Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.759exploits catalogados
38.127CVEs com exploração pública
24.695testados em laboratório
81.759 exploits
GitHub PoC★ 1
Woo Inquiry <= 0.1 - Unauthenticated SQL Injection
CVE-2024-7854CRITICAL04 out 2024
Woo Inquiry <= 0.1 - Unauthenticated SQL Injection
63RISCO
abrir ↗
GitHub PoC
Exploit of CVE-2021-23639 for the vulnerable library 'md-to-pdf' in JS
CVE-2021-23639CRITICAL04 out 2024
Remote Code Execution (RCE)
48RISCO
abrir ↗
VulnCheck XDB
local
CVE-2024-0582HIGH03 out 2024
Kernel: io_uring: page use-after-free vulnerability via buffer ring mmap
46RISCO
abrir ↗
GitHub PoC★ 2
Nortek Linear eMerge E3 Pre-Auth RCE PoC (CVE-2024-9441)
CVE-2024-9441CRITICAL03 out 2024
Linear eMerge e3-Series Forgot Password Command Injection
60RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2024-47176MEDIUM03 out 2024
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISCO
abrir ↗
GitHub PoC★ 3
CVE-2023-41425 (Wonder CMS XSS to RCE) exploit which serves required scripts locally. Good if you're lost at sea and have found a problem with your bike.
CVE-2023-41425MEDIUM02 out 2024
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISCO
abrir ↗
GitHub PoC★ 1
Wechat Social login <= 1.3.0 - Authentication Bypass
CVE-2024-9106CRITICAL01 out 2024
Wechat Social login <= 1.3.0 - Authentication Bypass
48RISCO
abrir ↗
GitHub PoC★ 5
This Python script helps to detect the Etherleak (CVE-2003-0001) vulnerability on a target host by analyzing the padding data in network packets. The script uses Scapy to send various types of requests (ICMP, ARP, or TCP) and checks if the responses contain any padding data that could potentially leak sensitive memory contents.
CVE-2003-0001—01 out 2024
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote att
45RISCO
abrir ↗
Exploit-DB
openSIS 9.1 - SQLi (Authenticated)
CVE-2024-46626HIGHwebappsphp01 out 2024
OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload.
41RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-8353CRITICAL30 set 2024
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection
68RISCO
abrir ↗
GitHub PoC★ 8
is a PoC for CVE-2024-4040 tool for exploiting the SSTI vulnerability in CrushFTP
CVE-2024-4040CRITICALsob ataque30 set 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALsob ataqueransomware30 set 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗
GitHub PoC★ 11
POC - Jenkins File Read Vulnerability - CVE-2024-23897
CVE-2024-23897CRITICALsob ataqueransomware30 set 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗
GitHub PoC★ 12
GiveWP PHP Object Injection exploit
CVE-2024-8353CRITICAL30 set 2024
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection
68RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-4040CRITICALsob ataque30 set 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISCO
abrir ↗
GitHub PoC★ 10
CVE-2021-3129 (Laravel Ignition RCE Exploit)
CVE-2021-3129CRITICALsob ataqueransomware29 set 2024
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALsob ataqueransomware29 set 2024
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-24919HIGHsob ataqueransomware29 set 2024
Information disclosure
100RISCO
abrir ↗
GitHub PoC★ 6
PoC script for CVE-2024-24919 vulnerability. It scans a list of target URLs to identify security issues by sending HTTP POST requests and analyzing server responses
CVE-2024-24919HIGHsob ataqueransomware29 set 2024
Information disclosure
100RISCO
abrir ↗
GitHub PoC★ 8
p33d/CVE-2024-43917
CVE-2024-43917CRITICAL29 set 2024
WordPress TI WooCommerce Wishlist plugin <= 2.8.2 - SQL Injection vulnerability
68RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-43917CRITICAL29 set 2024
WordPress TI WooCommerce Wishlist plugin <= 2.8.2 - SQL Injection vulnerability
68RISCO
abrir ↗
GitHub PoC★ 42
p33d/CVE-2024-45519
CVE-2024-45519CRITICALsob ataque28 set 2024
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-38816HIGH28 set 2024
CVE-2024-38816: Path traversal vulnerability in functional web frameworks
61RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-45519CRITICALsob ataque28 set 2024
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALsob ataque28 set 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir ↗
GitHub PoC★ 1
GeoServer CVE-2024-36401: Remote Code Execution (RCE) Vulnerability In Evaluating Property Name Expressions
CVE-2024-36401CRITICALsob ataque28 set 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-47176MEDIUM28 set 2024
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-29269HIGH28 set 2024
An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the
56RISCO
abrir ↗
GitHub PoC★ 1
ADManager Plus Build < 7210 Elevation of Privilege Vulnerability
CVE-2024-24409HIGH28 set 2024
Privilege Escalation
41RISCO
abrir ↗
GitHub PoC★ 1
This project contains a Python script that exploits **CVE-2023-38831**, a vulnerability in **WinRAR** versions prior to 6.23. The exploit generates a **malicious RAR archive** that triggers the execution of arbitrary code when the victim opens a benign-looking file within the archive (such as a PDF).
CVE-2023-38831HIGHsob ataqueransomware27 set 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir ↗
← anteriorpágina 419 / 2.726próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.