Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.790exploits catalogados
37.482CVEs com exploração pública
24.695testados em laboratório
15.417 exploits
GitHub PoC
cve-2024/CVE-2024-27956-RCE
CVE-2024-27956CRITICAL14 jun 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISCO
abrir
GitHub PoC
TikiWiki CMS Groupware v8.3 - Open Redirect
CVE-2012-532114 jun 2024
tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frame
43RISCO
abrir
GitHub PoC1
huseyinstif/CVE-2024-28995-Nuclei-Template
CVE-2024-28995HIGHsob ataque14 jun 2024
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISCO
abrir
GitHub PoC2
ggfzx/CVE-2024-28995
CVE-2024-28995HIGHsob ataque14 jun 2024
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISCO
abrir
GitHub PoC12
vanboomqi/CVE-2024-23692
CVE-2024-23692CRITICALsob ataqueransomware13 jun 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISCO
abrir
GitHub PoC
Fix for CVE-2018-15473
CVE-2018-15473MEDIUM13 jun 2024
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC4
Fixed and minimalist PoC of the CVE-2024-4577
CVE-2024-4577CRITICALsob ataqueransomware13 jun 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC16
Unauthenticated RCE Flaw in Rejetto HTTP File Server (CVE-2024-23692)
CVE-2024-23692CRITICALsob ataqueransomware13 jun 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISCO
abrir
GitHub PoC20
PoC for the Veeam Recovery Orchestrator Authentication CVE-2024-29855
CVE-2024-29855CRITICAL13 jun 2024
Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator
53RISCO
abrir
GitHub PoC
WanLiChangChengWanLiChang/CVE-2024-23692-RCE
CVE-2024-23692CRITICALsob ataqueransomware13 jun 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISCO
abrir
GitHub PoC
Valve Press - CVE-2024-27956-RCE - SQL Injection
CVE-2024-27956CRITICAL13 jun 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISCO
abrir
GitHub PoC
Users of JetBrains IDEs at risk of GitHub access token compromise (CVE-2024-37051)
CVE-2024-37051CRITICAL13 jun 2024
GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ
48RISCO
abrir
GitHub PoC12
PDF.js是由Mozilla维护的基于JavaScript的PDF查看器。此漏洞允许攻击者在打开恶意 PDF 文件后立即执行任意 JavaScript 代码。这会影响所有 Firefox 用户 (<126),因为 Firefox 使用 PDF.js 来显示 PDF 文件,但也严重影响了许多基于 Web 和 Electron 的应用程序,这些应用程序(间接)使用 PDF.js 进行预览功能。
CVE-2024-4367MEDIUM13 jun 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir
GitHub PoC
HPT-Intern-Task-Submission/CVE-2022-46169
CVE-2022-46169CRITICALsob ataque12 jun 2024
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC1
0XFFFF-XD/CVE-2024-4577-PHP-CGI-RCE
CVE-2024-4577CRITICALsob ataqueransomware12 jun 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC25
Ivanti EPM SQL Injection Remote Code Execution Vulnerability
CVE-2024-29824CRITICALsob ataque12 jun 2024
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att
100RISCO
abrir
GitHub PoC
Vietnam National Cyber Security (NCS)'s Internship - 2nd Test
CVE-2024-4577CRITICALsob ataqueransomware12 jun 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC4
jakabakos/CVE-2024-27348-Apache-HugeGraph-RCE
CVE-2024-27348CRITICALsob ataque12 jun 2024
Apache HugeGraph-Server: Command execution in gremlin
100RISCO
abrir
GitHub PoC5
CVE-2024-4577
CVE-2024-4577CRITICALsob ataqueransomware12 jun 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
Rejetto http File Server 2.3.x (Reverse shell)
CVE-2014-6287CRITICALsob ataque12 jun 2024
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir
GitHub PoC2
POC for CVE-2024-4577 with Shodan integration
CVE-2024-4577CRITICALsob ataqueransomware12 jun 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
raytran54/CVE-2018-7600
CVE-2018-7600CRITICALsob ataqueransomware12 jun 2024
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC1
Dokan Pro <= 3.10.3 - Unauthenticated SQL Injection
CVE-2024-3922CRITICAL12 jun 2024
Dokan Pro <= 3.10.3 - Unauthenticated SQL Injection
75RISCO
abrir
GitHub PoC
PHP CGI Argument Injection (CVE-2024-4577) Remote Code Execution PoC
CVE-2024-4577CRITICALsob ataqueransomware11 jun 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC29
CVE-2024-37051 poc and exploit
CVE-2024-37051CRITICAL11 jun 2024
GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ
48RISCO
abrir
GitHub PoC
CVE-2022-36446 POC 실습
CVE-2022-3644611 jun 2024
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
60RISCO
abrir
GitHub PoC
This is a PoC for PHP CVE-2024-4577.
CVE-2024-4577CRITICALsob ataqueransomware11 jun 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC1
SalehLardhi/CVE-2024-24919
CVE-2024-24919HIGHsob ataqueransomware11 jun 2024
Information disclosure
100RISCO
abrir
GitHub PoC
Basic POC to test CVE-2024-3094 vulnerability inside K8s cluster
CVE-2024-3094CRITICAL11 jun 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC4
NanoWraith/CVE-2024-23692
CVE-2024-23692CRITICALsob ataqueransomware11 jun 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISCO
abrir
anteriorpágina 269 / 514próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.