Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.445exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
13.627 exploits
GitHub PoC
CVE-2019-9053 rewritten in python3 to fix broken syntax. Affects CMS made simple <2.2.10
CVE-2019-905326 out 2024
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
GitHub PoC18
Pyload RCE with js2py sandbox escape
CVE-2024-39205CRITICAL26 out 2024
An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a
68RISCO
abrir
GitHub PoC
tadash10/Detailed-Analysis-and-Mitigation-Strategies-for-CVE-2024-38124-and-CVE-2024-43468
CVE-2024-38124CRITICAL25 out 2024
Windows Netlogon Elevation of Privilege Vulnerability
48RISCO
abrir
GitHub PoC1
CVE-2022-0944 Remote Code Execution Exploit
CVE-2022-0944CRITICAL25 out 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISCO
abrir
GitHub PoC3
Zabbix Frontend Authentication Bypass Vulnerability
CVE-2022-23131CRITICALsob ataque25 out 2024
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISCO
abrir
GitHub PoC13
Cobalt Strike 的 CVE-2024-35250 的 BOF。(请给我加个星,谢谢。)
CVE-2024-35250HIGHsob ataque25 out 2024
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
91RISCO
abrir
GitHub PoC5
Proof of concept for CVE-2024-37383
CVE-2024-37383MEDIUMsob ataque24 out 2024
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
85RISCO
abrir
GitHub PoC
This script performs vulnerability scanning for CVE-2024-21762, a Fortinet SSL VPN remote code execution vulnerability. It checks whether a given server is vulnerable to this CVE by sending specific requests and analyzing the responses.
CVE-2024-21762CRITICALsob ataqueransomware24 out 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISCO
abrir
GitHub PoC3
CVE-2022-41082-poc
CVE-2022-41082HIGHsob ataqueransomware24 out 2024
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
rahisec/CVE-2024-4040
CVE-2024-4040CRITICALsob ataque23 out 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISCO
abrir
GitHub PoC1
bueno-armando/CVE-2023-4220-RCE
CVE-2023-4220HIGH23 out 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir
GitHub PoC51
PfSense Stored XSS lead to Arbitrary Code Execution exploit
CVE-2024-46538CRITICAL23 out 2024
A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML v
70RISCO
abrir
GitHub PoC2
CVE-2024-6387, also known as RegreSSHion, is a high-severity vulnerability found in OpenSSH servers (sshd) running on glibc-based Linux systems. It is a regression of a previously fixed vulnerability (CVE-2006-5051), which means the issue was reintroduced in newer versions of OpenSSH.
CVE-2024-6387HIGH22 out 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir
GitHub PoC1
grecosamuel/CVE-2024-32002
CVE-2024-32002CRITICAL22 out 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
GitHub PoC5
Arbitrary File Read and DoS in vendure-ecommerce exploit
CVE-2024-48914CRITICAL21 out 2024
Vendure asset server plugin has local file read vulnerability with AssetServerPlugin & LocalAssetStorageStrategy
75RISCO
abrir
GitHub PoC11
p33d/CVE-2024-23113
CVE-2024-23113CRITICALsob ataque21 out 2024
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RISCO
abrir
GitHub PoC
punitdarji/Grafana-CVE-2024-9264
CVE-2024-9264CRITICAL21 out 2024
Grafana SQL Expressions allow for remote code execution
85RISCO
abrir
GitHub PoC39
Grafana RCE exploit (CVE-2024-9264)
CVE-2024-9264CRITICAL21 out 2024
Grafana SQL Expressions allow for remote code execution
85RISCO
abrir
GitHub PoC7
File Read Proof of Concept for CVE-2024-9264
CVE-2024-9264CRITICAL20 out 2024
Grafana SQL Expressions allow for remote code execution
85RISCO
abrir
GitHub PoC5
Proof-of-Concept for LFI/Path Traversal vulnerability in Aiohttp =< 3.9.1
CVE-2024-23334MEDIUM20 out 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISCO
abrir
GitHub PoC1
Affected versions of this package are vulnerable to Race Condition. The whitespace normalisation using in 1.x and 2.x removes any unicode whitespace. Under certain specific conditions this could potentially allow a malicious user to execute code remotely.
CVE-2021-32708CRITICAL19 out 2024
Time-of-check Time-of-use (TOCTOU) Race Condition in league/flysystem
48RISCO
abrir
GitHub PoC132
Exploit for Grafana arbitrary file-read and RCE (CVE-2024-9264)
CVE-2024-9264CRITICAL19 out 2024
Grafana SQL Expressions allow for remote code execution
85RISCO
abrir
GitHub PoC2
Security Bulletin for CVE-2024-35133 - With PoC
CVE-2024-35133MEDIUM18 out 2024
IBM Security Verify Access HTTP open redirect
33RISCO
abrir
GitHub PoC11
Pre-Authentication Heap Overflow in Xlight SFTP server <= 3.9.4.2
CVE-2024-46483CRITICAL18 out 2024
Xlight FTP Server <3.9.4.3 has an integer overflow vulnerability in the packet parsing logic of the SFTP server, which c
48RISCO
abrir
GitHub PoC
Vulnerability Overview CVE-2023-38408 affects OpenSSH versions < 9.3p2 and stems from improper validation of data when SSH agent forwarding is enabled. When users connect to a remote server with ssh -A, they allow the agent on their local machine to be used for authentication to further systems
CVE-2023-38408CRITICAL17 out 2024
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISCO
abrir
GitHub PoC2
GutenKit <= 2.1.0 - Unauthenticated Arbitrary File Upload
CVE-2024-9234CRITICAL17 out 2024
GutenKit <= 2.1.0 - Unauthenticated Arbitrary File Upload
68RISCO
abrir
GitHub PoC11
tdonaworth/Firefox-CVE-2024-9680
CVE-2024-9680CRITICALsob ataqueransomware17 out 2024
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timeli
83RISCO
abrir
GitHub PoC
Exploit and check CVE-2013-5211
CVE-2013-521116 out 2024
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RISCO
abrir
GitHub PoC
check and exploit for NTP vuln CVE-2013-5211
CVE-2013-521116 out 2024
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RISCO
abrir
GitHub PoC43
CVE-2024-40711-exp
CVE-2024-40711CRITICALsob ataqueransomware16 out 2024
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code exec
100RISCO
abrir
anteriorpágina 194 / 455próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.