Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.859exploits catalogados
38.203CVEs com exploração pública
24.695testados em laboratório
81.859 exploits
VulnCheck XDB
infoleak
CVE-2024-34102CRITICALsob ataque13 jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-34102CRITICALsob ataque13 jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir ↗
GitHub PoC★ 1
CVE-2024-39250 TimeTrax SQLi
CVE-2024-39250CRITICAL13 jul 2024
EfroTech Timetrax v8.3 was discovered to contain an unauthenticated SQL injection vulnerability via the q parameter in t
63RISCO
abrir ↗
GitHub PoC★ 5
Exploitation CVE-2024-34102
CVE-2024-34102CRITICALsob ataque13 jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir ↗
GitHub PoC
BlackFrog-hub/cve-2015-1328
CVE-2015-1328—12 jul 2024
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISCO
abrir ↗
GitHub PoC
jakabakos/CVE-2024-36401-GeoServer-RCE
CVE-2024-36401CRITICALsob ataque12 jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALsob ataque12 jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir ↗
GitHub PoC★ 4
CVE-2024-4879.py is a Python script designed to detect specific vulnerabilities in ServiceNow instances and dump database connection details if the vulnerability is found. This tool is particularly useful for security researchers and penetration testers.
CVE-2024-4879CRITICALsob ataque12 jul 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISCO
abrir ↗
GitHub PoC★ 26
CVE-2024-4879 - Jelly Template Injection Vulnerability in ServiceNow
CVE-2024-4879CRITICALsob ataque12 jul 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-4879CRITICALsob ataque12 jul 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-4879CRITICALsob ataque12 jul 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-4879CRITICALsob ataque12 jul 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISCO
abrir ↗
GitHub PoC★ 10
Bulk scanning tool for ServiceNow CVE-2024-4879 vulnerability
CVE-2024-4879CRITICALsob ataque12 jul 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALsob ataqueransomware11 jul 2024
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir ↗
GitHub PoC★ 5
ATTACK PoC - PHP CVE-2024-4577
CVE-2024-4577CRITICALsob ataqueransomware11 jul 2024
Argument Injection in PHP-CGI
100RISCO
abrir ↗
GitHub PoC
Examining the phases of an attack using “Dragonfish's Elise Malware”, specifically, exploring the exploitation of vulnerability CVE-2017-11882.
CVE-2017-11882HIGHsob ataqueransomware11 jul 2024
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALsob ataque11 jul 2024
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-27956CRITICAL11 jul 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALsob ataqueransomware11 jul 2024
Argument Injection in PHP-CGI
100RISCO
abrir ↗
GitHub PoC★ 3
This project demonstrates a Web Application Firewall (WAF) simulation using Flask and a vulnerability checker for CVE-2017-5638. The WAF middleware blocks HTTP requests containing specific patterns, and the vulnerability checker tests for and exploits the Apache Struts 2 vulnerability (CVE-2017-5638).
CVE-2017-5638CRITICALsob ataqueransomware11 jul 2024
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir ↗
GitHub PoC
ThinkAdmin v5 v6 任意文件读取漏洞利用,可自定义字典爆破
CVE-2020-25540—11 jul 2024
ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on
60RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-4220HIGH11 jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir ↗
GitHub PoC
Burp Extension to test for CVE-2024-34102
CVE-2024-34102CRITICALsob ataque11 jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir ↗
GitHub PoC
CVE-2023–4220 Exploit
CVE-2023-4220HIGH11 jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir ↗
GitHub PoC★ 1
OpenSSH vulnerability CVE-2024-6387
CVE-2024-6387HIGH11 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2020-25540—11 jul 2024
ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on
60RISCO
abrir ↗
GitHub PoC★ 8
Perform with massive Wordpress SQLI 2 RCE
CVE-2024-27956CRITICAL11 jul 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISCO
abrir ↗
GitHub PoC★ 3
Guardian Code: A Script to Uncover CVE-2024-5274 Vulnerabilities
CVE-2024-5274HIGHsob ataque10 jul 2024
Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside
71RISCO
abrir ↗
GitHub PoC
DimaMend/cve-2024-6387-poc
CVE-2024-6387HIGH10 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir ↗
GitHub PoC★ 1
Rejetto HTTP File Server (HFS) 2.x - Unauthenticated RCE exploit module (CVE-2024-23692)
CVE-2024-23692CRITICALsob ataqueransomware10 jul 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISCO
abrir ↗
← anteriorpágina 440 / 2.729próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.