Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.753exploits catalogados
37.445CVEs com exploração pública
24.695testados em laboratório
15.407 exploits
GitHub PoC
deskfiler 1.2.3 Open Redirect exploit
CVE-2024-25291CRITICAL06 set 2024
Deskfiler v1.2.3 allows attackers to execute arbitrary code via uploading a crafted plugin.
48RISCO
abrir
GitHub PoC
nteract 0.28.0 open redirect to RCE exploit
CVE-2024-22891CRITICAL06 set 2024
Nteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link.
48RISCO
abrir
GitHub PoC5
Research and PoC for CVE-2024-6386
CVE-2024-6386CRITICAL05 set 2024
WPML Multilingual CMS <= 4.6.12 - Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template Injection
53RISCO
abrir
GitHub PoC12
Web Help Desk Hardcoded Credential Vulnerability (CVE-2024-28987)
CVE-2024-28987CRITICALsob ataque05 set 2024
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RISCO
abrir
GitHub PoC
bryanqb07/CVE-2023-32315
CVE-2023-32315HIGHsob ataque05 set 2024
Openfire administration console authentication bypass
100RISCO
abrir
GitHub PoC6
fru1ts/CVE-2024-44902
CVE-2024-44902CRITICAL05 set 2024
A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.
48RISCO
abrir
GitHub PoC2
This repository provides a PoC for CVE-2017-5638, a remote code execution vulnerability in Apache Struts 2, exploitable via a crafted Content-Type HTTP header.
CVE-2017-5638CRITICALsob ataqueransomware04 set 2024
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC5
Analysis and PoC for CVE-2024-4367: arbitrary JavaScript execution (XSS) in PDF.js
CVE-2024-4367MEDIUM04 set 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir
GitHub PoC1
Adobe ColdFusion CVE-2023-26360/CVE-2023-29298 自动化实现反弹
CVE-2023-26360HIGHsob ataque03 set 2024
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RISCO
abrir
GitHub PoC1
brownpanda29/Cve-2024-38063
CVE-2024-38063CRITICAL03 set 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC3
Authenticated Code execution
CVE-2023-26785CRITICAL03 set 2024
MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File
48RISCO
abrir
GitHub PoC1
Raffli-Dev/CVE-2023-41425
CVE-2023-41425MEDIUM03 set 2024
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISCO
abrir
GitHub PoC1
(CVE-2023-4220) Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
CVE-2023-4220HIGH03 set 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir
GitHub PoC
ImageMagick 7.1.0-49 vulnerable to Information Disclosure
CVE-2022-44268MEDIUM02 set 2024
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISCO
abrir
GitHub PoC
ps-interactive/cve-2024-38063
CVE-2024-38063CRITICAL02 set 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC8
This module exploits a vulnerability in the target service identified as CVE-2023-42115.
CVE-2023-42115CRITICAL02 set 2024
Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability
48RISCO
abrir
GitHub PoC9
This is a C language program designed to test the Windows TCP/IP Remote Code Execution Vulnerability (CVE-2024-38063). It sends specially crafted IPv6 packets with embedded shellcode to exploit the vulnerability.
CVE-2024-38063CRITICAL01 set 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC9
Unauthenticated Remote Code Execution in SPIP versions up to and including 4.2.12
CVE-2024-7954CRITICAL01 set 2024
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISCO
abrir
GitHub PoC
Yowise/CVE-2022-26923
CVE-2022-26923HIGHsob ataque01 set 2024
Active Directory Domain Services Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC30
poc code for CVE-2024-38080
CVE-2024-38080HIGHsob ataque01 set 2024
Windows Hyper-V Elevation of Privilege Vulnerability
71RISCO
abrir
GitHub PoC
Proof of Concept Exploit for CVE-2024-44812 - SQL Injection Authentication Bypass vulnerability in Online Complaint Site v1.0
CVE-2024-44812CRITICAL31 ago 2024
SQL Injection vulnerability in Online Complaint Site v.1.0 allows a remote attacker to escalate privileges via the usern
48RISCO
abrir
GitHub PoC11
POC for CVE-2023-29360
CVE-2023-29360HIGHsob ataque31 ago 2024
Microsoft Streaming Service Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC
🔍 Just wrapped up an incident report on a Phishing Alert (Event ID 257, SOC282). Enhancing my expertise in email threat detection and response! 🚨 #Cybersecurity #SOCAnalyst #LetsDefend
CVE-2024-24919HIGHsob ataqueransomware31 ago 2024
Information disclosure
100RISCO
abrir
GitHub PoC25
CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC
CVE-2024-21413CRITICALsob ataque31 ago 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC43
CVE-2024-38063 is a critical security vulnerability in the Windows TCP/IP stack that allows for remote code execution (RCE)
CVE-2024-38063CRITICAL31 ago 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC
A POC demo on CVE-2023-38831
CVE-2023-38831HIGHsob ataqueransomware30 ago 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC35
sinsinology/CVE-2024-6670
CVE-2024-6670CRITICALsob ataqueransomware30 ago 2024
WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability
100RISCO
abrir
GitHub PoC140
exploits for CVE-2024-20017
CVE-2024-20017CRITICAL30 ago 2024
In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote cod
60RISCO
abrir
GitHub PoC23
Proof of concept : CVE-2024-1071: WordPress Vulnerability Exploited
CVE-2024-1071CRITICAL30 ago 2024
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RISCO
abrir
GitHub PoC
LuisMateo1/Arbitrary-File-Read-CVE-2024-24919
CVE-2024-24919HIGHsob ataqueransomware29 ago 2024
Information disclosure
100RISCO
abrir
anteriorpágina 253 / 514próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.