Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.759exploits catalogados
38.127CVEs com exploração pública
24.695testados em laboratório
81.759 exploits
VulnCheck XDB
infoleak
CVE-2024-50340HIGH06 nov 2024
Ability to change environment from query in symfony/runtime
68RISCO
abrir ↗
GitHub PoC
pedrochalegre7/CVE-2024-4367-pdf-sample
CVE-2024-4367MEDIUM06 nov 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir ↗
GitHub PoC★ 25
CVE-2024-4577 RCE PoC
CVE-2024-4577CRITICALsob ataqueransomware06 nov 2024
Argument Injection in PHP-CGI
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALsob ataqueransomware06 nov 2024
Argument Injection in PHP-CGI
100RISCO
abrir ↗
GitHub PoC★ 3
Wux Blog Editor <= 3.0.0 - Unauthenticated Arbitrary File Upload
CVE-2024-9932CRITICAL05 nov 2024
Wux Blog Editor <= 3.0.0 - Unauthenticated Arbitrary File Upload
60RISCO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2022-29078—05 nov 2024
The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[
50RISCO
abrir ↗
GitHub PoC
1-Click Login: Passwordless Authentication 1.4.5 - Authentication Bypass via Account Takeover
CVE-2024-50478CRITICAL05 nov 2024
WordPress 1-Click Login: Passwordless Authentication plugin 1.4.5 - Broken Authentication vulnerability
48RISCO
abrir ↗
GitHub PoC
Woocommerce Product Design <= 1.0.0 - Unauthenticated Arbitrary File Upload
CVE-2024-50482CRITICAL05 nov 2024
WordPress Woocommerce Product Design plugin <= 1.0.0 - Arbitrary File Upload vulnerability
48RISCO
abrir ↗
GitHub PoC★ 2
Meetup <= 0.1 - Authentication Bypass via Account Takeover
CVE-2024-50483CRITICAL05 nov 2024
WordPress Meetup plugin <= 0.1 - Broken Authentication vulnerability
48RISCO
abrir ↗
GitHub PoC★ 4
This repository contains a Crystallographic Information File (CIF) intended for use on the "Chemistry" machine on Hack The Box (HTB).
CVE-2024-23346CRITICAL05 nov 2024
pymatgen arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
48RISCO
abrir ↗
GitHub PoC
WatchTowerHQ <= 3.10.1 - Authentication Bypass to Administrator due to Missing Empty Value Check
CVE-2024-9933CRITICAL05 nov 2024
WatchTowerHQ <= 3.10.1 - Authentication Bypass to Administrator due to Missing Empty Value Check
48RISCO
abrir ↗
GitHub PoC
guigui237/Expoitation-de-la-vuln-rabilit-CVE-2022-22965
CVE-2022-22965CRITICALsob ataque05 nov 2024
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir ↗
GitHub PoC
GRÜN spendino Spendenformular <= 1.0.1 - Unauthenticated Arbitrary Options Update
CVE-2024-50476CRITICAL04 nov 2024
WordPress GRÜN spendino Spendenformular plugin <= 1.0.1 - Arbitrary Option Update to Privilege Escalation vulnerability
48RISCO
abrir ↗
GitHub PoC★ 3
WP Query Console <= 1.0 - Unauthenticated Remote Code Execution
CVE-2024-50498CRITICAL04 nov 2024
WordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability
75RISCO
abrir ↗
GitHub PoC
Signup Page <= 1.0 - Unauthenticated Arbitrary Options Update
CVE-2024-50475CRITICAL04 nov 2024
WordPress Signup Page plugin <= 1.0 - Arbitrary Option Update to Privilege Escalation vulnerability
48RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-50498CRITICAL04 nov 2024
WordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability
75RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2024-37383MEDIUMsob ataque03 nov 2024
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
85RISCO
abrir ↗
GitHub PoC
Roundcube mail server exploit for CVE-2024-37383 (Stored XSS)
CVE-2024-37383MEDIUMsob ataque03 nov 2024
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
85RISCO
abrir ↗
GitHub PoC
ahmetramazank/CVE-2024-4577
CVE-2024-4577CRITICALsob ataqueransomware03 nov 2024
Argument Injection in PHP-CGI
100RISCO
abrir ↗
GitHub PoC★ 1
JAckLosingHeart/CVE-2024-51132-POC
CVE-2024-51132CRITICAL02 nov 2024
An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information o
48RISCO
abrir ↗
GitHub PoC
POC firewall with rules designed to detect and block Spring4Shell vulnerability (CVE-2022-22965) exploit
CVE-2022-22965CRITICALsob ataque02 nov 2024
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir ↗
GitHub PoC
77Philly/CVE-2024-7456scripts
CVE-2024-7456CRITICAL02 nov 2024
SQL Injection in lunary-ai/lunary
48RISCO
abrir ↗
GitHub PoC
CVE-2023-4220 Chamilo Exploit
CVE-2023-4220HIGH02 nov 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-4220HIGH02 nov 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-1071CRITICAL01 nov 2024
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RISCO
abrir ↗
GitHub PoC★ 2
wp/ultimate-member - SQL Injection Vulnerability Exploit Script.
CVE-2024-1071CRITICAL01 nov 2024
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2015-9251—01 nov 2024
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed wi
28RISCO
abrir ↗
GitHub PoC
GodOfServer/CVE-2021-3129
CVE-2021-3129CRITICALsob ataqueransomware31 out 2024
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-51567CRITICALsob ataqueransomware31 out 2024
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas
100RISCO
abrir ↗
GitHub PoC★ 1
puckiestyle/CVE-2024-23113
CVE-2024-23113CRITICALsob ataque31 out 2024
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RISCO
abrir ↗
← anteriorpágina 408 / 2.726próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.