Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.445exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
13.627 exploits
GitHub PoC
Automatic Translation <= 1.0.4 - Unauthenticated Arbitrary File Upload
CVE-2024-50493CRITICAL10 nov 2024
WordPress Automatic Translation plugin <= 1.0.4 - Arbitrary File Upload vulnerability
48RISCO
abrir
GitHub PoC1
oxapavan/CVE-2023-4220-HTB-PermX
CVE-2023-4220HIGH10 nov 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir
GitHub PoC
To test elasticsearch vulnerabillity on newer version of debian
CVE-2015-1427CRITICALsob ataque10 nov 2024
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RISCO
abrir
GitHub PoC48
POC - CVE-2024–10914- Command Injection Vulnerability in `name` parameter for D-Link NAS
CVE-2024-10914CRITICAL10 nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir
GitHub PoC
In December 2021, the world of cybersecurity was shaken by the discovery of the Log4Shell vulnerability (CVE-2021-44228), embedded within the widely-used Apache Log4j library. With a CVSS score of 10
CVE-2021-44228CRITICALsob ataqueransomware10 nov 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
Debug Tool <= 2.2 - Unauthenticated Arbitrary File Creation
CVE-2024-10586CRITICAL10 nov 2024
Debug Tool <= 2.2 - Unauthenticated Arbitrary File Creation
48RISCO
abrir
GitHub PoC14
Exploit for cve-2024-10914: D-Link DNS-320, DNS-320LW, DNS-325, DNS-340L Version 1.00, Version 1.01.0914.2012, Version 1.01, Version 1.02, Version 1.08 Command Injection
CVE-2024-10914CRITICAL09 nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir
GitHub PoC
Ajar in5 Embed <= 3.1.3 - Unauthenticated Arbitrary File Upload
CVE-2024-50473CRITICAL09 nov 2024
WordPress Ajar in5 Embed plugin <= 3.1.3 - Arbitrary File Upload vulnerability
48RISCO
abrir
GitHub PoC
WP Dropbox Dropins <= 1.0 - Unauthenticated Arbitrary File Upload
CVE-2024-49607CRITICAL09 nov 2024
WordPress WP Dropbox Dropins plugin <= 1.0 - Arbitrary File Upload vulnerability
48RISCO
abrir
GitHub PoC
sea-middle/cve-2023-25813
CVE-2023-25813CRITICAL09 nov 2024
SQL Injection via replacements in sequelize
48RISCO
abrir
GitHub PoC3
WP Sessions Time Monitoring Full Automatic <= 1.0.9 - Unauthenticated SQL Injection
CVE-2024-49681CRITICAL09 nov 2024
WordPress WP Sessions Time Monitoring Full Automatic plugin <= 1.0.9 - SQL Injection vulnerability
48RISCO
abrir
GitHub PoC1
Proof of concept of the parh traversal in python AioHTTP library =< 3.9.1
CVE-2024-23334MEDIUM09 nov 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISCO
abrir
GitHub PoC
SurveyJS: Drag & Drop WordPress Form Builder <= 1.9.136 - Authenticated (Subscriber+) Arbitrary File Upload
CVE-2024-50427CRITICAL08 nov 2024
WordPress SurveyJS plugin <= 1.9.136 - Arbitrary File Upload vulnerability
48RISCO
abrir
GitHub PoC
CVE-2024-4898 InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.38 - Missing Authorization to Unauthenticated API setup/Arbitrary Options Update/Administrative User Creation
CVE-2024-4898CRITICAL08 nov 2024
InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.38 - Missing Authorization to Unauthenticated API setup/Arbitrary Options Update/Administrative User Creation
63RISCO
abrir
GitHub PoC
WPLMS Learning Management System for WordPress <= 4.962 – Unauthenticated Arbitrary File Read and Deletion
CVE-2024-10470CRITICAL08 nov 2024
WPLMS Learning Management System for WordPress <= 4.962 - Unauthenticated Arbitrary File Read and Deletion
60RISCO
abrir
GitHub PoC
Stacks Mobile App Builder <= 5.2.3 - Authentication Bypass via Account Takeover
CVE-2024-50477CRITICAL08 nov 2024
WordPress Stacks Mobile App Builder plugin <= 5.2.3 - Account Takeover vulnerability
63RISCO
abrir
GitHub PoC
CVE-2023-25813 Vulnerability Reproduction - SQL Injection in Sequelize
CVE-2023-25813CRITICAL07 nov 2024
SQL Injection via replacements in sequelize
48RISCO
abrir
GitHub PoC1
cbyerpanel rce exploit
CVE-2024-51567CRITICALsob ataqueransomware07 nov 2024
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas
100RISCO
abrir
GitHub PoC1
0xR00/CVE-2024-23334
CVE-2024-23334MEDIUM07 nov 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISCO
abrir
GitHub PoC
Exploit Development for CVE-2023-6553 on Backup Plugin in Wordpress
CVE-2023-6553CRITICAL07 nov 2024
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RISCO
abrir
GitHub PoC1
AliHj98/cve-2024-38063-Anonyvader
CVE-2024-38063CRITICAL07 nov 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC98
Fortinet Fortimanager Unauthenticated Remote Code Execution AKA FortiJump CVE-2024-47575
CVE-2024-47575CRITICALsob ataque07 nov 2024
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2
100RISCO
abrir
GitHub PoC6
WP REST API FNS <= 1.0.0 - Privilege Escalation
CVE-2024-49328CRITICAL06 nov 2024
WordPress WP REST API FNS Plugin plugin <= 1.0.0 - Account Takeover vulnerability
48RISCO
abrir
GitHub PoC
pbj2647/CVE-2023-25813
CVE-2023-25813CRITICAL06 nov 2024
SQL Injection via replacements in sequelize
48RISCO
abrir
GitHub PoC25
CVE-2024-4577 RCE PoC
CVE-2024-4577CRITICALsob ataqueransomware06 nov 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
pedrochalegre7/CVE-2024-4367-pdf-sample
CVE-2024-4367MEDIUM06 nov 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir
GitHub PoC
WatchTowerHQ <= 3.10.1 - Authentication Bypass to Administrator due to Missing Empty Value Check
CVE-2024-9933CRITICAL05 nov 2024
WatchTowerHQ <= 3.10.1 - Authentication Bypass to Administrator due to Missing Empty Value Check
48RISCO
abrir
GitHub PoC3
Wux Blog Editor <= 3.0.0 - Unauthenticated Arbitrary File Upload
CVE-2024-9932CRITICAL05 nov 2024
Wux Blog Editor <= 3.0.0 - Unauthenticated Arbitrary File Upload
60RISCO
abrir
GitHub PoC4
This repository contains a Crystallographic Information File (CIF) intended for use on the "Chemistry" machine on Hack The Box (HTB).
CVE-2024-23346CRITICAL05 nov 2024
pymatgen arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
48RISCO
abrir
GitHub PoC
Woocommerce Product Design <= 1.0.0 - Unauthenticated Arbitrary File Upload
CVE-2024-50482CRITICAL05 nov 2024
WordPress Woocommerce Product Design plugin <= 1.0.0 - Arbitrary File Upload vulnerability
48RISCO
abrir
anteriorpágina 192 / 455próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.