Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.646exploits catalogados
37.382CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.482Referência 23.825GitHub PoC 15.392VulnCheck XDB 9.029Nuclei 4.416Metasploit 3.502✓ só verificadosrecentespopularesrisco
15.392 exploits
GitHub PoC
A simple python script to test for CVE-2024-9441.
Linear eMerge e3-Series Forgot Password Command Injection
60RISCO
abrir ↗GitHub PoC★ 1
WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion
WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion
68RISCO
abrir ↗GitHub PoC
This is an exploit for CVE-2024-23346 that acts as a "terminal" (tested on chemistry.htb)
pymatgen arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
48RISCO
abrir ↗GitHub PoC
Danyw24/CVE-2004-1561-Icecast-Header-Overwrite-buffer-overflow-RCE-2.0.1-Win32-
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with
60RISCO
abrir ↗GitHub PoC
Jimmy01240397/CVE-2012-1823-Analyze
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RISCO
abrir ↗GitHub PoC★ 1
This repository is a proof of concept (POC) for CVE-2024-23334, demonstrating an attempt to replicate the bug in aiohttp that leads to Local File Inclusion (LFI).
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISCO
abrir ↗GitHub PoC★ 4
D1se0/CVE-2024-23897-Vulnerabilidad-Jenkins
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗GitHub PoC★ 1
Proof of concept of CVE-2017-5638 including the whole setup of the Apache vulnerable server
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir ↗GitHub PoC★ 1
The issue only affects nginx if the "resolver" directive is used in the configuration file. Further, the attack is only possible if an attacker is able to forge UDP packets from the DNS server.
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t
35RISCO
abrir ↗GitHub PoC★ 3
POC for CVE-2024-42327, an authenticated SQL Injection in Zabbix through the user.get API Method
SQL injection in user.get API
70RISCO
abrir ↗GitHub PoC
Technical Details and Exploit for CVE-2024-11392
Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability
41RISCO
abrir ↗GitHub PoC★ 4
CVE-2024-10914 D-Link Remote Code Execution (RCE)
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir ↗GitHub PoC
lu4m575/CVE-2024-35286_scan.nse
A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to cond
75RISCO
abrir ↗GitHub PoC
fredagsguf/Windows-CVE-2024-38063
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC
PoC for Watchguard CVE-2022-26318 updated to Python3.12
On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulner
100RISCO
abrir ↗GitHub PoC
Veeam Service Provider Console (VSPC) remote code execution.
From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is pos
53RISCO
abrir ↗GitHub PoC★ 1
Carga de archivos sin restricciones en la funcionalidad de carga de archivos grandes en `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` en Chamilo LMS en versiones <= 1.11.24 permite a atacantes no autenticados realizar ataques de Cross Site Scripting almacenados y obtener código remoto ejecución mediante la carga de web shell.
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir ↗GitHub PoC★ 19
watchtowrlabs/Mitel-MiCollab-Auth-Bypass_CVE-2024-41713
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could
100RISCO
abrir ↗GitHub PoC★ 12
This repository contains a Proof of Concept (PoC) exploit for CVE-2024-11680, a critical vulnerability in ProjectSend r1605 and older versions. The exploit targets an improper authentication flaw due Privilege Misconfiguration issues.
ProjectSend Unauthenticated Configuration Modification
100RISCO
abrir ↗GitHub PoC★ 1
This is a exploit for CVE-2024-50498
WordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability
75RISCO
abrir ↗GitHub PoC
A Proof-of-Concept (PoC) exploit for CVE-2018-16763 (Fuel CMS - Preauthenticated Remote Code Execution).
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir ↗GitHub PoC★ 4
based on [EQSTLab](https://github.com/EQSTLab)
A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML v
70RISCO
abrir ↗GitHub PoC
CVE-2024-10914 is a critical vulnerability affecting the D-Link DNS-320, DNS-320LW, DNS-325, and DNS-340L up to version 20241028. The function cgi_user_add in the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add is the culprit, allowing attackers to inject operating system commands remotely.
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir ↗GitHub PoC★ 4
D1se0/CVE-2024-21413-Vulnerabilidad-Outlook-LAB
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC
Modified version of laravel ignition RCE (CVE-2021-3129) exploit script for Hour of Hack Session-4
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir ↗GitHub PoC
A utility for Magento 2 encryption key rotation and management. CVE-2024-34102(aka Cosmic Sting) victims can use it as an aftercare.
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir ↗GitHub PoC
Hunt3r850/CVE-2024-10924-Wordpress-Docker
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir ↗GitHub PoC★ 11
threatlabindonesia/CVE-2023-44487-HTTP-2-Rapid-Reset-Exploit-PoC
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.