Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.753exploits catalogados
37.445CVEs com exploração pública
24.695testados em laboratório
15.407 exploits
GitHub PoC3
K7 Ultimate Security < v17.0.2019 "K7RKScan.sys" Null Pointer Dereference PoC
CVE-2024-36424MEDIUM13 ago 2024
K7RKScan.sys in K7 Ultimate Security before 17.0.2019 allows local users to cause a denial of service (BSOD) because of
33RISCO
abrir
GitHub PoC
This script is a proof-of-concept exploit for pfBlockerNG <= 2.1.4_26 that allows for remote code execution. It takes a single target URL or a list of URLs, tries to upload a shell using multiple payloads, executes a command, and then deletes the shell.
CVE-2022-31814CRITICAL12 ago 2024
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISCO
abrir
GitHub PoC
This repository contains detailed documentation and code related to the exploitation, detection, and mitigation of two significant vulnerabilities: CVE-2020-0796 (SMBGhost) and Print Spooler.
CVE-2020-0796CRITICALsob ataqueransomware12 ago 2024
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC
CVE-2024-37085 unauthenticated shell upload to full administrator on domain-joined esxi hypervisors.
CVE-2024-37085MEDIUMsob ataqueransomware12 ago 2024
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) per
68RISCO
abrir
GitHub PoC
A bash automation that exploits the vulnerable endpoints for the Joomla! API 4.0 - 4.2.7
CVE-2023-23752MEDIUMsob ataque11 ago 2024
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
GitHub PoC
CVE-2017-16921: In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged into OTRS as an agent can manipulate form parameters (related to PGP) and execute arbitrary shell commands with the permissions of the OTRS or web server user.
CVE-2017-1692111 ago 2024
In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.2
28RISCO
abrir
GitHub PoC1
Wonder CMS RCE (XSS)
CVE-2023-41425MEDIUM11 ago 2024
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISCO
abrir
GitHub PoC2
A PoC Exploit for CVE-2024-3105 - The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress Remote Code Execution (RCE)
CVE-2024-3105CRITICAL10 ago 2024
Woody code snippets – Insert Header Footer Code, AdSense Ads <= 2.5.0 -Authenticated (Contributor+) Remote Code Execution
48RISCO
abrir
GitHub PoC7
检测RDL服务是否运行,快速排查受影响资产
CVE-2024-38077CRITICAL10 ago 2024
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC2
基于135端口检测目标是否存在CVE-2024-38077漏洞
CVE-2024-38077CRITICAL10 ago 2024
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC
lworld0x00/CVE-2024-38077-notes
CVE-2024-38077CRITICAL10 ago 2024
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC13
Unauthenticated Remote Code Execution in SPIP versions up to and including 4.2.12
CVE-2024-7954CRITICAL10 ago 2024
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISCO
abrir
GitHub PoC2
Perform With Massive Apache OFBiz Zero-Day Scanner & RCE
CVE-2024-38856HIGHsob ataque10 ago 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISCO
abrir
GitHub PoC223
RDL的堆溢出导致的RCE
CVE-2024-38077CRITICAL09 ago 2024
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC13
远程探测 remote desktop licensing 服务开放情况,用于 CVE-2024-38077 漏洞快速排查
CVE-2024-38077CRITICAL09 ago 2024
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC5
it is script designed to interact with a router by sending a payload to its system tools. The script retrieves the router's configuration from environment variables to ensure security. It includes functions for generating an authorization header, sending a payload, and logging the process.
CVE-2022-44149HIGH09 ago 2024
The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by
53RISCO
abrir
GitHub PoC1
Sec-Link/CVE-2024-38077
CVE-2024-38077CRITICAL09 ago 2024
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC3
CVE-2024-38077,本仓库仅用作备份,
CVE-2024-38077CRITICAL09 ago 2024
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC1
psl-b/CVE-2024-38077-check
CVE-2024-38077CRITICAL09 ago 2024
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC
elliotosama/CVE-2012-2982
CVE-2012-298209 ago 2024
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISCO
abrir
GitHub PoC
jtoalu/CTF-CVE-2019-9053-GTFOBins
CVE-2019-905309 ago 2024
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
GitHub PoC9
SecStarBot/CVE-2024-38077-POC
CVE-2024-38077CRITICAL09 ago 2024
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC5
it is script designed to exploit certain vulnerabilities in routers by sending payloads through SNMP (Simple Network Management Protocol). The script automates the process of authorization, payload generation, and execution, allowing for remote command execution on the target device.
CVE-2022-45701HIGH09 ago 2024
Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.
53RISCO
abrir
GitHub PoC
Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code execution.
CVE-2024-6782CRITICAL09 ago 2024
Calibre Remote Code Execution
85RISCO
abrir
GitHub PoC1
An alternative solution(as a Magento 2 extension) to fix the XXE vulnerability CVE-2024-34102(aka Cosmic Sting). If you cannot upgrade Magento or cannot apply the official patch, try this one.
CVE-2024-34102CRITICALsob ataque08 ago 2024
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir
GitHub PoC49
Apache OFBiz RCE Scanner & Exploit (CVE-2024-38856)
CVE-2024-38856HIGHsob ataque08 ago 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISCO
abrir
GitHub PoC2
exploit que vulnera Jenkins hecho en Python
CVE-2024-25897CRITICAL08 ago 2024
ChurchCRM 5.5.0 FRCatalog.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.
48RISCO
abrir
GitHub PoC1
CVE-2024-41651
CVE-2024-41651CRITICAL08 ago 2024
An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade func
48RISCO
abrir
GitHub PoC
bolkv/CVE-2024-4320
CVE-2024-4320CRITICAL08 ago 2024
Remote Code Execution due to LFI in '/install_extension' in parisneo/lollms-webui
60RISCO
abrir
GitHub PoC
This repository details a SQL Injection vulnerability in Inventio Lite v4's, including exploitation steps and a Python script to automate the attack. It provides information on the vulnerable code, recommended fixes, and how to extract and decrypt administrative credentials.
CVE-2024-44541CRITICAL07 ago 2024
evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action
48RISCO
abrir
anteriorpágina 257 / 514próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.