Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.753exploits catalogados
37.445CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.482Referência 23.871GitHub PoC 15.407VulnCheck XDB 9.065Nuclei 4.426Metasploit 3.502✓ só verificadosrecentespopularesrisco
15.407 exploits
GitHub PoC★ 8
This repository automates the process of exploiting CVE-2024-25641 on Cacti 1.2.26
Cacti RCE vulnerability when importing packages
85RISCO
abrir ↗GitHub PoC
RCE OpenSSH CVE-2024-6387 Check and Exploit
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir ↗GitHub PoC
Sudo Privilege Escalation: CVE-2023-22809 Simulation This project simulates the Sudo privilege escalation vulnerability (CVE-2023-22809) to demonstrate how unauthorized root access can be gained. It involves identifying and exploiting this vulnerability in a controlled environment using Parrot OS, the Sudo command, and Bash scripting.
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISCO
abrir ↗GitHub PoC★ 77
GiveWP PHP Object Injection exploit
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RISCO
abrir ↗GitHub PoC★ 5
LiteSpeed Cache Privilege Escalation PoC - CVE-2024-28000
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISCO
abrir ↗GitHub PoC★ 2
Modified for GLPI Offsec Lab: call_user_func, array_map, passthru
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISCO
abrir ↗GitHub PoC★ 1
Kernel exploit for Xbox SystemOS using CVE-2024-30088
Windows Kernel Elevation of Privilege Vulnerability
83RISCO
abrir ↗GitHub PoC★ 1
Python exploit for Chamilo Unrestricted File Upload Vuln - CVE-2023-4220
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir ↗GitHub PoC
CVE-2023-4220 PoC Chamilo RCE
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir ↗GitHub PoC
TeamCity CVE-2023-42793 RCE (Remote Code Execution)
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir ↗GitHub PoC★ 695
poc for CVE-2024-38063 (RCE in tcpip.sys)
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC★ 23
LiteSpeed Cache Privilege Escalation PoC
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISCO
abrir ↗GitHub PoC★ 3
Telerik Report Server deserialization and authentication bypass exploit chain for CVE-2024-4358/CVE-2024-1800
Registration Authentication Bypass Vulnerability
100RISCO
abrir ↗GitHub PoC★ 4
SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISCO
abrir ↗GitHub PoC★ 2
Windows远程桌面授权服务CVE-2024-38077检测工具
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC★ 19
Scripts for Analysis of a RCE in Moodle Calculated Questions (CVE-2024-43425)
Moodle: remote code execution via calculated question types
78RISCO
abrir ↗GitHub PoC★ 2
CVE-2024-38063 research so you don't have to.
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC★ 9
CVE-2024-38856 Exploit
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISCO
abrir ↗GitHub PoC
Research
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISCO
abrir ↗GitHub PoC
MLflow LFI/RFI Vulnerability -CVE-2023-1177 - Reproduced
Path Traversal: '\..\filename' in mlflow/mlflow
75RISCO
abrir ↗GitHub PoC★ 1
CVE-2023-7028 POC && Exploit
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISCO
abrir ↗GitHub PoC★ 3
Proof-of-Concept for CVE-2024-5932 GiveWP PHP Object Injection
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection
68RISCO
abrir ↗GitHub PoC
Reproducing the following CVEs with dockerfile:CVE-2024-33644 CVE-2024-34370 CVE-2024-22120
WordPress Customify Site Library plugin <= 0.0.9 - Remote Code Execution (RCE) vulnerability
48RISCO
abrir ↗GitHub PoC★ 25
PHP CGI Argument Injection (CVE-2024-4577) RCE
Argument Injection in PHP-CGI
100RISCO
abrir ↗GitHub PoC
A PowerShell script to temporarily mitigate the CVE-2024-38063 vulnerability by disabling IPv6 on Windows systems. This workaround modifies the registry to reduce the risk of exploitation without needing the immediate installation of the official Microsoft KB update. Intended as a temporary fix
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC
A Bash script to mitigate the CVE-2024-6387 vulnerability in OpenSSH by providing an option to upgrade to a secure version or apply a temporary workaround. This repository helps secure systems against potential remote code execution risks associated with affected OpenSSH versions.
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir ↗GitHub PoC
CVE-2023-29384 Auto Exploiter on WordPress Job Board and Recruitment Plugin
WordPress WordPress Job Board and Recruitment Plugin – JobWP Plugin <= 2.0 is vulnerable to Arbitrary File Upload
48RISCO
abrir ↗GitHub PoC
RedTeam-Rediron/CVE-2020-1938
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir ↗GitHub PoC
Unauthenticated Remote Code Execution – Bricks
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.