Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
81.689exploits catalogados
38.075CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.482Referência 24.381GitHub PoC 15.712VulnCheck XDB 9.162Nuclei 4.445Metasploit 3.507✓ só verificadosrecentespopularesrisco
81.689 exploits
VulnCheck XDB
initial-access
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RISCO
abrir ↗GitHub PoC
This repo contains both the exploit and the explaination of how this vulnerability is exploited
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISCO
abrir ↗VulnCheck XDB
initial-access
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISCO
abrir ↗VulnCheck XDB
initial-access
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RISCO
abrir ↗GitHub PoC★ 1
KiviCare – Clinic & Patient Management System (EHR) WordPress Plugin Unauthenticated SQL Injection PoC
KiviCare – Clinic & Patient Management System (EHR) <= 3.6.4 - Unauthenticated SQL Injection
61RISCO
abrir ↗GitHub PoC★ 1
CVE-2024-55557
ui/pref/ProxyPrefView.java in weasis-core in Weasis 4.5.1 has a hardcoded key for symmetric encryption of proxy credenti
48RISCO
abrir ↗GitHub PoC★ 1
Privilege escaltion exploit script for Boardlight machine on HackTheBox. I had access as the Larissa user and ran this script from the /tmp directory; script has been adjusted accordingly.
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RISCO
abrir ↗VulnCheck XDB
infoleak
WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion
68RISCO
abrir ↗VulnCheck XDB
infoleak
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISCO
abrir ↗GitHub PoC
Jimmy01240397/CVE-2012-1823-Analyze
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RISCO
abrir ↗GitHub PoC
A simple python script to test for CVE-2024-9441.
Linear eMerge e3-Series Forgot Password Command Injection
60RISCO
abrir ↗Metasploit600
Cleo LexiCom, VLTrader, and Harmony Unauthenticated Remote Code Execution
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can impo
95RISCO
abrir ↗GitHub PoC★ 1
WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion
WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion
68RISCO
abrir ↗GitHub PoC
Danyw24/CVE-2004-1561-Icecast-Header-Overwrite-buffer-overflow-RCE-2.0.1-Win32-
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with
60RISCO
abrir ↗GitHub PoC★ 1
This repository is a proof of concept (POC) for CVE-2024-23334, demonstrating an attempt to replicate the bug in aiohttp that leads to Local File Inclusion (LFI).
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISCO
abrir ↗GitHub PoC
This is an exploit for CVE-2024-23346 that acts as a "terminal" (tested on chemistry.htb)
pymatgen arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
48RISCO
abrir ↗GitHub PoC★ 4
D1se0/CVE-2024-23897-Vulnerabilidad-Jenkins
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗GitHub PoC★ 1
Proof of concept of CVE-2017-5638 including the whole setup of the Apache vulnerable server
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir ↗GitHub PoC★ 1
The issue only affects nginx if the "resolver" directive is used in the configuration file. Further, the attack is only possible if an attacker is able to forge UDP packets from the DNS server.
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t
35RISCO
abrir ↗VulnCheck XDB
infoleak
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗GitHub PoC
Technical Details and Exploit for CVE-2024-11392
Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability
41RISCO
abrir ↗GitHub PoC★ 3
POC for CVE-2024-42327, an authenticated SQL Injection in Zabbix through the user.get API Method
SQL injection in user.get API
70RISCO
abrir ↗GitHub PoC★ 4
CVE-2024-10914 D-Link Remote Code Execution (RCE)
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir ↗GitHub PoC
fredagsguf/Windows-CVE-2024-38063
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir ↗VulnCheck XDB
infoleak
Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure
100RISCO
abrir ↗VulnCheck XDB
initial-access
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.