Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.859exploits catalogados
38.203CVEs com exploração pública
24.695testados em laboratório
81.859 exploits
GitHub PoC
y1s4s/CVE-2024-36401-PoC
CVE-2024-36401CRITICALsob ataque01 ago 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALsob ataque01 ago 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir ↗
GitHub PoC★ 1
bananoname/cve-2021-42013
CVE-2021-42013CRITICALsob ataqueransomware31 jul 2024
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALsob ataqueransomware31 jul 2024
Argument Injection in PHP-CGI
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALsob ataqueransomware31 jul 2024
Argument Injection in PHP-CGI
100RISCO
abrir ↗
GitHub PoC★ 1
An exploit for CVE-2024-6387, targeting a signal handler race condition in OpenSSH's server
CVE-2024-6387HIGH31 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir ↗
GitHub PoC
Exploit script for CVE-2022-41544 in GetSimple CMS, with enhanced error handling and detailed usage instructions.
CVE-2022-41544HIGH31 jul 2024
GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file paramete
46RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALsob ataqueransomware31 jul 2024
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir ↗
GitHub PoC
批量验证POC和EXP
CVE-2024-4577CRITICALsob ataqueransomware31 jul 2024
Argument Injection in PHP-CGI
100RISCO
abrir ↗
GitHub PoC★ 1
apena-ba/CVE-2024-39304
CVE-2024-39304HIGH31 jul 2024
ChurchCRM SQL Injection Vulnerability
41RISCO
abrir ↗
Metasploit600
Calibre Python Code Injection (CVE-2024-6782)
CVE-2024-6782CRITICAL31 jul 2024
Calibre Remote Code Execution
85RISCO
abrir ↗
GitHub PoC★ 1
12
CVE-2023-25813CRITICAL30 jul 2024
SQL Injection via replacements in sequelize
48RISCO
abrir ↗
GitHub PoC
KaSooMi0228/CVE-2024-25600-Bricks-Builder-WordPress
CVE-2024-25600CRITICAL30 jul 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir ↗
GitHub PoC★ 12
Proof of concept python script for regreSSHion exploit.
CVE-2024-6387HIGH30 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALsob ataque30 jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir ↗
GitHub PoC★ 3
PoC of CVE-2024-32002 - Remote Code Execution while cloning special-crafted local repositories
CVE-2024-32002CRITICAL30 jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir ↗
GitHub PoC★ 86
GeoServer Remote Code Execution
CVE-2024-36401CRITICALsob ataque30 jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir ↗
GitHub PoC
Just small script to exploit CVE-2024-32002
CVE-2024-32002CRITICAL30 jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL30 jul 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir ↗
GitHub PoC
FlojBoj/CVE-2024-32002
CVE-2024-32002CRITICAL30 jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-4220HIGH29 jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir ↗
GitHub PoC
GIT RCE CVE-2024-32002
CVE-2024-32002CRITICAL29 jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir ↗
VulnCheck XDB
local
CVE-2024-21338HIGHsob ataqueransomware29 jul 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISCO
abrir ↗
GitHub PoC
CVE-2023-4220 POC RCE
CVE-2023-4220HIGH29 jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir ↗
GitHub PoC
Blind SQL Injection to RCE in a PHP open source application
CVE-2024-40498CRITICAL29 jul 2024
SQL Injection vulnerability in PuneethReddyHC Online Shopping sysstem advanced v.1.0 allows an attacker to execute arbit
48RISCO
abrir ↗
GitHub PoC★ 1
CVE-2024-39700 Proof of Concept
CVE-2024-39700CRITICAL29 jul 2024
Remote Code Execution (RCE) vulnerability in jupyterlab extension template `update-integration-tests` GitHub Action
48RISCO
abrir ↗
GitHub PoC★ 2
PoC for CVE-2024-34144
CVE-2024-34144CRITICAL29 jul 2024
A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_
60RISCO
abrir ↗
GitHub PoC
projectforsix/CVE-2021-45428-Defacer
CVE-2021-45428—29 jul 2024
TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can uploa
50RISCO
abrir ↗
GitHub PoC★ 83
Windows AppLocker Driver (appid.sys) LPE
CVE-2024-21338HIGHsob ataqueransomware29 jul 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISCO
abrir ↗
GitHub PoC★ 2
veritas-rt/CVE-2010-0219
CVE-2010-0219—28 jul 2024
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products
60RISCO
abrir ↗
← anteriorpágina 436 / 2.729próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.