Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.646exploits catalogados
37.382CVEs com exploração pública
24.695testados em laboratório
15.392 exploits
GitHub PoC
CVE-2023-28354
CVE-2023-28354CRITICAL20 nov 2024
An issue was discovered in Opsview Monitor Agent 6.8. An unauthenticated remote attacker can call check_nrpe against aff
48RISCO
abrir
GitHub PoC
FAFAF
CVE-2018-15473MEDIUM20 nov 2024
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC1
PANW NGFW CVE-2024-0012
CVE-2024-0012CRITICALsob ataqueransomware20 nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISCO
abrir
GitHub PoC
CVE-2024-52316 - Apache Tomcat Authentication Bypass Vulnerability
CVE-2024-52316CRITICAL20 nov 2024
Apache Tomcat: Authentication bypass when using Jakarta Authentication API
48RISCO
abrir
GitHub PoC3
Vulnerable docker container for Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 – 9.1.1.1 – Authentication Bypass CVE-2023-50164
CVE-2024-10924CRITICAL20 nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir
GitHub PoC
GEO my WordPress < 4.5.0.2 - Unauthenticated LFI to RCE/PHAR Deserialization
CVE-2024-6330CRITICAL20 nov 2024
GEO my WordPress < 4.4.0.2 - Unauthenticated RCE via LFI
48RISCO
abrir
GitHub PoC
POC for CVE-2024-10924 written in Python
CVE-2024-10924CRITICAL20 nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir
GitHub PoC
wudidwo/CVE-2017-12615-poc
CVE-2017-12615HIGHsob ataqueransomware19 nov 2024
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISCO
abrir
GitHub PoC2
Unauthenticated Remote Code Execution via Angular-Base64-Upload Library (npm:bower)
CVE-2024-42640CRITICAL19 nov 2024
angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Explo
75RISCO
abrir
GitHub PoC45
PAN-OS auth bypass + RCE
CVE-2024-9474MEDIUMsob ataqueransomware19 nov 2024
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RISCO
abrir
GitHub PoC20
Exploits Really Simple Security < 9.1.2 authentication bypass (CVE-2024-10924).
CVE-2024-10924CRITICAL19 nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir
GitHub PoC
Simple Python script
CVE-2024-10924CRITICAL19 nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir
GitHub PoC143
WPTaskScheduler RPC Persistence & CVE-2024-49039 via Task Scheduler
CVE-2024-49039HIGHsob ataqueransomware19 nov 2024
Windows Task Scheduler Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC
ubaydev/CVE-2024-10508
CVE-2024-10508CRITICAL19 nov 2024
RegistrationMagic – User Registration Plugin with Custom Registration Forms <= 6.0.2.6 - Unauthenticated Privilege Escalation via Password Recovery
48RISCO
abrir
GitHub PoC24
watchtowrlabs/palo-alto-panos-cve-2024-0012
CVE-2024-0012CRITICALsob ataqueransomware19 nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISCO
abrir
GitHub PoC20
CVE-2024-0012 PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015) RCE POC
CVE-2024-0012CRITICALsob ataqueransomware19 nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISCO
abrir
GitHub PoC8
WARNING: This is a vulnerable application to test the exploit for the Really Simple Security < 9.1.2 authentication bypass (CVE-2024-10924). Run it at your own risk!
CVE-2024-10924CRITICAL18 nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir
GitHub PoC
Porto <= 7.1.0 - Unauthenticated Local File Inclusion via porto_ajax_posts
CVE-2024-3806CRITICAL18 nov 2024
Porto <= 7.1.0 - Unauthenticated Local File Inclusion via porto_ajax_posts
48RISCO
abrir
GitHub PoC
Andriod binder bug record
CVE-2019-2215HIGHsob ataque18 nov 2024
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir
GitHub PoC2
Relais 2FA <= 1.0 - Authentication Bypass
CVE-2024-10245CRITICAL17 nov 2024
Relais 2FA <= 1.0 - Authentication Bypass
48RISCO
abrir
GitHub PoC2
Vuln disclosure for XOne app
CVE-2024-54820CRITICAL17 nov 2024
XOne Web Monitor v02.10.2024.530 framework 1.0.4.9 was discovered to contain a SQL injection vulnerability in the login
48RISCO
abrir
GitHub PoC3
PoC for Windows' IPv6 CVE-2024-38063
CVE-2024-38063CRITICAL16 nov 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC2
WordPress WP Time Capsule Plugin Arbitrary File Upload Vulnerability
CVE-2024-8856CRITICAL16 nov 2024
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RISCO
abrir
GitHub PoC1
jesicatjan/WordPress-NotificationX-CVE-2024-1698
CVE-2024-1698CRITICAL16 nov 2024
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RISCO
abrir
GitHub PoC9
CVE-2024-10914 is a critical command injection vulnerability affecting several legacy D-Link Network Attached Storage (NAS) devices.
CVE-2024-10914CRITICAL16 nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir
GitHub PoC12
Proof of concept for CVE-2024-54756, a vulnerability I found in GZDoom's ZScript scripting engine.
CVE-2024-54756CRITICAL15 nov 2024
A remote code execution (RCE) vulnerability in the ZScript function of ZDoom Team GZDoom v4.13.1 allows attackers to exe
48RISCO
abrir
GitHub PoC1
CVE-2024-54761 PoC
CVE-2024-54761MEDIUM15 nov 2024
BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.
33RISCO
abrir
GitHub PoC
这是安徽大学 “漏洞分析实验”(大三秋冬)期中作业归档。完整文档位于https://testgames.me/2024/11/10/cve-2021-44228/
CVE-2021-44228CRITICALsob ataqueransomware15 nov 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
这是一个D-Link rce漏洞 检测程序
CVE-2024-10914CRITICAL15 nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir
GitHub PoC
p33d/Palo-Alto-Expedition-Remote-Code-Execution-Exploit-CVE-2024-5910-CVE-2024-9464
CVE-2024-5910CRITICALsob ataque15 nov 2024
Expedition: Missing Authentication Leads to Admin Account Takeover
100RISCO
abrir
anteriorpágina 242 / 514próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.