Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
82.004exploits catalogados
38.306CVEs com exploração pública
24.695testados em laboratório
TodosReferência 24.541Exploit-DB 24.485GitHub PoC 15.811VulnCheck XDB 9.205Nuclei 4.449Metasploit 3.513✓ só verificadosrecentespopularesrisco
82.004 exploits
GitHub PoC★ 9
local poc for CVE-2024-32002
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir ↗GitHub PoC★ 109
CVE-2024-32002 RCE PoC
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir ↗GitHub PoC★ 7
Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.
Windows Kernel Elevation of Privilege Vulnerability
83RISCO
abrir ↗GitHub PoC★ 4
A PoC exploit for CVE-2014-6271 - Shellshock
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗GitHub PoC
jakob-pennington/cve-2024-32002-submodule-rce
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir ↗GitHub PoC★ 1
jakob-pennington/cve-2024-32002-poc-rce
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir ↗GitHub PoC
CVE-2023-4596 Vulnerable Exploit and Checker Version
Forminator <= 1.24.6 - Unauthenticated Arbitrary File Upload
68RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Communit
35RISCO
abrir ↗VulnCheck XDB
initial-access
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗VulnCheck XDB
initial-access
Forminator <= 1.24.6 - Unauthenticated Arbitrary File Upload
68RISCO
abrir ↗GitHub PoC★ 1
WHOISshuvam/CVE-2015-1397
SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Communit
35RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
WordPress WP Fusion Lite plugin <= 3.41.24 - Remote Code Execution (RCE) vulnerability
48RISCO
abrir ↗VulnCheck XDB
initial-access
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir ↗GitHub PoC
CVE-2019-9054 exploit added support for python3 + bug fixes
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir ↗GitHub PoC★ 9
(CVE-2024-33559) The XStore theme for WordPress is vulnerable to SQL Injection due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query
WordPress XStore theme <= 9.3.5 - Unauthenticated SQL Injection vulnerability
48RISCO
abrir ↗GitHub PoC★ 18
Hook for the PoC for exploiting CVE-2024-32002
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir ↗GitHub PoC★ 532
Exploit PoC for CVE-2024-32002
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir ↗GitHub PoC
A submodule for exploiting CVE-2024-32002 vulnerability.
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir ↗GitHub PoC★ 5
CVE-2024-29895 | RCE on CACTI 1.3.X dev
Cacti command injection in cmd_realtime.php
85RISCO
abrir ↗GitHub PoC★ 2
A proof of concept for the git vulnerability CVE-2024-32002
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir ↗GitHub PoC
svchostmm/CVE-2024-25600-mass
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir ↗GitHub PoC
10cks/CVE-2024-21111-del
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
41RISCO
abrir ↗GitHub PoC★ 27
CVE-2023-34992: Fortinet FortiSIEM Command Injection Proof of Concept Exploit
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
85RISCO
abrir ↗GitHub PoC★ 14
Poc para explotar la vulnerabilidad CVE-2024-23897 en versiones 2.441 y anteriores de Jenkins, mediante la cual podremos leer archivos internos del sistema sin estar autenticados
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗GitHub PoC
CVE-2016-10033 Wordpress 4.6 Exploit
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.