Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.589exploits catalogados
34.508CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.554GitHub PoC 13.689VulnCheck XDB 8.216Nuclei 4.223Metasploit 3.464✓ só verificadosrecentespopularesrisco
13.689 exploits
GitHub PoC★ 5
A PoC exploit for CVE-2024-3273 - D-Link Remote Code Execution RCE
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISCO
abrir ↗GitHub PoC
CVE-2020-12641: Command Injection via “_im_convert_path” Parameter in Roundcube Webmail
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in
100RISCO
abrir ↗GitHub PoC★ 23
CVE-2024-2879 - LayerSlider 7.9.11 - 7.10.0 - Unauthenticated SQL Injection
The LayerSlider plugin for WordPress is vulnerable to SQL Injection via the ls_get_popup_markup action in versions 7.9.1
68RISCO
abrir ↗GitHub PoC★ 3
CVE-2021-42013 Vulnerability Scanner This Python script checks for the Remote Code Execution (RCE) vulnerability (CVE-2021-42013) in Apache 2.4.50.
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir ↗GitHub PoC
Quick and dirty honeypot for CVE-2024-3273
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISCO
abrir ↗GitHub PoC★ 101
D-Link NAS CVE-2024-3273 Exploit Tool
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISCO
abrir ↗GitHub PoC★ 13
Exploit for CVE-2024-3273, supports single and multiple hosts
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISCO
abrir ↗GitHub PoC
Scan for files containing the signature from the `xz` backdoor (CVE-2024-3094)
Xz: malicious code in distributed source
70RISCO
abrir ↗GitHub PoC
RomainBayle08/CVE-2023-38831
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir ↗GitHub PoC★ 6
An Ansible Role that installs the xz backdoor (CVE-2024-3094) on a Debian host and optionally installs the xzbot tool.
Xz: malicious code in distributed source
70RISCO
abrir ↗GitHub PoC
churamanib/CVE-2023-0386
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISCO
abrir ↗GitHub PoC
DirtyCOW 笔记
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir ↗GitHub PoC★ 4
Ansible playbooks designed to check and remediate CVE-2024-3094 (XZ Backdoor)
Xz: malicious code in distributed source
70RISCO
abrir ↗GitHub PoC★ 3
A tutorial on how to detect the CVE 2024-3094
Xz: malicious code in distributed source
70RISCO
abrir ↗GitHub PoC
Scans liblzma from xu-utils for backdoor (CVE-2024-3094)
Xz: malicious code in distributed source
70RISCO
abrir ↗GitHub PoC★ 1
A small repo with a single playbook.
Xz: malicious code in distributed source
70RISCO
abrir ↗GitHub PoC★ 2
Verify if your installed version of xz-utils is vulnerable to CVE-2024-3094 backdoor
Xz: malicious code in distributed source
70RISCO
abrir ↗GitHub PoC
This is a container environment running CVE-2024-3094 sshd backdoor instance, working with https://github.com/amlweems/xzbot project. IT IS NOT Docker, just implemented by chroot.
Xz: malicious code in distributed source
70RISCO
abrir ↗GitHub PoC★ 2
Collection of Detection, Fix, and exploit for CVE-2024-3094
Xz: malicious code in distributed source
70RISCO
abrir ↗GitHub PoC
The repository consists of a checker file that confirms if your xz version and xz-utils package is vulnerable to CVE-2024-3094.
Xz: malicious code in distributed source
70RISCO
abrir ↗GitHub PoC
LAB: TẤN CÔNG HỆ ĐIỀU HÀNH WINDOWS DỰA VÀO LỖ HỔNG GIAO THỨC SMB.
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir ↗GitHub PoC★ 1
The CVE-2024-3094 Checker is a Bash tool for identifying if Linux systems are at risk from the CVE-2024-3094 flaw in XZ/LZMA utilities. It checks XZ versions, SSHD's LZMA linkage, and scans for specific byte patterns, delivering results in a concise table format.
Xz: malicious code in distributed source
70RISCO
abrir ↗GitHub PoC★ 3
Alicey0719/docker-POC_CVE-2024-1086
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISCO
abrir ↗GitHub PoC★ 1
cjybao/CVE-2024-1709-and-CVE-2024-1708
Authentication bypass using an alternate path or channel
100RISCO
abrir ↗GitHub PoC
YangHyperData/LOGJ4_PocShell_CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗GitHub PoC★ 1
This Repository Includes Kubernetes manifest files for configuration of Honeypot system and Falco IDS in K8s environment. There are also Demo Application written with Node.js which is containing Remote Code Execution Vulnerability (CVE-2023-32314) for demonstrating all addvantages of this architecture to manage Honeypot systems
Sandbox Escape
48RISCO
abrir ↗GitHub PoC
Em fevereiro de 2024, foi identificado duas novas vulnerabilidades que afetam o servidor JetBrains TeamCity (CVE-2024-27198 e CVE-2024-27199)
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir ↗GitHub PoC
Script en bash para revisar si tienes la vulnerabilidad CVE-2024-3094.
Xz: malicious code in distributed source
70RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.