Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.526exploits catalogados
34.478CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.534GitHub PoC 13.654VulnCheck XDB 8.213Nuclei 4.218Metasploit 3.464✓ só verificadosrecentespopularesrisco
13.627 exploits
GitHub PoC★ 5
This Python script helps to detect the Etherleak (CVE-2003-0001) vulnerability on a target host by analyzing the padding data in network packets. The script uses Scapy to send various types of requests (ICMP, ARP, or TCP) and checks if the responses contain any padding data that could potentially leak sensitive memory contents.
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote att
45RISCO
abrir ↗GitHub PoC★ 1
Wechat Social login <= 1.3.0 - Authentication Bypass
Wechat Social login <= 1.3.0 - Authentication Bypass
48RISCO
abrir ↗GitHub PoC★ 10
POC - Jenkins File Read Vulnerability - CVE-2024-23897
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗GitHub PoC★ 12
GiveWP PHP Object Injection exploit
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection
68RISCO
abrir ↗GitHub PoC★ 8
is a PoC for CVE-2024-4040 tool for exploiting the SSTI vulnerability in CrushFTP
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISCO
abrir ↗GitHub PoC★ 6
PoC script for CVE-2024-24919 vulnerability. It scans a list of target URLs to identify security issues by sending HTTP POST requests and analyzing server responses
Information disclosure
100RISCO
abrir ↗GitHub PoC★ 10
CVE-2021-3129 (Laravel Ignition RCE Exploit)
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir ↗GitHub PoC★ 8
p33d/CVE-2024-43917
WordPress TI WooCommerce Wishlist plugin <= 2.8.2 - SQL Injection vulnerability
68RISCO
abrir ↗GitHub PoC★ 1
ADManager Plus Build < 7210 Elevation of Privilege Vulnerability
Privilege Escalation
41RISCO
abrir ↗GitHub PoC★ 42
p33d/CVE-2024-45519
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RISCO
abrir ↗GitHub PoC★ 1
GeoServer CVE-2024-36401: Remote Code Execution (RCE) Vulnerability In Evaluating Property Name Expressions
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir ↗GitHub PoC
This is a demo for CVE-2024-32002 POC
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir ↗GitHub PoC★ 1
Proof of Concept for CVE-2024-32002
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir ↗GitHub PoC
This is a demo for CVE-2024-32002 POC
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir ↗GitHub PoC★ 1
This project contains a Python script that exploits **CVE-2023-38831**, a vulnerability in **WinRAR** versions prior to 6.23. The exploit generates a **malicious RAR archive** that triggers the execution of arbitrary code when the victim opens a benign-looking file within the archive (such as a PDF).
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir ↗GitHub PoC
Reproduction of SQL Injection Vulnerabilities in OpenHIS
SQL Injection vulnerability in OpenHIS v.1.0 allows an attacker to execute arbitrary code via the refund function in the
48RISCO
abrir ↗GitHub PoC
d
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir ↗GitHub PoC★ 8
Pgadmin4 Sensitive Information Exposure
OAuth2 client id and secret exposed through the web browser in pgAdmin 4
63RISCO
abrir ↗GitHub PoC★ 5
A proof of concept of traefik CVE to understand the impact
HTTP client can remove the X-Forwarded headers in Traefik
48RISCO
abrir ↗GitHub PoC★ 3
A vulnerability scanner that searches for the CVE-2024-9166 vulnerability on websites, more info about this vulnerability here: https://www.tenable.com/cve/CVE-2024-9166
OS Command Injection in Atelmo Atemio AM 520 HD Full HD Satellite Receiver
63RISCO
abrir ↗GitHub PoC
UMASANKAR-MG/Path-Traversal-CVE-2024-4956
Nexus Repository 3 - Path Traversal
61RISCO
abrir ↗GitHub PoC
p33d/CVE-2024-8275
The Events Calendar <= 6.6.4 - Unauthenticated SQL Injection
60RISCO
abrir ↗GitHub PoC★ 5
PrusaSlicer Arbitrary Code Execution using .3mf
In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrar
33RISCO
abrir ↗GitHub PoC
CVE-2019-15107 webmin 취약점에 대해서 직접 서버를 구축하고 공격 결과를 남긴 정보입니다.
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir ↗GitHub PoC
CVE-2024-46627 - Incorrect access control in BECN DATAGERRY v2.2 allows attackers to > execute arbitrary commands via crafted web requests.
Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.
63RISCO
abrir ↗GitHub PoC★ 7
Proof of Concept Exploit for CVE-2024-28987: SolarWinds Web Help Desk Hardcoded Credential Vulnerability
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RISCO
abrir ↗GitHub PoC★ 146
CVE-2024-38200 & CVE-2024-43609 - Microsoft Office NTLMv2 Disclosure Vulnerability
Microsoft Office Spoofing Vulnerability
38RISCO
abrir ↗GitHub PoC★ 9
CVE-2024-7593 Ivanti Virtual Traffic Manager 22.2R1 / 22.7R2 Admin Panel Authentication Bypass PoC [EXPLOIT]
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remo
100RISCO
abrir ↗GitHub PoC★ 3
WBW Product Table Pro <= 1.9.4 - Unauthenticated Arbitrary SQL Execution to RCE
WordPress WBW Product Table PRO plugin <= 1.9.4 - Unauthenticated Arbitrary SQL Query Execution vulnerability
48RISCO
abrir ↗GitHub PoC★ 4
Proof-of-Concept for CVE-2024-47066
Lobe Chat has insufficient fix for GHSA-mxhq-xw3g-rphc (CVE-2024-32964)
53RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.