Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.859exploits catalogados
38.203CVEs com exploração pública
24.695testados em laboratório
81.859 exploits
VulnCheck XDB
local
CVE-2024-30088HIGHsob ataqueransomware27 jun 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISCO
abrir ↗
GitHub PoC★ 31
POC for CVE-2024-34102. A pre-authentication XML entity injection issue in Magento / Adobe Commerce.
CVE-2024-34102CRITICALsob ataque27 jun 2024
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir ↗
GitHub PoC★ 8
🆘New Windows Kernel Priviledge Escalation Vulnerability
CVE-2024-30088HIGHsob ataqueransomware27 jun 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISCO
abrir ↗
GitHub PoC★ 1
Exploit for CVE-2024-28995 affecting SolarWinds Serv-U 15.4.2 HF 1 and previous versions
CVE-2024-28995HIGHsob ataque26 jun 2024
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISCO
abrir ↗
GitHub PoC★ 1
ggfzx/CVE-2024-4577
CVE-2024-4577CRITICALsob ataqueransomware26 jun 2024
Argument Injection in PHP-CGI
100RISCO
abrir ↗
Exploit-DB
SolarWinds Platform 2024.1 SR1 - Race Condition
CVE-2024-28999MEDIUMwebappsmultiple26 jun 2024
SolarWinds Platform Race Condition Vulnerability
38RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALsob ataqueransomware26 jun 2024
Argument Injection in PHP-CGI
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-28995HIGHsob ataque26 jun 2024
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISCO
abrir ↗
GitHub PoC★ 1
Exploit for CVE-2024-28995 affecting SolarWinds Serv-U 15.4.2 HF 1 and previous versions
CVE-2024-28995HIGHsob ataque26 jun 2024
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISCO
abrir ↗
GitHub PoC★ 1
The script has been remastered by Teymur Novruzov to ensure compatibility with Python 3. This tool is intended for educational purposes only. Unauthorized use of this tool on any system or network without permission is illegal. The author is not responsible for any misuse of this tool.
CVE-2019-9053—25 jun 2024
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir ↗
Metasploit300
Fortra FileCatalyst Workflow SQL Injection (CVE-2024-5276)
CVE-2024-5276CRITICAL25 jun 2024
SQL Injection Vulnerability in FileCatalyst Workflow 5.1.6 Build 135 (and earlier)
65RISCO
abrir ↗
Metasploit300
Progress MOVEit SFTP Authentication Bypass for Arbitrary File Read
CVE-2024-5806CRITICAL25 jun 2024
MOVEit Transfer Authentication Bypass Vulnerability
85RISCO
abrir ↗
GitHub PoC
Hirusha-N/CVE-2021-34527-CVE-2023-38831-and-CVE-2023-32784
CVE-2021-34527HIGHsob ataqueransomware25 jun 2024
Windows Print Spooler Remote Code Execution Vulnerability
100RISCO
abrir ↗
GitHub PoC
CVE-2024-6028 Quiz Maker <= 6.5.8.3 - Unauthenticated SQL Injection via 'ays_questions' Parameter
CVE-2024-6028CRITICAL25 jun 2024
Quiz Maker <= 6.5.8.3 - Unauthenticated SQL Injection via 'ays_questions' Parameter
68RISCO
abrir ↗
GitHub PoC
Hirusha-N/CVE-2021-34527-CVE-2023-38831-and-CVE-2023-32784
CVE-2023-38831HIGHsob ataqueransomware25 jun 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir ↗
GitHub PoC
zerobytesecure/CVE-2019-19781
CVE-2019-19781CRITICALsob ataqueransomware25 jun 2024
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2024-6028CRITICAL25 jun 2024
Quiz Maker <= 6.5.8.3 - Unauthenticated SQL Injection via 'ays_questions' Parameter
68RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2019-19781CRITICALsob ataqueransomware25 jun 2024
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir ↗
GitHub PoC★ 1
Proof of concept of CVE-2024-29868 affecting Apache StreamPipes from 0.69.0 through 0.93.0
CVE-2024-29868CRITICAL24 jun 2024
Apache StreamPipes, Apache StreamPipes: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Recovery Token Generation
63RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-5806CRITICAL24 jun 2024
MOVEit Transfer Authentication Bypass Vulnerability
85RISCO
abrir ↗
GitHub PoC
CVE-2018-9995
CVE-2018-9995—24 jun 2024
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir ↗
GitHub PoC★ 45
Exploit for the CVE-2024-5806
CVE-2024-5806CRITICAL24 jun 2024
MOVEit Transfer Authentication Bypass Vulnerability
85RISCO
abrir ↗
GitHub PoC★ 1
This is an Incident Response Walkthrough: Mitigating a Zero-Day Attack (CVE-2024-4577)
CVE-2024-4577CRITICALsob ataqueransomware24 jun 2024
Argument Injection in PHP-CGI
100RISCO
abrir ↗
GitHub PoC★ 290
tykawaii98/CVE-2024-30088
CVE-2024-30088HIGHsob ataqueransomware24 jun 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2018-9995—24 jun 2024
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir ↗
VulnCheck XDB
local
CVE-2024-30088HIGHsob ataqueransomware24 jun 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2019-7609CRITICALsob ataque23 jun 2024
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISCO
abrir ↗
GitHub PoC
PoC and analysis for Kibana Prototype Pollution RCE (CVE-2019-7609).
CVE-2019-7609CRITICALsob ataque23 jun 2024
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2024-21338HIGHsob ataqueransomware23 jun 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISCO
abrir ↗
GitHub PoC★ 40
tykawaii98/CVE-2024-21338_PoC
CVE-2024-21338HIGHsob ataqueransomware23 jun 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISCO
abrir ↗
← anteriorpágina 448 / 2.729próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.