Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.746exploits catalogados
38.126CVEs com exploração pública
24.695testados em laboratório
81.746 exploits
GitHub PoC★ 1
This is POC of CVE-2024-29671
CVE-2024-29671CRITICAL21 nov 2024
Buffer Overflow vulnerability in NEXTU FLATA AX1500 Router v.1.0.2 allows a remote attacker to execute arbitrary code vi
53RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALsob ataqueransomware21 nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISCO
abrir ↗
GitHub PoC★ 1
This tool scans WordPress sites for vulnerabilities in the "RegistrationMagic" plugin (CVE-2024-10508). It checks for the presence of a specific version (`6.0.2.6`) and marks the site as vulnerable if found. The results are saved in a file (`vuln.txt`) for further analysis.
CVE-2024-10508CRITICAL21 nov 2024
RegistrationMagic – User Registration Plugin with Custom Registration Forms <= 6.0.2.6 - Unauthenticated Privilege Escalation via Password Recovery
48RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-9474MEDIUMsob ataqueransomware20 nov 2024
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL20 nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir ↗
GitHub PoC
CVE-2024-52316 - Apache Tomcat Authentication Bypass Vulnerability
CVE-2024-52316CRITICAL20 nov 2024
Apache Tomcat: Authentication bypass when using Jakarta Authentication API
48RISCO
abrir ↗
GitHub PoC
GEO my WordPress < 4.5.0.2 - Unauthenticated LFI to RCE/PHAR Deserialization
CVE-2024-6330CRITICAL20 nov 2024
GEO my WordPress < 4.4.0.2 - Unauthenticated RCE via LFI
48RISCO
abrir ↗
GitHub PoC★ 3
Vulnerable docker container for Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 – 9.1.1.1 – Authentication Bypass CVE-2023-50164
CVE-2024-10924CRITICAL20 nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALsob ataqueransomware20 nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISCO
abrir ↗
GitHub PoC★ 1
PANW NGFW CVE-2024-0012
CVE-2024-0012CRITICALsob ataqueransomware20 nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISCO
abrir ↗
GitHub PoC
POC for CVE-2024-10924 written in Python
CVE-2024-10924CRITICAL20 nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir ↗
GitHub PoC
CVE-2023-28354
CVE-2023-28354CRITICAL20 nov 2024
An issue was discovered in Opsview Monitor Agent 6.8. An unauthenticated remote attacker can call check_nrpe against aff
48RISCO
abrir ↗
GitHub PoC
PoC for PAN-OS Exploit
CVE-2024-9474MEDIUMsob ataqueransomware20 nov 2024
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RISCO
abrir ↗
GitHub PoC
FAFAF
CVE-2018-15473MEDIUM20 nov 2024
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir ↗
GitHub PoC★ 2
Unauthenticated Remote Code Execution via Angular-Base64-Upload Library (npm:bower)
CVE-2024-42640CRITICAL19 nov 2024
angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Explo
75RISCO
abrir ↗
GitHub PoC
Simple Python script
CVE-2024-10924CRITICAL19 nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir ↗
GitHub PoC★ 20
Exploits Really Simple Security < 9.1.2 authentication bypass (CVE-2024-10924).
CVE-2024-10924CRITICAL19 nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir ↗
GitHub PoC★ 143
WPTaskScheduler RPC Persistence & CVE-2024-49039 via Task Scheduler
CVE-2024-49039HIGHsob ataqueransomware19 nov 2024
Windows Task Scheduler Elevation of Privilege Vulnerability
76RISCO
abrir ↗
Metasploit500
Ubuntu needrestart Privilege Escalation
CVE-2024-48990HIGH19 nov 2024
Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tric
41RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-3722HIGH19 nov 2024
Avaya Aura Device Services Remote Code Execution
56RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2018-3760—19 nov 2024
There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12
43RISCO
abrir ↗
GitHub PoC
ubaydev/CVE-2024-10508
CVE-2024-10508CRITICAL19 nov 2024
RegistrationMagic – User Registration Plugin with Custom Registration Forms <= 6.0.2.6 - Unauthenticated Privilege Escalation via Password Recovery
48RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-0012CRITICALsob ataqueransomware19 nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALsob ataqueransomware19 nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2017-12615HIGHsob ataqueransomware19 nov 2024
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2024-49039HIGHsob ataqueransomware19 nov 2024
Windows Task Scheduler Elevation of Privilege Vulnerability
76RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-9474MEDIUMsob ataqueransomware19 nov 2024
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-9474MEDIUMsob ataqueransomware19 nov 2024
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL19 nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL19 nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir ↗
← anteriorpágina 403 / 2.725próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.