Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.753exploits catalogados
37.445CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.482Referência 23.871GitHub PoC 15.407VulnCheck XDB 9.065Nuclei 4.426Metasploit 3.502✓ só verificadosrecentespopularesrisco
15.407 exploits
GitHub PoC★ 4
Server-Side Template Injection Exploit
Server Side Template Injection in Jinja2 allows Remote Command Execution
85RISCO
abrir ↗GitHub PoC★ 49
This repository contains PoC for CVE-2024-7965. This is the vulnerability in the V8 that occurs only within ARM64.
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially expl
76RISCO
abrir ↗GitHub PoC★ 1
PoC code for vulnerability in webmod v0.48. Originally written in 2007, assigned CVE-2007-1260.
Stack-based buffer overflow in the connectHandle function in server.cpp in WebMod 0.48 allows remote attackers to execut
23RISCO
abrir ↗GitHub PoC
Exploit a 2021 Kernel vulnerability in Ubuntu to become root almost instantly!
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISCO
abrir ↗GitHub PoC★ 16
CVE-2024-8190: Ivanti Cloud Service Appliance Command Injection
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remo
93RISCO
abrir ↗GitHub PoC★ 3
CVE-2024-44000-LiteSpeed-Cache
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RISCO
abrir ↗GitHub PoC★ 4
Proof Of Concept for CVE-2023-21716 Microsoft Word Heap Corruption
Microsoft Word Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC★ 5
A Bash script for Kali Linux that exploits an iOS WebKit vulnerability (CVE-2020-27950) using Metasploit and ngrok. Automates payload delivery with a public URL via ngrok, checks for required tools, handles errors, and provides an easy way to crash browsers for educational purposes only.
A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watch
68RISCO
abrir ↗GitHub PoC★ 54
Pre-Auth Exploit for CVE-2024-40711
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code exec
100RISCO
abrir ↗GitHub PoC★ 2
dogucyber/WordPress-Exploit-CVE-2024-1071
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RISCO
abrir ↗GitHub PoC★ 1
Unauthenticated remote code execution via Calibre’s content server in Calibre <= 7.14.0.
Calibre Remote Code Execution
85RISCO
abrir ↗GitHub PoC
New exploit for pyLoad v0.5.0 - Unauthenticated remote code excecution
Code Injection in pyload/pyload
85RISCO
abrir ↗GitHub PoC★ 49
POC - Unauthenticated RCE Flaw in Rejetto HTTP File Server - CVE-2024-23692
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISCO
abrir ↗GitHub PoC★ 2
chsxthwik/CVE-2024-2876
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RISCO
abrir ↗GitHub PoC★ 19
Exploit for CVE-2024-29847
Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows
60RISCO
abrir ↗GitHub PoC★ 2
Robocopsita/CVE-2022-0944_RCE_POC
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISCO
abrir ↗GitHub PoC
🚨 Just completed a detailed investigation for Event ID 193: "SOC231 - Cisco IOS XE Web UI ZeroDay (CVE-2023-20198)" via @LetsDefend.io. The attacker successfully bypassed authentication, gaining admin control over the device! Immediate containment was critical. Stay vigilant! 💻🔐
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISCO
abrir ↗GitHub PoC
sshipanoo/CVE-2024-44542
SQL Injection vulnerability in todesk v.1.1 allows a remote attacker to execute arbitrary code via the /todesk.com/news.
48RISCO
abrir ↗GitHub PoC
acidburn2049/CVE-2021-3156
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir ↗GitHub PoC★ 3
Proof-of-Concept Exploit for CVE-2024-36401 GeoServer 2.25.1
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir ↗GitHub PoC
0xWhoami35/CVE-2024-4879
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISCO
abrir ↗GitHub PoC
pwning netconsd
netconsd prior to v0.2 was vulnerable to an integer overflow in its parse_packet function. A malicious individual could
48RISCO
abrir ↗GitHub PoC
CVE-2024-8277 - 0Day Auto Exploit Authentication Bypass in WooCommerce Photo Reviews Plugin
WooCommerce Photo Reviews Premium <= 1.3.13.2 - Authentication Bypass to Account Takeover and Privilege Escalation
48RISCO
abrir ↗GitHub PoC
Old weaponized CVE-2022-1388 exploit.
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir ↗GitHub PoC
Event ID 189 Rule Name SOC227 Microsoft SharePoint Server Elevation of Privilege Possible CVE-2023-29357 .. Exploitation
Microsoft SharePoint Server Elevation of Privilege Vulnerability
100RISCO
abrir ↗GitHub PoC
🚨 New Incident Report Completed! 🚨 Just wrapped up "Event ID 268: SOC292 - Possible PHP Injection Detected (CVE-2024-4577)" on LetsDefend.io. This analysis involved investigating an attempted Command Injection targeting our PHP server. Staying ahead of these threats with continuous monitoring and swift containment! 🛡️
Argument Injection in PHP-CGI
100RISCO
abrir ↗GitHub PoC
Event ID 229 Rule Name SOC262 ScreenConnect Authentication Bypass Exploitation Detected (CVE-2024-1709)
Authentication bypass using an alternate path or channel
100RISCO
abrir ↗GitHub PoC
CVE Exploitation Reports: CVE-2007-3280, CVE-2017-0144, CVE-2019-0708
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir ↗GitHub PoC
Log4J exploit CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.