Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.445exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.497GitHub PoC 13.627VulnCheck XDB 8.198Nuclei 4.217Metasploit 3.463✓ só verificadosrecentespopularesrisco
13.627 exploits
GitHub PoC★ 3
Wux Blog Editor <= 3.0.0 - Unauthenticated Arbitrary File Upload
Wux Blog Editor <= 3.0.0 - Unauthenticated Arbitrary File Upload
60RISCO
abrir ↗GitHub PoC
WatchTowerHQ <= 3.10.1 - Authentication Bypass to Administrator due to Missing Empty Value Check
WatchTowerHQ <= 3.10.1 - Authentication Bypass to Administrator due to Missing Empty Value Check
48RISCO
abrir ↗GitHub PoC
Woocommerce Product Design <= 1.0.0 - Unauthenticated Arbitrary File Upload
WordPress Woocommerce Product Design plugin <= 1.0.0 - Arbitrary File Upload vulnerability
48RISCO
abrir ↗GitHub PoC
Signup Page <= 1.0 - Unauthenticated Arbitrary Options Update
WordPress Signup Page plugin <= 1.0 - Arbitrary Option Update to Privilege Escalation vulnerability
48RISCO
abrir ↗GitHub PoC
GRÜN spendino Spendenformular <= 1.0.1 - Unauthenticated Arbitrary Options Update
WordPress GRÜN spendino Spendenformular plugin <= 1.0.1 - Arbitrary Option Update to Privilege Escalation vulnerability
48RISCO
abrir ↗GitHub PoC★ 3
WP Query Console <= 1.0 - Unauthenticated Remote Code Execution
WordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability
75RISCO
abrir ↗GitHub PoC
Roundcube mail server exploit for CVE-2024-37383 (Stored XSS)
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
85RISCO
abrir ↗GitHub PoC★ 1
JAckLosingHeart/CVE-2024-51132-POC
An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information o
48RISCO
abrir ↗GitHub PoC
POC firewall with rules designed to detect and block Spring4Shell vulnerability (CVE-2022-22965) exploit
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir ↗GitHub PoC
CVE-2023-4220 Chamilo Exploit
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir ↗GitHub PoC★ 2
wp/ultimate-member - SQL Injection Vulnerability Exploit Script.
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RISCO
abrir ↗GitHub PoC★ 5
CVE-2024-51567 is a Python PoC exploit targeting an RCE vulnerability in CyberPanel v2.3.6’s upgrademysqlstatus endpoint, bypassing CSRF protections.
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas
100RISCO
abrir ↗GitHub PoC
GodOfServer/CVE-2021-3129
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir ↗GitHub PoC★ 1
puckiestyle/CVE-2024-23113
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RISCO
abrir ↗GitHub PoC
hualy13/CVE-2019-0708-Check
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir ↗GitHub PoC★ 1
CVE-2024-48359 PoC
Qualitor v8.24 was discovered to contain a remote code execution (RCE) vulnerability via the gridValoresPopHidden parame
48RISCO
abrir ↗GitHub PoC
Writing one because the one I found isn't working
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISCO
abrir ↗GitHub PoC★ 2
cve-2024-38821
Authorization Bypass of Static Resources in WebFlux Applications
48RISCO
abrir ↗GitHub PoC★ 1
chsxthwik/CVE-2024-27954
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability
85RISCO
abrir ↗GitHub PoC★ 4
Automatic Plugin for WordPress < 3.92.1 Multiples Vulnerabilities
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability
85RISCO
abrir ↗GitHub PoC★ 23
Exploit for CyberPanel Pre-Auth RCE via Command Injection
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
100RISCO
abrir ↗GitHub PoC
It's Proof of Concept on CVE-2024-24919-POC , i made it after it's discoverd
Information disclosure
100RISCO
abrir ↗GitHub PoC★ 2
Stack-Overflow on TendaAC8
Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the timeZone parameter in the sub_44db3c funct
48RISCO
abrir ↗GitHub PoC★ 1
0xDTC/Prestashop-CVE-2024-34716
PrestaShop vulnerable to XSS via customer contact form in FO, through file upload
60RISCO
abrir ↗GitHub PoC
Refurbish
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISCO
abrir ↗GitHub PoC
Refurbish Chamilo LMS CVE-2023-4220 exploit written in bash
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir ↗GitHub PoC
CVE-2023-41425 Refurbish
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.