abrir
GitHub PoC4
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 – 9.1.1.1 – Authentication Bypass
CVE-2024-10924CRITICAL14 nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir
GitHub PoC
Fortigate SSL VPN buffer overflow exploit
CVE-2023-27997CRITICALsob ataqueransomware14 nov 2024
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISCO
abrir
GitHub PoC
CiscoRV320Dump CVE-2019-1653 - Automatition.
CVE-2019-1653HIGHsob ataque14 nov 2024
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISCO
abrir
GitHub PoC2
working exploit for the old cve-2021-21425 grav cms 1.7.10 vuln
CVE-2021-21425CRITICAL13 nov 2024
Unauthenticated Arbitrary YAML Write/Update leads to Code Execution
85RISCO
abrir
GitHub PoC
Ivanti Cloud Services Appliance - Path Traversal
CVE-2024-8963CRITICALsob ataque13 nov 2024
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted func
100RISCO
abrir
GitHub PoC
https://nvd.nist.gov/vuln/detail/CVE-2023-4220
CVE-2023-4220HIGH13 nov 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir
GitHub PoC
CVE-2024-10914_Manual testing with burpsuite
CVE-2024-10914CRITICAL13 nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir
GitHub PoC
fork of worawit/CVE-2021-3156 exploit_nss.py modified to work with ifconfig instead of the ip command
CVE-2021-3156HIGHsob ataque13 nov 2024
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC
This script is specifically designed to solve the challenge on PentesterLab for the CVE-2013-0156 exploit
CVE-2013-015613 nov 2024
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RISCO
abrir
GitHub PoC1
Proof-of-concept (PoC) exploit for JSONPath-plus vulnerability
CVE-2024-21534CRITICAL13 nov 2024
All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitizati
48RISCO
abrir
GitHub PoC
CVE: 2015-1328 On python test
CVE-2015-132812 nov 2024
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISCO
abrir
GitHub PoC
harshtech123/cve-2020-24881
CVE-2020-2488112 nov 2024
SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.
60RISCO
abrir
GitHub PoC
Attempt at making the CVE-2024-3400 initial exploit (for educational purposes)
CVE-2024-3400CRITICALsob ataqueransomware12 nov 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISCO
abrir
GitHub PoC1
Python POC for CVE-2024-32640 Mura CMS SQLi
CVE-2024-32640CRITICAL12 nov 2024
MasaCMS SQL Injection vulnerability
85RISCO
abrir
GitHub PoC
CVE-2022-21661 docker and poc
CVE-2022-21661HIGH12 nov 2024
SQL injection in WordPress
78RISCO
abrir
GitHub PoC1
This repository contains an exploit for CVE-2019-16278 in Nostromo Web Server 1.9.6, allowing remote code execution via a directory traversal vulnerability. The script uses pwntools to establish a reverse shell. For educational and authorized testing use only.
CVE-2019-16278CRITICALsob ataque12 nov 2024
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISCO
abrir
GitHub PoC
uthrasri/CVE-2018-14881_no_patch
CVE-2018-14881CRITICAL11 nov 2024
The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_RESTA
48RISCO
abrir
GitHub PoC
In December 2021, the world of cybersecurity was shaken by the discovery of the Log4Shell vulnerability (CVE-2021-44228), embedded within the widely-used Apache Log4j library. With a CVSS score of 10
CVE-2021-44228CRITICALsob ataqueransomware10 nov 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
anteriorpágina 191 / 455próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.