Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.526exploits catalogados
34.478CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.534GitHub PoC 13.654VulnCheck XDB 8.213Nuclei 4.218Metasploit 3.464✓ só verificadosrecentespopularesrisco
13.654 exploits
GitHub PoC
Wytchwulf/CVE-2015-1397-Magento-Shoplift
SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Communit
35RISCO
abrir ↗GitHub PoC★ 4
Vulnerability checking tool via Nmap Scripting Engine
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISCO
abrir ↗GitHub PoC★ 2
Proof Of Concept for CVE-2024-1874
Command injection via array-ish $command parameter of proc_open()
60RISCO
abrir ↗GitHub PoC★ 1
Script para eliminar vulnerabilidad de openssh de ubuntu 22.04 LTS
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISCO
abrir ↗GitHub PoC★ 3
Exploit for CVE-2024-31989.
ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache
48RISCO
abrir ↗GitHub PoC★ 43
geoserver CVE-2024-36401漏洞利用工具
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir ↗GitHub PoC
Automated PHP remote code execution scanner for CVE-2024-4577
Argument Injection in PHP-CGI
100RISCO
abrir ↗GitHub PoC
khanhtranngoccva/cve-2023-38831-poc
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir ↗GitHub PoC
Laravel Debug Mode and Payload
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir ↗GitHub PoC
On October 4, 2021, Apache HTTP Server Project released Security advisory on a Path traversal and File disclosure vulnerability in Apache HTTP Server 2.4.49 and 2.4.50 tracked as CVE-2021-41773 and CVE-2021-42013. In the advisory, Apache also highlighted “the issue is known to be exploited in the wild” and later it was identified that the vulnerabi
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir ↗GitHub PoC★ 1
Exploit for CVE-2024-4879 affecting Vancouver, Washington DC Now and Utah Platform releases
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISCO
abrir ↗GitHub PoC★ 525
Kernel exploit for Xbox SystemOS using CVE-2024-30088
Windows Kernel Elevation of Privilege Vulnerability
83RISCO
abrir ↗GitHub PoC★ 2
OpenSSH RCE Massive Vulnerable Scanner
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir ↗GitHub PoC
LMS Chamilo 1.11.24 CVE-2023-4220 Exploit
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir ↗GitHub PoC
OpenSSH a publié un avis de sécurité concernant la vulnérabilité critique CVE-2024-6387. Cette vulnérabilité permet à un attaquant non authentifié d'exécuter du code arbitraire
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir ↗GitHub PoC★ 1
Phantom-IN/CVE-2024-34102
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir ↗GitHub PoC★ 1
Prueba de concepto para abusar de la vulnerabilidad Shellshock (CVE-2014-6271).
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗GitHub PoC★ 1
Exploit para abusar de la vulnerabilidad Shellshock (CVE-2014-6271).
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗GitHub PoC★ 1
CVE-2024-39250 TimeTrax SQLi
EfroTech Timetrax v8.3 was discovered to contain an unauthenticated SQL injection vulnerability via the q parameter in t
63RISCO
abrir ↗GitHub PoC★ 5
Exploitation CVE-2024-34102
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir ↗GitHub PoC★ 76
CVE-2024-41570: Havoc C2 0.7 Teamserver SSRF exploit
An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send
48RISCO
abrir ↗GitHub PoC
BlackFrog-hub/cve-2015-1328
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISCO
abrir ↗GitHub PoC
jakabakos/CVE-2024-36401-GeoServer-RCE
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir ↗GitHub PoC★ 10
Bulk scanning tool for ServiceNow CVE-2024-4879 vulnerability
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISCO
abrir ↗GitHub PoC★ 26
CVE-2024-4879 - Jelly Template Injection Vulnerability in ServiceNow
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISCO
abrir ↗GitHub PoC★ 4
CVE-2024-4879.py is a Python script designed to detect specific vulnerabilities in ServiceNow instances and dump database connection details if the vulnerability is found. This tool is particularly useful for security researchers and penetration testers.
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISCO
abrir ↗GitHub PoC★ 8
Perform with massive Wordpress SQLI 2 RCE
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISCO
abrir ↗GitHub PoC★ 3
This project demonstrates a Web Application Firewall (WAF) simulation using Flask and a vulnerability checker for CVE-2017-5638. The WAF middleware blocks HTTP requests containing specific patterns, and the vulnerability checker tests for and exploits the Apache Struts 2 vulnerability (CVE-2017-5638).
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir ↗GitHub PoC
Examining the phases of an attack using “Dragonfish's Elise Malware”, specifically, exploring the exploitation of vulnerability CVE-2017-11882.
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.