Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.759exploits catalogados
38.127CVEs com exploração pública
24.695testados em laboratório
81.759 exploits
GitHub PoC★ 2
Spring Cloud Remote Code Execution
CVE-2024-37084CRITICAL11 set 2024
CVE-2024-37084: Remote code execution in Spring Cloud Data Flow
60RISCO
abrir ↗
Metasploit300
WordPress LearnPress Unauthenticated SQLi (CVE-2024-8522, CVE-2024-8529)
CVE-2024-8522CRITICAL11 set 2024
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'
75RISCO
abrir ↗
GitHub PoC
OtisSymbos/CVE-2021-44228-Log4Shell-
CVE-2021-44228CRITICALsob ataqueransomware11 set 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗
GitHub PoC
CVE Exploitation Reports: CVE-2007-3280, CVE-2017-0144, CVE-2019-0708
CVE-2019-0708CRITICALsob ataqueransomware11 set 2024
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir ↗
GitHub PoC
Log4J exploit CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware11 set 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗
GitHub PoC★ 1
KaoXx/CVE-2022-37706
CVE-2022-37706HIGH10 set 2024
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RISCO
abrir ↗
Metasploit600
VICIdial Authenticated Remote Code Execution
CVE-2024-8504HIGH10 set 2024
VICIdial Authenticated Remote Code Execution
58RISCO
abrir ↗
GitHub PoC★ 9
0xRoqeeb/sqlpad-rce-exploit-CVE-2022-0944
CVE-2022-0944CRITICAL10 set 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISCO
abrir ↗
GitHub PoC★ 1
Artemisxxx37/OverlayFS-PrivEsc-CVE-2022-0944
CVE-2022-0944CRITICAL10 set 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISCO
abrir ↗
Metasploit300
Vicidial SQL Injection Time-based Admin Credentials Enumeration
CVE-2024-8503CRITICAL10 set 2024
VICIdial Unauthenticated SQL Injection
85RISCO
abrir ↗
GitHub PoC★ 3
Analysis , Demo exploit and poc about CVE-2024-37084
CVE-2024-37084CRITICAL10 set 2024
CVE-2024-37084: Remote code execution in Spring Cloud Data Flow
60RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-28000CRITICAL10 set 2024
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISCO
abrir ↗
GitHub PoC★ 1
CVE-2024-38063 - Remotely Exploiting The Kernel Via IPv6
CVE-2024-38063CRITICAL10 set 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2017-0199HIGHsob ataqueransomware10 set 2024
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir ↗
GitHub PoC★ 1
Scanning CVE-2024-4577 vulnerability with a url list.
CVE-2024-4577CRITICALsob ataqueransomware10 set 2024
Argument Injection in PHP-CGI
100RISCO
abrir ↗
GitHub PoC★ 3
JSON API User <= 3.9.3 - Unauthenticated Privilege Escalation
CVE-2024-6624CRITICAL10 set 2024
JSON API User <= 3.9.3 - Unauthenticated Privilege Escalation
48RISCO
abrir ↗
GitHub PoC
carradolly/CVE-2015-8660
CVE-2015-8660—10 set 2024
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op
43RISCO
abrir ↗
GitHub PoC★ 5
CVE-2024-28000 Exploit for litespeed-cache =<6.3 allows Privilege Escalation with creation of administrator account
CVE-2024-28000CRITICAL10 set 2024
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALsob ataqueransomware10 set 2024
Argument Injection in PHP-CGI
100RISCO
abrir ↗
GitHub PoC
Python3 toolkit update
CVE-2017-0199HIGHsob ataqueransomware10 set 2024
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir ↗
GitHub PoC
LucasOneZ/CVE-2023-4966
CVE-2023-4966CRITICALsob ataqueransomware09 set 2024
Unauthenticated sensitive information disclosure
100RISCO
abrir ↗
GitHub PoC
PoC code written for CVE-2022-0944 to make exploitation easier. Based on information found here: https://huntr.com/bounties/46630727-d923-4444-a421-537ecd63e7fb
CVE-2022-0944CRITICAL09 set 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISCO
abrir ↗
GitHub PoC★ 4
CVE-2018-0834 full code exec
CVE-2018-0834—09 set 2024
Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remot
35RISCO
abrir ↗
GitHub PoC★ 5
SQLPad - Template injection (POC exploit for SQLPad RCE [CVE-2022-0944])
CVE-2022-0944CRITICAL09 set 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISCO
abrir ↗
GitHub PoC★ 1
CVE-2024-28000 LiteSpeed Cache Privilege Escalation Scan&Exp
CVE-2024-28000CRITICAL09 set 2024
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2023-4966CRITICALsob ataqueransomware09 set 2024
Unauthenticated sensitive information disclosure
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-28000CRITICAL09 set 2024
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISCO
abrir ↗
GitHub PoC
CVE-2024-23897 분석
CVE-2024-23897CRITICALsob ataqueransomware09 set 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-29269HIGH08 set 2024
An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the
56RISCO
abrir ↗
GitHub PoC★ 4
A proof of concept of the LFI vulnerability on aiohttp 3.9.1
CVE-2024-23334MEDIUM08 set 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISCO
abrir ↗
← anteriorpágina 424 / 2.726próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.