Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.526exploits catalogados
34.478CVEs com exploração pública
24.695testados em laboratório
13.627 exploits
GitHub PoC5
This Python script helps to detect the Etherleak (CVE-2003-0001) vulnerability on a target host by analyzing the padding data in network packets. The script uses Scapy to send various types of requests (ICMP, ARP, or TCP) and checks if the responses contain any padding data that could potentially leak sensitive memory contents.
CVE-2003-000101 out 2024
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote att
45RISCO
abrir
GitHub PoC1
Wechat Social login <= 1.3.0 - Authentication Bypass
CVE-2024-9106CRITICAL01 out 2024
Wechat Social login <= 1.3.0 - Authentication Bypass
48RISCO
abrir
GitHub PoC10
POC - Jenkins File Read Vulnerability - CVE-2024-23897
CVE-2024-23897CRITICALsob ataqueransomware30 set 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
GitHub PoC12
GiveWP PHP Object Injection exploit
CVE-2024-8353CRITICAL30 set 2024
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection
68RISCO
abrir
GitHub PoC8
is a PoC for CVE-2024-4040 tool for exploiting the SSTI vulnerability in CrushFTP
CVE-2024-4040CRITICALsob ataque30 set 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISCO
abrir
GitHub PoC6
PoC script for CVE-2024-24919 vulnerability. It scans a list of target URLs to identify security issues by sending HTTP POST requests and analyzing server responses
CVE-2024-24919HIGHsob ataqueransomware29 set 2024
Information disclosure
100RISCO
abrir
GitHub PoC10
CVE-2021-3129 (Laravel Ignition RCE Exploit)
CVE-2021-3129CRITICALsob ataqueransomware29 set 2024
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
GitHub PoC8
p33d/CVE-2024-43917
CVE-2024-43917CRITICAL29 set 2024
WordPress TI WooCommerce Wishlist plugin <= 2.8.2 - SQL Injection vulnerability
68RISCO
abrir
GitHub PoC1
ADManager Plus Build < 7210 Elevation of Privilege Vulnerability
CVE-2024-24409HIGH28 set 2024
Privilege Escalation
41RISCO
abrir
GitHub PoC42
p33d/CVE-2024-45519
CVE-2024-45519CRITICALsob ataque28 set 2024
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RISCO
abrir
GitHub PoC1
GeoServer CVE-2024-36401: Remote Code Execution (RCE) Vulnerability In Evaluating Property Name Expressions
CVE-2024-36401CRITICALsob ataque28 set 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir
GitHub PoC
This is a demo for CVE-2024-32002 POC
CVE-2024-32002CRITICAL27 set 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
GitHub PoC1
Proof of Concept for CVE-2024-32002
CVE-2024-32002CRITICAL27 set 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
GitHub PoC
This is a demo for CVE-2024-32002 POC
CVE-2024-32002CRITICAL27 set 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
GitHub PoC1
This project contains a Python script that exploits **CVE-2023-38831**, a vulnerability in **WinRAR** versions prior to 6.23. The exploit generates a **malicious RAR archive** that triggers the execution of arbitrary code when the victim opens a benign-looking file within the archive (such as a PDF).
CVE-2023-38831HIGHsob ataqueransomware27 set 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC
Reproduction of SQL Injection Vulnerabilities in OpenHIS
CVE-2024-46532CRITICAL27 set 2024
SQL Injection vulnerability in OpenHIS v.1.0 allows an attacker to execute arbitrary code via the refund function in the
48RISCO
abrir
GitHub PoC
d
CVE-2023-38831HIGHsob ataqueransomware26 set 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC8
Pgadmin4 Sensitive Information Exposure
CVE-2024-9014CRITICAL26 set 2024
OAuth2 client id and secret exposed through the web browser in pgAdmin 4
63RISCO
abrir
GitHub PoC5
A proof of concept of traefik CVE to understand the impact
CVE-2024-45410CRITICAL26 set 2024
HTTP client can remove the X-Forwarded headers in Traefik
48RISCO
abrir
GitHub PoC3
A vulnerability scanner that searches for the CVE-2024-9166 vulnerability on websites, more info about this vulnerability here: https://www.tenable.com/cve/CVE-2024-9166
CVE-2024-9166CRITICAL26 set 2024
OS Command Injection in Atelmo Atemio AM 520 HD Full HD Satellite Receiver
63RISCO
abrir
GitHub PoC
UMASANKAR-MG/Path-Traversal-CVE-2024-4956
CVE-2024-4956HIGH26 set 2024
Nexus Repository 3 - Path Traversal
61RISCO
abrir
GitHub PoC
p33d/CVE-2024-8275
CVE-2024-8275CRITICAL26 set 2024
The Events Calendar <= 6.6.4 - Unauthenticated SQL Injection
60RISCO
abrir
GitHub PoC5
PrusaSlicer Arbitrary Code Execution using .3mf
CVE-2023-47268MEDIUM26 set 2024
In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrar
33RISCO
abrir
GitHub PoC
CVE-2019-15107 webmin 취약점에 대해서 직접 서버를 구축하고 공격 결과를 남긴 정보입니다.
CVE-2019-15107CRITICALsob ataqueransomware25 set 2024
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
GitHub PoC
CVE-2024-46627 - Incorrect access control in BECN DATAGERRY v2.2 allows attackers to > execute arbitrary commands via crafted web requests.
CVE-2024-46627CRITICAL25 set 2024
Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.
63RISCO
abrir
GitHub PoC7
Proof of Concept Exploit for CVE-2024-28987: SolarWinds Web Help Desk Hardcoded Credential Vulnerability
CVE-2024-28987CRITICALsob ataque24 set 2024
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RISCO
abrir
GitHub PoC146
CVE-2024-38200 & CVE-2024-43609 - Microsoft Office NTLMv2 Disclosure Vulnerability
CVE-2024-38200MEDIUM24 set 2024
Microsoft Office Spoofing Vulnerability
38RISCO
abrir
GitHub PoC9
CVE-2024-7593 Ivanti Virtual Traffic Manager 22.2R1 / 22.7R2 Admin Panel Authentication Bypass PoC [EXPLOIT]
CVE-2024-7593CRITICALsob ataque24 set 2024
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remo
100RISCO
abrir
GitHub PoC3
WBW Product Table Pro <= 1.9.4 - Unauthenticated Arbitrary SQL Execution to RCE
CVE-2024-43918CRITICAL24 set 2024
WordPress WBW Product Table PRO plugin <= 1.9.4 - Unauthenticated Arbitrary SQL Query Execution vulnerability
48RISCO
abrir
GitHub PoC4
Proof-of-Concept for CVE-2024-47066
CVE-2024-47066CRITICAL24 set 2024
Lobe Chat has insufficient fix for GHSA-mxhq-xw3g-rphc (CVE-2024-32964)
53RISCO
abrir
anteriorpágina 197 / 455próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.