Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.526exploits catalogados
34.478CVEs com exploração pública
24.695testados em laboratório
13.654 exploits
GitHub PoC5
ATTACK PoC - PHP CVE-2024-4577
CVE-2024-4577CRITICALsob ataqueransomware11 jul 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
Burp Extension to test for CVE-2024-34102
CVE-2024-34102CRITICALsob ataque11 jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir
GitHub PoC
ThinkAdmin v5 v6 任意文件读取漏洞利用,可自定义字典爆破
CVE-2020-2554011 jul 2024
ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on
60RISCO
abrir
GitHub PoC8
Perform with massive Wordpress SQLI 2 RCE
CVE-2024-27956CRITICAL11 jul 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISCO
abrir
GitHub PoC1
Rejetto HTTP File Server (HFS) 2.x - Unauthenticated RCE exploit module (CVE-2024-23692)
CVE-2024-23692CRITICALsob ataque10 jul 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISCO
abrir
GitHub PoC3
Guardian Code: A Script to Uncover CVE-2024-5274 Vulnerabilities
CVE-2024-5274HIGHsob ataque10 jul 2024
Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside
76RISCO
abrir
GitHub PoC
year 2 semester 1 Systems and Network Programming Assignment
CVE-2015-386410 jul 2024
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RISCO
abrir
GitHub PoC
DimaMend/cve-2024-6387-poc
CVE-2024-6387HIGH10 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir
GitHub PoC
year 2 semester 1 Systems and Network Programming Assignment
CVE-2019-644710 jul 2024
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISCO
abrir
GitHub PoC102
This Python script checks for the CVE-2024-6387 vulnerability in OpenSSH servers. It supports multiple IP addresses, URLs, CIDR ranges, and ports. The script can also read addresses from a file.
CVE-2024-6387HIGH09 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir
GitHub PoC
This Rust Code is designed to check SSH servers for the CVE-2024-6387 vulnerability
CVE-2024-6387HIGH09 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir
GitHub PoC
regreSSHion is a security tool designed to test for vulnerabilities related to CVE-2024-6387, specifically focusing on SSH and remote access exploitation.
CVE-2024-6387HIGH09 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir
GitHub PoC
dgourillon/mitigate-CVE-2024-6387
CVE-2024-6387HIGH09 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir
GitHub PoC
PoC for CVE-2023-4220 - Chamilo LMS - Unauthenticated File Upload in BigUpload
CVE-2023-4220HIGH09 jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir
GitHub PoC
foudadev/CVE-2007-2447
CVE-2007-244709 jul 2024
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir
GitHub PoC7
alperenugurlu/CVE-2024-3596-Detector
CVE-2024-3596CRITICAL09 jul 2024
RADIUS Protocol under RFC2865 is vulnerable to forgery attacks.
53RISCO
abrir
GitHub PoC
This is a exploit for CVE-2007-2447; Vulnerable SMB
CVE-2007-244708 jul 2024
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir
GitHub PoC11
Exploit for CVE-2024-4883
CVE-2024-4883CRITICAL08 jul 2024
WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution Vulnerability
60RISCO
abrir
GitHub PoC4
PIN-based Authentication Bypass vulnerability in Kaiten
CVE-2024-41276CRITICAL08 jul 2024
A vulnerability in Kaiten version 57.131.12 and earlier allows attackers to bypass the PIN code authentication mechanism
48RISCO
abrir
GitHub PoC
poc for CVE-2024-34102
CVE-2024-34102CRITICALsob ataque08 jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir
GitHub PoC
Chef Inspec profile for checking regreSSHion vulnerability CVE-2024-6387
CVE-2024-6387HIGH08 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir
GitHub PoC186
Remote Unauthenticated Code Execution Vulnerability in OpenSSH server (CVE-2024-6387)
CVE-2024-6387HIGH08 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir
GitHub PoC17
Exploit for CVE-2024-4885
CVE-2024-4885CRITICALsob ataque08 jul 2024
WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC5
This is an Exploit for Unrestricted file upload in big file upload functionality in Chamilo-LMS for this location "/main/inc/lib/javascript/bigupload/inc/bigUpload.php" in Chamilo LMS <= v1.11.24, and Attackers can obtain remote code execution via uploading of web shell.
CVE-2023-4220HIGH08 jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir
GitHub PoC1
Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via uploading of web shell.
CVE-2023-4220HIGH07 jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir
GitHub PoC
sysonlai/CVE-2024-32002-hook
CVE-2024-32002CRITICAL07 jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
GitHub PoC
YISF 2024 CTF-Web (Directory Traversal via ".tar" file, CVE-2007-4559), easy
CVE-2007-4559CRITICAL07 jul 2024
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows
53RISCO
abrir
GitHub PoC5
This is a script written in Python that allows the exploitation of the Chamilo's LMS software security flaw described in CVE-2023-4220
CVE-2023-4220HIGH07 jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir
GitHub PoC1
RCE Chamilo 1.11.24
CVE-2023-4220HIGH07 jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir
GitHub PoC
CosmicSting (CVE-2024-34102) POC / Patch Validator
CVE-2024-34102CRITICALsob ataque07 jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir
anteriorpágina 210 / 456próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.