Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.805exploits catalogados
37.493CVEs com exploração pública
24.695testados em laboratório
15.428 exploits
GitHub PoC
NSE script to check if app is vulnerable to cve-2023-22515
CVE-2023-22515CRITICALsob ataqueransomware08 jun 2024
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISCO
abrir
GitHub PoC10
Proof Of Concept RCE exploit for critical vulnerability in PHP <8.2.15 (Windows), allowing attackers to execute arbitrary commands.
CVE-2024-4577CRITICALsob ataqueransomware08 jun 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC4
CVE-2024-4577 Exploit POC
CVE-2024-4577CRITICALsob ataqueransomware08 jun 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC75
CVE-2024-4577 is a critical vulnerability in PHP affecting CGI configurations, allowing attackers to execute arbitrary commands via crafted URL parameters.
CVE-2024-4577CRITICALsob ataqueransomware07 jun 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
CVE-2024-4577
CVE-2024-4577CRITICALsob ataqueransomware07 jun 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC43
POC & $BASH script for CVE-2024-4577
CVE-2024-4577CRITICALsob ataqueransomware07 jun 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC1
PHP CGI Argument Injection (CVE-2024-4577) Remote Code Execution PoC
CVE-2024-4577CRITICALsob ataqueransomware07 jun 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
CVE-2024-4577
CVE-2024-4577CRITICALsob ataqueransomware07 jun 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC1
taida957789/CVE-2024-4577
CVE-2024-4577CRITICALsob ataqueransomware07 jun 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC1
Wh02m1/CVE-2024-4577
CVE-2024-4577CRITICALsob ataqueransomware07 jun 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
CVE-2022-26134 exploit script
CVE-2022-26134CRITICALsob ataqueransomware07 jun 2024
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC21
huseyinstif/CVE-2024-4577-Nuclei-Template
CVE-2024-4577CRITICALsob ataqueransomware07 jun 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
CVE-2024-24919 exploit that checks more files for better visibility
CVE-2024-24919HIGHsob ataqueransomware07 jun 2024
Information disclosure
100RISCO
abrir
GitHub PoC322
PHP CGI Argument Injection (CVE-2024-4577) Remote Code Execution PoC
CVE-2024-4577CRITICALsob ataqueransomware07 jun 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
CVE-2022-29464 exploit script
CVE-2022-29464CRITICALsob ataqueransomware07 jun 2024
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir
GitHub PoC
WanLiChangChengWanLiChang/CVE-2024-4577-RCE-EXP
CVE-2024-4577CRITICALsob ataqueransomware07 jun 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC2
WordPress Automatic Plugin <= 3.92.0 - SQL Injection
CVE-2024-27956CRITICAL07 jun 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISCO
abrir
GitHub PoC
graphite-org/CVE-2024-4577
CVE-2024-4577CRITICALsob ataqueransomware07 jun 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
CVE-2021-22204 exploit script
CVE-2021-22204MEDIUMsob ataque07 jun 2024
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISCO
abrir
GitHub PoC1
Nuclei Template for CVE-2024-4577
CVE-2024-4577CRITICALsob ataqueransomware07 jun 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
princew88/CVE-2024-4577
CVE-2024-4577CRITICALsob ataqueransomware07 jun 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
oracle weblogic
CVE-2020-14883HIGHsob ataque07 jun 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC1
A Simple Exploit Code(POC) to Automate CVE-2024–24919
CVE-2024-24919HIGHsob ataqueransomware06 jun 2024
Information disclosure
100RISCO
abrir
GitHub PoC
A script to exploit CVE-2020-1472 (Zerologon)
CVE-2020-1472MEDIUMsob ataqueransomware06 jun 2024
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC
DigitalNinja00/CVE-2018-1335
CVE-2018-133506 jun 2024
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISCO
abrir
GitHub PoC
muhammad1596/CVE-2022-0847-DirtyPipe-Exploits
CVE-2022-0847HIGHsob ataque06 jun 2024
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC4
conan-sudo/CVE-2019-14974-bypass
CVE-2019-1497406 jun 2024
SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS.
43RISCO
abrir
GitHub PoC
sql延时注入poc
CVE-2024-32640CRITICAL06 jun 2024
MasaCMS SQL Injection vulnerability
85RISCO
abrir
GitHub PoC
CVE-2024-4295 Email Subscribers by Icegram Express <= 5.7.20 - Unauthenticated SQL Injection via hash
CVE-2024-4295CRITICAL06 jun 2024
Email Subscribers by Icegram Express <= 5.7.20 - Unauthenticated SQL Injection via hash
68RISCO
abrir
GitHub PoC
NanoWraith/CVE-2024-5084
CVE-2024-5084CRITICAL06 jun 2024
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
75RISCO
abrir
anteriorpágina 271 / 515próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.