Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.859exploits catalogados
38.203CVEs com exploração pública
24.695testados em laboratório
81.859 exploits
GitHub PoC
CosmicSting (CVE-2024-34102) POC / Patch Validator
CVE-2024-34102CRITICALsob ataque07 jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir ↗
GitHub PoC★ 1
Chamilo LMS Unauthenticated Remote Code Execution
CVE-2023-4220HIGH07 jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir ↗
GitHub PoC★ 5
This is a script written in Python that allows the exploitation of the Chamilo's LMS software security flaw described in CVE-2023-4220
CVE-2023-4220HIGH07 jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir ↗
GitHub PoC
This is a script written in Python that allows the exploitation of the Chamilo's LMS software security flaw described in CVE-2023-4220
CVE-2023-4220HIGH07 jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir ↗
GitHub PoC★ 1
RCE Chamilo 1.11.24
CVE-2023-4220HIGH07 jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir ↗
GitHub PoC
sysonlai/CVE-2024-32002-hook
CVE-2024-32002CRITICAL07 jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-34102CRITICALsob ataque07 jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir ↗
GitHub PoC★ 7
PoC - PHP CGI Argument Injection CVE-2024-4577 (Scanner and Exploit)
CVE-2024-4577CRITICALsob ataqueransomware06 jul 2024
Argument Injection in PHP-CGI
100RISCO
abrir ↗
GitHub PoC★ 56
Remote Code Execution (RCE) Vulnerability In Evaluating Property Name Expressions with multies ways to exploit
CVE-2024-36401CRITICALsob ataque06 jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALsob ataque06 jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALsob ataqueransomware06 jul 2024
Argument Injection in PHP-CGI
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-36991HIGH06 jul 2024
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
61RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-36991HIGH06 jul 2024
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
61RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-36991HIGH06 jul 2024
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
61RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-36991HIGH06 jul 2024
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
61RISCO
abrir ↗
GitHub PoC★ 3
CVE-2024-4040 PoC
CVE-2024-4040CRITICALsob ataque05 jul 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2024-30088HIGHsob ataqueransomware05 jul 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISCO
abrir ↗
GitHub PoC
CVE-2024-39943 rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have Upload permissions). This occurs because a shell is used to execute df (i.e., with execSync instead of spawnSync in child_process in Node.js).
CVE-2024-39943CRITICAL05 jul 2024
rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote auth
60RISCO
abrir ↗
GitHub PoC★ 4
POC
CVE-2024-36401CRITICALsob ataque05 jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir ↗
GitHub PoC★ 1
TeamCity RCE for Linux (CVE-2023-42793)
CVE-2023-42793CRITICALsob ataqueransomware05 jul 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir ↗
GitHub PoC★ 1
CVE-2024-37770
CVE-2024-37770CRITICAL05 jul 2024
14Finger v1.1 was discovered to contain a remote command execution (RCE) vulnerability in the fingerprint function. This
48RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALsob ataqueransomware05 jul 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-27532HIGHsob ataqueransomware05 jul 2024
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database
93RISCO
abrir ↗
GitHub PoC★ 1
Quick regreSSHion checker (based on software version) for nuclei CVE-2024-6387
CVE-2024-6387HIGH05 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir ↗
GitHub PoC
imv7/CVE-2024-6387
CVE-2024-6387HIGH05 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir ↗
GitHub PoC★ 44
该漏洞存在于 NtQueryInformationToken 函数中,特别是在处理AuthzBasepCopyoutInternalSecurityAttributes 函数时,该漏洞源于内核在操作对象时对锁定机制的不当管理,这一失误可能导致恶意实体意外提升权限。
CVE-2024-30088HIGHsob ataqueransomware05 jul 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISCO
abrir ↗
GitHub PoC★ 386
HikvisionExploiter is a Python-based utility designed to automate exploitation and directory accessibility checks on Hikvision network cameras exploiting the Web interface Version 3.1.3.150324 + CVE-2021-36260 Detection
CVE-2021-36260CRITICALsob ataque05 jul 2024
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALsob ataque05 jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALsob ataque05 jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-4040CRITICALsob ataque05 jul 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISCO
abrir ↗
← anteriorpágina 442 / 2.729próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.