Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.526exploits catalogados
34.478CVEs com exploração pública
24.695testados em laboratório
13.654 exploits
GitHub PoC2
dogucyber/WordPress-Exploit-CVE-2024-1071
CVE-2024-1071CRITICAL15 set 2024
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RISCO
abrir
GitHub PoC54
Pre-Auth Exploit for CVE-2024-40711
CVE-2024-40711CRITICALsob ataqueransomware15 set 2024
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code exec
100RISCO
abrir
GitHub PoC5
A Bash script for Kali Linux that exploits an iOS WebKit vulnerability (CVE-2020-27950) using Metasploit and ngrok. Automates payload delivery with a public URL via ngrok, checks for required tools, handles errors, and provides an easy way to crash browsers for educational purposes only.
CVE-2020-27950MEDIUMsob ataque15 set 2024
A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watch
68RISCO
abrir
GitHub PoC1
Unauthenticated remote code execution via Calibre’s content server in Calibre <= 7.14.0.
CVE-2024-6782CRITICAL15 set 2024
Calibre Remote Code Execution
85RISCO
abrir
GitHub PoC48
POC - Unauthenticated RCE Flaw in Rejetto HTTP File Server - CVE-2024-23692
CVE-2024-23692CRITICALsob ataque15 set 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISCO
abrir
GitHub PoC19
Exploit for CVE-2024-29847
CVE-2024-29847CRITICAL14 set 2024
Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows
60RISCO
abrir
GitHub PoC2
chsxthwik/CVE-2024-2876
CVE-2024-2876CRITICAL14 set 2024
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RISCO
abrir
GitHub PoC2
Robocopsita/CVE-2022-0944_RCE_POC
CVE-2022-0944CRITICAL13 set 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISCO
abrir
GitHub PoC
0xWhoami35/CVE-2024-4879
CVE-2024-4879CRITICALsob ataque13 set 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISCO
abrir
GitHub PoC
sshipanoo/CVE-2024-44542
CVE-2024-44542CRITICAL13 set 2024
SQL Injection vulnerability in todesk v.1.1 allows a remote attacker to execute arbitrary code via the /todesk.com/news.
48RISCO
abrir
GitHub PoC
acidburn2049/CVE-2021-3156
CVE-2021-3156HIGHsob ataque13 set 2024
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC3
Proof-of-Concept Exploit for CVE-2024-36401 GeoServer 2.25.1
CVE-2024-36401CRITICALsob ataque13 set 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir
GitHub PoC
🚨 Just completed a detailed investigation for Event ID 193: "SOC231 - Cisco IOS XE Web UI ZeroDay (CVE-2023-20198)" via @LetsDefend.io. The attacker successfully bypassed authentication, gaining admin control over the device! Immediate containment was critical. Stay vigilant! 💻🔐
CVE-2023-20198CRITICALsob ataque13 set 2024
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISCO
abrir
GitHub PoC
pwning netconsd
CVE-2023-28753CRITICAL12 set 2024
netconsd prior to v0.2 was vulnerable to an integer overflow in its parse_packet function. A malicious individual could
48RISCO
abrir
GitHub PoC
Event ID 229 Rule Name SOC262 ScreenConnect Authentication Bypass Exploitation Detected (CVE-2024-1709)
CVE-2024-1709CRITICALsob ataqueransomware12 set 2024
Authentication bypass using an alternate path or channel
100RISCO
abrir
GitHub PoC
🚨 New Incident Report Completed! 🚨 Just wrapped up "Event ID 268: SOC292 - Possible PHP Injection Detected (CVE-2024-4577)" on LetsDefend.io. This analysis involved investigating an attempted Command Injection targeting our PHP server. Staying ahead of these threats with continuous monitoring and swift containment! 🛡️
CVE-2024-4577CRITICALsob ataqueransomware12 set 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
CVE-2024-8277 - 0Day Auto Exploit Authentication Bypass in WooCommerce Photo Reviews Plugin
CVE-2024-8277CRITICAL12 set 2024
WooCommerce Photo Reviews Premium <= 1.3.13.2 - Authentication Bypass to Account Takeover and Privilege Escalation
48RISCO
abrir
GitHub PoC2
phirojshah/CVE-2024-4577
CVE-2024-4577CRITICALsob ataqueransomware12 set 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
Old weaponized CVE-2022-1388 exploit.
CVE-2022-1388CRITICALsob ataqueransomware12 set 2024
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir
GitHub PoC
Event ID 189 Rule Name SOC227 Microsoft SharePoint Server Elevation of Privilege Possible CVE-2023-29357 .. Exploitation
CVE-2023-29357CRITICALsob ataqueransomware12 set 2024
Microsoft SharePoint Server Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC
Log4J exploit CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware11 set 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
OtisSymbos/CVE-2021-44228-Log4Shell-
CVE-2021-44228CRITICALsob ataqueransomware11 set 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
My proof of concept for CVE-2019 Microsoft-Edge
CVE-2019-056711 set 2024
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RISCO
abrir
GitHub PoC
CVE Exploitation Reports: CVE-2007-3280, CVE-2017-0144, CVE-2019-0708
CVE-2019-0708CRITICALsob ataqueransomware11 set 2024
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC
CVE Exploitation Reports: CVE-2007-3280, CVE-2017-0144, CVE-2019-0708
CVE-2017-0144HIGHsob ataqueransomware11 set 2024
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
GitHub PoC2
Spring Cloud Remote Code Execution
CVE-2024-37084CRITICAL11 set 2024
CVE-2024-37084: Remote code execution in Spring Cloud Data Flow
60RISCO
abrir
GitHub PoC1
Powershell script that checks for cert padding in the Windows Registry and adds it if it does not exist. Meant to resolve the WinTrustVerify Vulnerability.
CVE-2013-3900MEDIUMsob ataque11 set 2024
WinVerifyTrust Signature Validation Vulnerability
75RISCO
abrir
GitHub PoC1
Scanning CVE-2024-4577 vulnerability with a url list.
CVE-2024-4577CRITICALsob ataqueransomware10 set 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC1
CVE-2024-38063 - Remotely Exploiting The Kernel Via IPv6
CVE-2024-38063CRITICAL10 set 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC3
JSON API User <= 3.9.3 - Unauthenticated Privilege Escalation
CVE-2024-6624CRITICAL10 set 2024
JSON API User <= 3.9.3 - Unauthenticated Privilege Escalation
48RISCO
abrir
anteriorpágina 200 / 456próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.