Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.842exploits catalogados
37.493CVEs com exploração pública
24.695testados em laboratório
15.465 exploits
GitHub PoC2
Horizon-Software-Development/CVE-2024-3094
CVE-2024-3094CRITICAL30 mar 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC1
efekaanakkar/CVE-2024-30998
CVE-2024-30998CRITICAL30 mar 2024
SQL Injection vulnerability in PHPGurukul Men Salon Management System v.2.0, allows remote attackers to execute arbitrar
48RISCO
abrir
GitHub PoC1
brinhosa/CVE-2024-3094-One-Liner
CVE-2024-3094CRITICAL30 mar 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC26
Shell scripts to identify and fix installations of xz-utils affected by the CVE-2024-3094 vulnerability. Versions 5.6.0 and 5.6.1 of xz-utils are known to be vulnerable, and this script aids in detecting them and optionally downgrading to a stable, un-compromised version (5.4.6) or upgrading to latest version. Added Ansible Playbook
CVE-2024-3094CRITICAL30 mar 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC147
An ssh honeypot with the XZ backdoor. CVE-2024-3094
CVE-2024-3094CRITICAL30 mar 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC
hazemkya/CVE-2024-3094-checker
CVE-2024-3094CRITICAL30 mar 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC1
Checker for CVE-2024-3094 where malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code.
CVE-2024-3094CRITICAL30 mar 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC11
K8S and Docker Vulnerability Check for CVE-2024-3094
CVE-2024-3094CRITICAL30 mar 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC5
wgetnz/CVE-2024-3094-check
CVE-2024-3094CRITICAL30 mar 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC10
History of commits related to the xz backdoor Discovered On March 29, 2024: CVE-2024-3094.
CVE-2024-3094CRITICAL30 mar 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC
ashwani95/CVE-2024-3094
CVE-2024-3094CRITICAL30 mar 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC
More specific : Dirty COW (CVE-2016-5195)
CVE-2016-5195HIGHsob ataque30 mar 2024
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC54
Information for CVE-2024-3094
CVE-2024-3094CRITICAL29 mar 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC
Fractal-Tess/CVE-2024-3094
CVE-2024-3094CRITICAL29 mar 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC8
This repository contains a Bash script and a one-liner command to verify if a system is running a vulnerable version of the "xz" utility, as specified by CVE-2024-3094.
CVE-2024-3094CRITICAL29 mar 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC
Script to detect CVE-2024-3094.
CVE-2024-3094CRITICAL29 mar 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC
OpensourceICTSolutions/xz_utils-CVE-2024-3094
CVE-2024-3094CRITICAL29 mar 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC4
Verify that your XZ Utils version is not vulnerable to CVE-2024-3094
CVE-2024-3094CRITICAL29 mar 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC72
Quick and dirty PoC for checking whether a vulnerable version of xz-utils is installed (CVE-2024-3094)
CVE-2024-3094CRITICAL29 mar 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC8
This is an exploit script to find out wordpress admin's username and password hash by exploiting CVE-2024-1698.
CVE-2024-1698CRITICAL29 mar 2024
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RISCO
abrir
GitHub PoC6
ShadowRay RCE POC (CVE-2023-48022)
CVE-2023-48022CRITICAL29 mar 2024
Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the ve
85RISCO
abrir
GitHub PoC
Bludit 3.9.2 auth bruteforce bypass
CVE-2019-17240LOW28 mar 2024
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RISCO
abrir
GitHub PoC
mind2hex/CVE-2022-46169-Cacti-v1.2.22-RCE
CVE-2022-46169CRITICALsob ataque28 mar 2024
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC
ecrit un script python de correction de la vulnérabilités windows 7 pour réponse automatique de wazuh: CVE-2017-0143 (MS17-010 - EternalBlue) CVE-2019-0708 (BlueKeep), CVE-2019-1181 / CVE-2019-1182 (BlueKeep II), CVE-2015-1701 (MS15-034), CVE-2010-3333 (MS10-092), CVE-2012-0003 (MS12-020), CVE-2017-8759, CVE-2014-4114
CVE-2017-0143HIGHsob ataqueransomware28 mar 2024
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
GitHub PoC
ecrit un script python de correction de la vulnérabilités windows 7 pour réponse automatique de wazuh: CVE-2017-0143 (MS17-010 - EternalBlue) CVE-2019-0708 (BlueKeep), CVE-2019-1181 / CVE-2019-1182 (BlueKeep II), CVE-2015-1701 (MS15-034), CVE-2010-3333 (MS10-092), CVE-2012-0003 (MS12-020), CVE-2017-8759, CVE-2014-4114
CVE-2019-0708CRITICALsob ataqueransomware28 mar 2024
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC
ecrit un script python de correction de la vulnérabilités windows 7 pour réponse automatique de wazuh: CVE-2017-0143 (MS17-010 - EternalBlue) CVE-2019-0708 (BlueKeep), CVE-2019-1181 / CVE-2019-1182 (BlueKeep II), CVE-2015-1701 (MS15-034), CVE-2010-3333 (MS10-092), CVE-2012-0003 (MS12-020), CVE-2017-8759, CVE-2014-4114
CVE-2012-0003HIGH28 mar 2024
Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows
68RISCO
abrir
GitHub PoC
A working POC found while doing a HTB challenge. Original: https://github.com/user0x1337/CVE-2022-39227
CVE-2022-39227CRITICAL28 mar 2024
Python-jwt subject to Authentication Bypass by Spoofing
48RISCO
abrir
GitHub PoC1
Bludit 3.9.2 Remote Command Execution (RCE)
CVE-2019-1611328 mar 2024
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RISCO
abrir
GitHub PoC1
Check CVE-2023-42789
CVE-2023-42789CRITICAL28 mar 2024
A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0
48RISCO
abrir
GitHub PoC
ecrit un script python de correction de la vulnérabilités windows 7 pour réponse automatique de wazuh: CVE-2017-0143 (MS17-010 - EternalBlue) CVE-2019-0708 (BlueKeep), CVE-2019-1181 / CVE-2019-1182 (BlueKeep II), CVE-2015-1701 (MS15-034), CVE-2010-3333 (MS10-092), CVE-2012-0003 (MS12-020), CVE-2017-8759, CVE-2014-4114
CVE-2010-3333HIGHsob ataque28 mar 2024
Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2
100RISCO
abrir
anteriorpágina 287 / 516próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.