Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.646exploits catalogados
37.382CVEs com exploração pública
24.695testados em laboratório
15.392 exploits
GitHub PoC1
Proof of Concept for the Log4Shell vulnerability (CVE-2021-44228), developed as part of the coursework for the curricular unit TPAS in the Master's degree in Information Security at FCUP.
CVE-2021-44228CRITICALsob ataqueransomware08 out 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
TeamCity server scanner to detect CVE-2023-42793
CVE-2023-42793CRITICALsob ataqueransomware08 out 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir
GitHub PoC1
Automated Exploit for CVE-2020-6287
CVE-2020-6287CRITICALsob ataque07 out 2024
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISCO
abrir
GitHub PoC83
Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409) exploit
CVE-2024-45409CRITICAL07 out 2024
The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selector
53RISCO
abrir
GitHub PoC4
is a PoC tool designed to exploit an authenticated Remote Code Execution (RCE) vulnerability in specific versions of PostgreSQL (9.3 - 11.7)
CVE-2019-919306 out 2024
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISCO
abrir
GitHub PoC1
CVE-2023-22527 | RCE using SSTI in Confluence
CVE-2023-22527CRITICALsob ataqueransomware06 out 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RISCO
abrir
GitHub PoC4
is a PoC tool demonstrating an exploit for a known vulnerability in the WebDAV component of IIS6
CVE-2017-7269CRITICALsob ataque06 out 2024
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISCO
abrir
GitHub PoC139
Zimbra - Remote Command Execution (CVE-2024-45519)
CVE-2024-45519CRITICALsob ataque05 out 2024
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RISCO
abrir
GitHub PoC5
The CVE-2019-16172 Scanner is designed to check LimeSurvey instances for the stored XSS vulnerability.
CVE-2019-1617205 out 2024
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, Su
23RISCO
abrir
GitHub PoC6
CVE-2024-26304 is a critical vulnerability (CVSS score of 9.8) affecting ArubaOS
CVE-2024-26304CRITICAL05 out 2024
There is a buffer overflow vulnerability in the underlying L2/L3 Management service that could lead to unauthenticated r
60RISCO
abrir
GitHub PoC4
A simple Python script to test an off-by-one vulnerability in the OPIE library (CVE-2010-1938). This vulnerability affects certain FTP servers and may allow for Denial of Service (DoS) or arbitrary code execution.
CVE-2010-193805 out 2024
Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeB
28RISCO
abrir
GitHub PoC3
Python implementation of a tool for decrypting and encrypting sensitive data in Grafana, specifically addressing the vulnerabilities associated with CVE-2021-43798. Grafana encrypts all data source passwords using the AES algorithm with the secret_key found in the defaults.ini configuration file.
CVE-2021-43798HIGHsob ataque05 out 2024
Grafana path traversal
100RISCO
abrir
GitHub PoC2
Simple hash cracker for Apache Shiro hashes written in Golang. Useful for exploiting CVE-2024-4956.
CVE-2024-4956HIGH04 out 2024
Nexus Repository 3 - Path Traversal
61RISCO
abrir
GitHub PoC
RCE in pyload prior to 0.5.0b3.dev31.
CVE-2023-0297CRITICAL04 out 2024
Code Injection in pyload/pyload
85RISCO
abrir
GitHub PoC3
A Bash script designed to scan multiple domains for the CVE-2024-4577 vulnerability in PHP-CGI.
CVE-2024-4577CRITICALsob ataqueransomware04 out 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
Exploit of CVE-2021-23639 for the vulnerable library 'md-to-pdf' in JS
CVE-2021-23639CRITICAL04 out 2024
Remote Code Execution (RCE)
48RISCO
abrir
GitHub PoC
EuJin03/CVE-2021-4034-PoC
CVE-2021-4034HIGHsob ataqueransomware04 out 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC1
Woo Inquiry <= 0.1 - Unauthenticated SQL Injection
CVE-2024-7854CRITICAL04 out 2024
Woo Inquiry <= 0.1 - Unauthenticated SQL Injection
63RISCO
abrir
GitHub PoC2
Nortek Linear eMerge E3 Pre-Auth RCE PoC (CVE-2024-9441)
CVE-2024-9441CRITICAL03 out 2024
Linear eMerge e3-Series Forgot Password Command Injection
60RISCO
abrir
GitHub PoC3
CVE-2023-41425 (Wonder CMS XSS to RCE) exploit which serves required scripts locally. Good if you're lost at sea and have found a problem with your bike.
CVE-2023-41425MEDIUM02 out 2024
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISCO
abrir
GitHub PoC1
Wechat Social login <= 1.3.0 - Authentication Bypass
CVE-2024-9106CRITICAL01 out 2024
Wechat Social login <= 1.3.0 - Authentication Bypass
48RISCO
abrir
GitHub PoC5
This Python script helps to detect the Etherleak (CVE-2003-0001) vulnerability on a target host by analyzing the padding data in network packets. The script uses Scapy to send various types of requests (ICMP, ARP, or TCP) and checks if the responses contain any padding data that could potentially leak sensitive memory contents.
CVE-2003-000101 out 2024
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote att
45RISCO
abrir
GitHub PoC12
GiveWP PHP Object Injection exploit
CVE-2024-8353CRITICAL30 set 2024
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection
68RISCO
abrir
GitHub PoC8
is a PoC for CVE-2024-4040 tool for exploiting the SSTI vulnerability in CrushFTP
CVE-2024-4040CRITICALsob ataque30 set 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISCO
abrir
GitHub PoC11
POC - Jenkins File Read Vulnerability - CVE-2024-23897
CVE-2024-23897CRITICALsob ataqueransomware30 set 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
GitHub PoC8
p33d/CVE-2024-43917
CVE-2024-43917CRITICAL29 set 2024
WordPress TI WooCommerce Wishlist plugin <= 2.8.2 - SQL Injection vulnerability
68RISCO
abrir
GitHub PoC10
CVE-2021-3129 (Laravel Ignition RCE Exploit)
CVE-2021-3129CRITICALsob ataqueransomware29 set 2024
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
GitHub PoC6
PoC script for CVE-2024-24919 vulnerability. It scans a list of target URLs to identify security issues by sending HTTP POST requests and analyzing server responses
CVE-2024-24919HIGHsob ataqueransomware29 set 2024
Information disclosure
100RISCO
abrir
GitHub PoC42
p33d/CVE-2024-45519
CVE-2024-45519CRITICALsob ataque28 set 2024
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RISCO
abrir
GitHub PoC1
GeoServer CVE-2024-36401: Remote Code Execution (RCE) Vulnerability In Evaluating Property Name Expressions
CVE-2024-36401CRITICALsob ataque28 set 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir
anteriorpágina 248 / 514próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.