Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.759exploits catalogados
38.127CVEs com exploração pública
24.695testados em laboratório
81.759 exploits
GitHub PoC
This is a demo for CVE-2024-32002 POC
CVE-2024-32002CRITICAL27 set 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir ↗
GitHub PoC
This is a demo for CVE-2024-32002 POC
CVE-2024-32002CRITICAL27 set 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir ↗
GitHub PoC★ 1
Proof of Concept for CVE-2024-32002
CVE-2024-32002CRITICAL27 set 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir ↗
GitHub PoC
Reproduction of SQL Injection Vulnerabilities in OpenHIS
CVE-2024-46532CRITICAL27 set 2024
SQL Injection vulnerability in OpenHIS v.1.0 allows an attacker to execute arbitrary code via the refund function in the
48RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-38831HIGHsob ataqueransomware27 set 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir ↗
GitHub PoC★ 5
PrusaSlicer Arbitrary Code Execution using .3mf
CVE-2023-47268MEDIUM26 set 2024
In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrar
33RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-9014CRITICAL26 set 2024
OAuth2 client id and secret exposed through the web browser in pgAdmin 4
63RISCO
abrir ↗
GitHub PoC
p33d/CVE-2024-8275
CVE-2024-8275CRITICAL26 set 2024
The Events Calendar <= 6.6.4 - Unauthenticated SQL Injection
60RISCO
abrir ↗
GitHub PoC★ 3
A vulnerability scanner that searches for the CVE-2024-9166 vulnerability on websites, more info about this vulnerability here: https://www.tenable.com/cve/CVE-2024-9166
CVE-2024-9166CRITICAL26 set 2024
OS Command Injection in Atelmo Atemio AM 520 HD Full HD Satellite Receiver
63RISCO
abrir ↗
GitHub PoC★ 5
A proof of concept of traefik CVE to understand the impact
CVE-2024-45410CRITICAL26 set 2024
HTTP client can remove the X-Forwarded headers in Traefik
48RISCO
abrir ↗
GitHub PoC★ 8
Pgadmin4 Sensitive Information Exposure
CVE-2024-9014CRITICAL26 set 2024
OAuth2 client id and secret exposed through the web browser in pgAdmin 4
63RISCO
abrir ↗
GitHub PoC
d
CVE-2023-38831HIGHsob ataqueransomware26 set 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir ↗
Metasploit300
CUPS IPP Attributes LAN Remote Code Execution
CVE-2024-47175HIGH26 set 2024
libppd's ppdCreatePPDFromIPP2 function does not sanitize IPP attributes when creating the PPD buffer
48RISCO
abrir ↗
Metasploit300
CUPS IPP Attributes LAN Remote Code Execution
CVE-2024-47076HIGH26 set 2024
libcupsfilters's cfGetPrinterAttributes5 does not validate IPP attributes returned from an IPP server
58RISCO
abrir ↗
GitHub PoC
UMASANKAR-MG/Path-Traversal-CVE-2024-4956
CVE-2024-4956HIGH26 set 2024
Nexus Repository 3 - Path Traversal
61RISCO
abrir ↗
Metasploit300
CUPS IPP Attributes LAN Remote Code Execution
CVE-2024-47177—26 set 2024
15RISCO
abrir ↗
Metasploit300
CUPS IPP Attributes LAN Remote Code Execution
CVE-2024-47176MEDIUM26 set 2024
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISCO
abrir ↗
Metasploit300
WordPress TI WooCommerce Wishlist SQL Injection (CVE-2024-43917)
CVE-2024-43917CRITICAL25 set 2024
WordPress TI WooCommerce Wishlist plugin <= 2.8.2 - SQL Injection vulnerability
68RISCO
abrir ↗
GitHub PoC
CVE-2019-15107 webmin 취약점에 대해서 직접 서버를 구축하고 공격 결과를 남긴 정보입니다.
CVE-2019-15107CRITICALsob ataqueransomware25 set 2024
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2024-47176MEDIUM25 set 2024
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISCO
abrir ↗
GitHub PoC
CVE-2024-46627 - Incorrect access control in BECN DATAGERRY v2.2 allows attackers to > execute arbitrary commands via crafted web requests.
CVE-2024-46627CRITICAL25 set 2024
Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.
63RISCO
abrir ↗
GitHub PoC★ 4
Proof-of-Concept for CVE-2024-47066
CVE-2024-47066CRITICAL24 set 2024
Lobe Chat has insufficient fix for GHSA-mxhq-xw3g-rphc (CVE-2024-32964)
53RISCO
abrir ↗
GitHub PoC★ 147
CVE-2024-38200 & CVE-2024-43609 - Microsoft Office NTLMv2 Disclosure Vulnerability
CVE-2024-38200MEDIUM24 set 2024
Microsoft Office Spoofing Vulnerability
38RISCO
abrir ↗
GitHub PoC★ 7
Proof of Concept Exploit for CVE-2024-28987: SolarWinds Web Help Desk Hardcoded Credential Vulnerability
CVE-2024-28987CRITICALsob ataque24 set 2024
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-28987CRITICALsob ataque24 set 2024
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RISCO
abrir ↗
GitHub PoC★ 3
WBW Product Table Pro <= 1.9.4 - Unauthenticated Arbitrary SQL Execution to RCE
CVE-2024-43918CRITICAL24 set 2024
WordPress WBW Product Table PRO plugin <= 1.9.4 - Unauthenticated Arbitrary SQL Query Execution vulnerability
48RISCO
abrir ↗
GitHub PoC★ 9
CVE-2024-7593 Ivanti Virtual Traffic Manager 22.2R1 / 22.7R2 Admin Panel Authentication Bypass PoC [EXPLOIT]
CVE-2024-7593CRITICALsob ataque24 set 2024
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remo
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-7593CRITICALsob ataque24 set 2024
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remo
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-7954CRITICAL23 set 2024
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISCO
abrir ↗
GitHub PoC★ 2
vidura2/CVE-2024-46377
CVE-2024-46377CRITICAL23 set 2024
Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the save_settings() function
48RISCO
abrir ↗
← anteriorpágina 420 / 2.726próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.