Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.526exploits catalogados
34.478CVEs com exploração pública
24.695testados em laboratório
13.654 exploits
GitHub PoC1
(CVE-2023-4220) Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
CVE-2023-4220HIGH03 set 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir
GitHub PoC1
brownpanda29/Cve-2024-38063
CVE-2024-38063CRITICAL03 set 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC1
Raffli-Dev/CVE-2023-41425
CVE-2023-41425MEDIUM03 set 2024
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISCO
abrir
GitHub PoC1
Adobe ColdFusion CVE-2023-26360/CVE-2023-29298 自动化实现反弹
CVE-2023-26360HIGHsob ataque03 set 2024
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RISCO
abrir
GitHub PoC3
Authenticated Code execution
CVE-2023-26785CRITICAL03 set 2024
MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File
48RISCO
abrir
GitHub PoC
ImageMagick 7.1.0-49 vulnerable to Information Disclosure
CVE-2022-44268MEDIUM02 set 2024
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISCO
abrir
GitHub PoC8
This module exploits a vulnerability in the target service identified as CVE-2023-42115.
CVE-2023-42115CRITICAL02 set 2024
Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability
48RISCO
abrir
GitHub PoC
ps-interactive/cve-2024-38063
CVE-2024-38063CRITICAL02 set 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC
Yowise/CVE-2022-26923
CVE-2022-26923HIGHsob ataque01 set 2024
Active Directory Domain Services Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC9
This is a C language program designed to test the Windows TCP/IP Remote Code Execution Vulnerability (CVE-2024-38063). It sends specially crafted IPv6 packets with embedded shellcode to exploit the vulnerability.
CVE-2024-38063CRITICAL01 set 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC9
Unauthenticated Remote Code Execution in SPIP versions up to and including 4.2.12
CVE-2024-7954CRITICAL01 set 2024
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISCO
abrir
GitHub PoC30
poc code for CVE-2024-38080
CVE-2024-38080HIGHsob ataque01 set 2024
Windows Hyper-V Elevation of Privilege Vulnerability
71RISCO
abrir
GitHub PoC
🔍 Just wrapped up an incident report on a Phishing Alert (Event ID 257, SOC282). Enhancing my expertise in email threat detection and response! 🚨 #Cybersecurity #SOCAnalyst #LetsDefend
CVE-2024-24919HIGHsob ataqueransomware31 ago 2024
Information disclosure
100RISCO
abrir
GitHub PoC
Proof of Concept Exploit for CVE-2024-44812 - SQL Injection Authentication Bypass vulnerability in Online Complaint Site v1.0
CVE-2024-44812CRITICAL31 ago 2024
SQL Injection vulnerability in Online Complaint Site v.1.0 allows a remote attacker to escalate privileges via the usern
48RISCO
abrir
GitHub PoC43
CVE-2024-38063 is a critical security vulnerability in the Windows TCP/IP stack that allows for remote code execution (RCE)
CVE-2024-38063CRITICAL31 ago 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC11
POC for CVE-2023-29360
CVE-2023-29360HIGHsob ataque31 ago 2024
Microsoft Streaming Service Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC25
CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC
CVE-2024-21413CRITICALsob ataque31 ago 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC140
exploits for CVE-2024-20017
CVE-2024-20017CRITICAL30 ago 2024
In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote cod
60RISCO
abrir
GitHub PoC23
Proof of concept : CVE-2024-1071: WordPress Vulnerability Exploited
CVE-2024-1071CRITICAL30 ago 2024
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RISCO
abrir
GitHub PoC
A POC demo on CVE-2023-38831
CVE-2023-38831HIGHsob ataqueransomware30 ago 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC35
sinsinology/CVE-2024-6670
CVE-2024-6670CRITICALsob ataqueransomware30 ago 2024
WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability
100RISCO
abrir
GitHub PoC
LuisMateo1/Arbitrary-File-Read-CVE-2024-24919
CVE-2024-24919HIGHsob ataqueransomware29 ago 2024
Information disclosure
100RISCO
abrir
GitHub PoC3
CVE-2019-15107 Webmin unauthenticated RCE
CVE-2019-15107CRITICALsob ataqueransomware29 ago 2024
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
GitHub PoC7
Fully automated PoC - CVE-2024-25641 - RCE - Cacti < v1.2.26 🌵
CVE-2024-25641CRITICAL29 ago 2024
Cacti RCE vulnerability when importing packages
85RISCO
abrir
GitHub PoC1
In an era where digital security is crucial, a new vulnerability in OpenSSH, identified as CVE-2024-6387, has drawn the attention of system administrators and security professionals worldwide. Named "regreSSHion," this severe security flaw allows remote code execution (RCE) and could significant threat to the integrity of vulnerable systems.
CVE-2024-6387HIGH29 ago 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir
GitHub PoC83
mistymntncop/CVE-2024-5274
CVE-2024-5274HIGHsob ataque29 ago 2024
Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside
76RISCO
abrir
GitHub PoC294
tomcat自动化漏洞扫描利用工具,支持批量弱口令检测、后台部署war包getshell、CVE-2017-12615 文件上传、CVE-2020-1938/CNVD-2020-10487 文件包含
CVE-2017-12615HIGHsob ataqueransomware29 ago 2024
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISCO
abrir
GitHub PoC294
tomcat自动化漏洞扫描利用工具,支持批量弱口令检测、后台部署war包getshell、CVE-2017-12615 文件上传、CVE-2020-1938/CNVD-2020-10487 文件包含
CVE-2020-1938CRITICALsob ataque29 ago 2024
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
GitHub PoC2
D0rDa4aN919/CVE-2023-22809-Exploiter
CVE-2023-22809HIGH28 ago 2024
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISCO
abrir
GitHub PoC3
Apache OFBiz CVE-2024-38856
CVE-2024-38856HIGHsob ataque28 ago 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISCO
abrir
anteriorpágina 202 / 456próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.