Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.526exploits catalogados
34.478CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.534GitHub PoC 13.654VulnCheck XDB 8.213Nuclei 4.218Metasploit 3.464✓ só verificadosrecentespopularesrisco
13.648 exploits
GitHub PoC
btar1gan/exploit_CVE-2022-35914
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISCO
abrir ↗GitHub PoC★ 1
teamcity-exploit-cve-2023-42793
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir ↗GitHub PoC
MAHajian/CVE-2019-9978
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir ↗GitHub PoC★ 2
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'
75RISCO
abrir ↗GitHub PoC★ 1
Modification of: PoC of CVE-2019-14322: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.
50RISCO
abrir ↗GitHub PoC
CVE-2023-47253 | Qualitor <= 8.20 RCE
Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/reques
68RISCO
abrir ↗GitHub PoC
poc of cve-2024-8752(WebIQ 2.15.9)
WebIQ 2.15.9 Runtime on Windows - Directory Traversal Vulnerability
68RISCO
abrir ↗GitHub PoC
Webrun <= 3.6.0.42 SQLi
WebRun 3.6.0.42 is vulnerable to SQL Injection via the P_0 parameter used to set the username during the login process.
23RISCO
abrir ↗GitHub PoC
CVE-2023-47253 | Qualitor <= 8.20 RCE
Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/reques
68RISCO
abrir ↗GitHub PoC★ 6
POC_CVE-2024-46256
A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add
48RISCO
abrir ↗GitHub PoC
safeer-accuknox/CrushFTP-cve-2024-4040-poc
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISCO
abrir ↗GitHub PoC★ 4
CVE-2022-23131 Zabbix Server SAML authentication exploit
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISCO
abrir ↗GitHub PoC★ 3
Client Implementation for the WatchGuard SSO Agent Protocol used for Security Research (CVE-2024-6592, CVE-2024-6593, CVE-2024-6594)
WatchGuard Firebox Single Sign-On Agent Protocol Authorization Bypass
48RISCO
abrir ↗GitHub PoC★ 2
The BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript plugin for WordPress is vulnerable to arbitrary file uploads
WordPress BerqWP plugin <= 1.7.6 - Unauthenticated Arbitrary File Upload vulnerability
63RISCO
abrir ↗GitHub PoC★ 2
0xAgun/CVE-2024-2876
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RISCO
abrir ↗GitHub PoC★ 3
CVE-2024-44000-LiteSpeed-Cache
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RISCO
abrir ↗GitHub PoC★ 49
This repository contains PoC for CVE-2024-7965. This is the vulnerability in the V8 that occurs only within ARM64.
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially expl
76RISCO
abrir ↗GitHub PoC★ 1
PoC code for vulnerability in webmod v0.48. Originally written in 2007, assigned CVE-2007-1260.
Stack-based buffer overflow in the connectHandle function in server.cpp in WebMod 0.48 allows remote attackers to execut
23RISCO
abrir ↗GitHub PoC★ 4
Server-Side Template Injection Exploit
Server Side Template Injection in Jinja2 allows Remote Command Execution
85RISCO
abrir ↗GitHub PoC★ 16
CVE-2024-8190: Ivanti Cloud Service Appliance Command Injection
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remo
93RISCO
abrir ↗GitHub PoC★ 4
Proof Of Concept for CVE-2023-21716 Microsoft Word Heap Corruption
Microsoft Word Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC
Exploit a 2021 Kernel vulnerability in Ubuntu to become root almost instantly!
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISCO
abrir ↗GitHub PoC★ 48
POC - Unauthenticated RCE Flaw in Rejetto HTTP File Server - CVE-2024-23692
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISCO
abrir ↗GitHub PoC★ 5
A Bash script for Kali Linux that exploits an iOS WebKit vulnerability (CVE-2020-27950) using Metasploit and ngrok. Automates payload delivery with a public URL via ngrok, checks for required tools, handles errors, and provides an easy way to crash browsers for educational purposes only.
A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watch
68RISCO
abrir ↗GitHub PoC★ 2
dogucyber/WordPress-Exploit-CVE-2024-1071
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RISCO
abrir ↗GitHub PoC
New exploit for pyLoad v0.5.0 - Unauthenticated remote code excecution
Code Injection in pyload/pyload
85RISCO
abrir ↗GitHub PoC★ 1
Unauthenticated remote code execution via Calibre’s content server in Calibre <= 7.14.0.
Calibre Remote Code Execution
85RISCO
abrir ↗GitHub PoC★ 54
Pre-Auth Exploit for CVE-2024-40711
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code exec
100RISCO
abrir ↗GitHub PoC★ 2
chsxthwik/CVE-2024-2876
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.