Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.646exploits catalogados
37.382CVEs com exploração pública
24.695testados em laboratório
15.392 exploits
GitHub PoC
CVE-2023-4220 Chamilo Exploit
CVE-2023-4220HIGH02 nov 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir
GitHub PoC1
JAckLosingHeart/CVE-2024-51132-POC
CVE-2024-51132CRITICAL02 nov 2024
An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information o
48RISCO
abrir
GitHub PoC2
wp/ultimate-member - SQL Injection Vulnerability Exploit Script.
CVE-2024-1071CRITICAL01 nov 2024
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RISCO
abrir
GitHub PoC
GodOfServer/CVE-2021-3129
CVE-2021-3129CRITICALsob ataqueransomware31 out 2024
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
GitHub PoC1
puckiestyle/CVE-2024-23113
CVE-2024-23113CRITICALsob ataque31 out 2024
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RISCO
abrir
GitHub PoC
hualy13/CVE-2019-0708-Check
CVE-2019-0708CRITICALsob ataqueransomware31 out 2024
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC5
CVE-2024-51567 is a Python PoC exploit targeting an RCE vulnerability in CyberPanel v2.3.6’s upgrademysqlstatus endpoint, bypassing CSRF protections.
CVE-2024-51567CRITICALsob ataqueransomware31 out 2024
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas
100RISCO
abrir
GitHub PoC1
chsxthwik/CVE-2024-27954
CVE-2024-27954CRITICAL30 out 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability
85RISCO
abrir
GitHub PoC1
CVE-2024-48359 PoC
CVE-2024-48359CRITICAL30 out 2024
Qualitor v8.24 was discovered to contain a remote code execution (RCE) vulnerability via the gridValoresPopHidden parame
48RISCO
abrir
GitHub PoC2
cve-2024-38821
CVE-2024-38821CRITICAL30 out 2024
Authorization Bypass of Static Resources in WebFlux Applications
48RISCO
abrir
GitHub PoC2
sxyrxyy/CVE-2024-21320-POC
CVE-2024-21320MEDIUM30 out 2024
Windows Themes Spoofing Vulnerability
38RISCO
abrir
GitHub PoC
Writing one because the one I found isn't working
CVE-2023-41425MEDIUM30 out 2024
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISCO
abrir
GitHub PoC23
Exploit for CyberPanel Pre-Auth RCE via Command Injection
CVE-2024-51378CRITICALsob ataqueransomware29 out 2024
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
100RISCO
abrir
GitHub PoC4
Automatic Plugin for WordPress < 3.92.1 Multiples Vulnerabilities
CVE-2024-27954CRITICAL29 out 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability
85RISCO
abrir
GitHub PoC1
0xDTC/Prestashop-CVE-2024-34716
CVE-2024-34716CRITICAL28 out 2024
PrestaShop vulnerable to XSS via customer contact form in FO, through file upload
60RISCO
abrir
GitHub PoC2
Stack-Overflow on TendaAC8
CVE-2023-33669CRITICAL28 out 2024
Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the timeZone parameter in the sub_44db3c funct
48RISCO
abrir
GitHub PoC
It's Proof of Concept on CVE-2024-24919-POC , i made it after it's discoverd
CVE-2024-24919HIGHsob ataqueransomware28 out 2024
Information disclosure
100RISCO
abrir
GitHub PoC
Refurbish Chamilo LMS CVE-2023-4220 exploit written in bash
CVE-2023-4220HIGH27 out 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir
GitHub PoC
CVE-2023-41425 Refurbish
CVE-2023-41425MEDIUM27 out 2024
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISCO
abrir
GitHub PoC
Refurbish
CVE-2022-0944CRITICAL27 out 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISCO
abrir
GitHub PoC18
Pyload RCE with js2py sandbox escape
CVE-2024-39205CRITICAL26 out 2024
An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a
68RISCO
abrir
GitHub PoC
CVE-2019-9053 rewritten in python3 to fix broken syntax. Affects CMS made simple <2.2.10
CVE-2019-905326 out 2024
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
GitHub PoC
tadash10/Detailed-Analysis-and-Mitigation-Strategies-for-CVE-2024-38124-and-CVE-2024-43468
CVE-2024-38124CRITICAL25 out 2024
Windows Netlogon Elevation of Privilege Vulnerability
48RISCO
abrir
GitHub PoC3
Zabbix Frontend Authentication Bypass Vulnerability
CVE-2022-23131CRITICALsob ataque25 out 2024
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISCO
abrir
GitHub PoC1
CVE-2022-0944 Remote Code Execution Exploit
CVE-2022-0944CRITICAL25 out 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISCO
abrir
GitHub PoC13
Cobalt Strike 的 CVE-2024-35250 的 BOF。(请给我加个星,谢谢。)
CVE-2024-35250HIGHsob ataque25 out 2024
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
91RISCO
abrir
GitHub PoC5
Proof of concept for CVE-2024-37383
CVE-2024-37383MEDIUMsob ataque24 out 2024
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
85RISCO
abrir
GitHub PoC3
CVE-2022-41082-poc
CVE-2022-41082HIGHsob ataqueransomware24 out 2024
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
This script performs vulnerability scanning for CVE-2024-21762, a Fortinet SSL VPN remote code execution vulnerability. It checks whether a given server is vulnerable to this CVE by sending specific requests and analyzing the responses.
CVE-2024-21762CRITICALsob ataqueransomware24 out 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISCO
abrir
GitHub PoC
rahisec/CVE-2024-4040
CVE-2024-4040CRITICALsob ataque23 out 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISCO
abrir
anteriorpágina 245 / 514próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.