Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.753exploits catalogados
37.445CVEs com exploração pública
24.695testados em laboratório
15.407 exploits
GitHub PoC
dweger-scripts/CVE-2024-38063-Remediation
CVE-2024-38063CRITICAL19 ago 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC
s1d6point7bugcrowd/CVE-2024-6387-Race-Condition-in-Signal-Handling-for-OpenSSH
CVE-2024-6387HIGH19 ago 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir
GitHub PoC
PoC
CVE-2022-27925HIGHsob ataqueransomware19 ago 2024
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISCO
abrir
GitHub PoC1
anmolksachan/CVE-2020-2733
CVE-2020-2733CRITICAL19 ago 2024
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics)
68RISCO
abrir
GitHub PoC1
jeyabalaji711/CVE-2024-42919
CVE-2024-42919CRITICAL19 ago 2024
eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.
48RISCO
abrir
GitHub PoC
adobe commerce
CVE-2024-34102CRITICALsob ataque19 ago 2024
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir
GitHub PoC
Chamilo LMS Unauthenticated Big Upload File that allows remote code execution
CVE-2023-4220HIGH18 ago 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir
GitHub PoC1
Exploit for CVE-2024-38856 affecting Apache OFBiz versions before 18.12.15
CVE-2024-38856HIGHsob ataque18 ago 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISCO
abrir
GitHub PoC16
p0in7s/CVE-2024-38475
CVE-2024-38475CRITICALsob ataque18 ago 2024
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
100RISCO
abrir
GitHub PoC
PoC
CVE-2022-37706HIGH18 ago 2024
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RISCO
abrir
GitHub PoC
CVE-2024-7094 Vulnerability checker
CVE-2024-7094CRITICAL18 ago 2024
JS Help Desk – The Ultimate Help Desk & Support Plugin <= 2.8.6 - Unauthenticated PHP Code Injection to Remote Code Execution
60RISCO
abrir
GitHub PoC
WTN-arny/CVE-2024-37085
CVE-2024-37085MEDIUMsob ataqueransomware18 ago 2024
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) per
68RISCO
abrir
GitHub PoC
Poc for cve-2024-38063
CVE-2024-38063CRITICAL18 ago 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC
Comodo
CVE-2018-1743117 ago 2024
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication
60RISCO
abrir
GitHub PoC87
Note: I am not responsible for any bad act. This is written by Chirag Artani to demonstrate the vulnerability.
CVE-2024-38063CRITICAL17 ago 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC
CVE-2024-4577 Exploits
CVE-2024-4577CRITICALsob ataqueransomware17 ago 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
POC
CVE-2024-32002CRITICAL17 ago 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
GitHub PoC
PoC about CVE-2024-27198
CVE-2024-27198CRITICALsob ataqueransomware16 ago 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir
GitHub PoC13
mitigation script by disabling ipv6 of all interfaces
CVE-2024-38063CRITICAL15 ago 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC
MahdiOsman/CVE-2018-15473-SNMPv1-2-Community-String-Vulnerability-Testing
CVE-2018-15473MEDIUM15 ago 2024
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC7
CVE-2024-38077,仅支持扫描测试~
CVE-2024-38077CRITICAL15 ago 2024
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC1
An issue in Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.
CVE-2024-42850CRITICAL15 ago 2024
An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity
48RISCO
abrir
GitHub PoC
1amthebest1/CVE-2023-27372
CVE-2023-27372CRITICAL15 ago 2024
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISCO
abrir
GitHub PoC
JolyIrsb/CVE-2024-4956
CVE-2024-4956HIGH14 ago 2024
Nexus Repository 3 - Path Traversal
61RISCO
abrir
GitHub PoC
Python script designed to detect specific vulnerabilities in ServiceNow instances and dump database connection details if the vulnerability is found. This tool is particularly useful for security researchers and penetration testers.
CVE-2024-4879CRITICALsob ataque14 ago 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISCO
abrir
GitHub PoC125
fortra/CVE-2024-30051
CVE-2024-30051HIGHsob ataqueransomware14 ago 2024
Windows DWM Core Library Elevation of Privilege Vulnerability
71RISCO
abrir
GitHub PoC3
This exploit was created to exploit an XXE (XML External Entity). Through it, I read the backend code of the web service and found an endpoint where I could use gopher to make internal requests on Zabbix vulnerable to RCE.
CVE-2024-22120CRITICAL14 ago 2024
Time Based SQL Injection in Zabbix Server Audit Log
70RISCO
abrir
GitHub PoC3
This is my exploit for CVE-2024-22120, which involves an SSRF vulnerability inside an XXE with a Gopher payload.
CVE-2024-22120CRITICAL13 ago 2024
Time Based SQL Injection in Zabbix Server Audit Log
70RISCO
abrir
GitHub PoC3
K7 Ultimate Security < v17.0.2019 "K7RKScan.sys" Null Pointer Dereference PoC
CVE-2024-36424MEDIUM13 ago 2024
K7RKScan.sys in K7 Ultimate Security before 17.0.2019 allows local users to cause a denial of service (BSOD) because of
33RISCO
abrir
GitHub PoC4
Adobe Commerce XXE exploit
CVE-2024-34102CRITICALsob ataque13 ago 2024
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir
anteriorpágina 256 / 514próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.