Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

82.004exploits catalogados
38.306CVEs com exploração pública
24.695testados em laboratório
82.004 exploits
GitHub PoC★ 4
Critical use-after-free vulnerability discovered in Tinyproxy
CVE-2023-49606CRITICAL07 mai 2024
A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A
60RISCO
abrir ↗
GitHub PoC★ 1
[CVE-2024-23897] Jenkins CI Authenticated Arbitrary File Read Through the CLI Leads to Remote Code Execution (RCE)
CVE-2024-23897CRITICALsob ataqueransomware07 mai 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗
GitHub PoC★ 18
PoC for Exploiting CVE-2024-31848/49/50/51 - File Path Traversal
CVE-2024-31848CRITICAL07 mai 2024
A path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedde
63RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALsob ataqueransomware07 mai 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗
GitHub PoC
CVE-2024-27956
CVE-2024-27956CRITICAL07 mai 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISCO
abrir ↗
GitHub PoC★ 7
LINKSYS AC1900 EA7500v3 IGD UPnP Stack Buffer Overflow Remote Code Execution Vulnerability
CVE-2023-46012CRITICAL06 mai 2024
Buffer Overflow vulnerability LINKSYS EA7500 3.0.1.207964 allows a remote attacker to execute arbitrary code via an HTTP
48RISCO
abrir ↗
GitHub PoC★ 1
An issue in HSC Cybersecurity HSC Mailinspector version 5.2.17-3 has been identified, allowing a remote attacker to obtain sensitive information via a crafted payload to the id parameter in the mliSystemUsers.php component.
CVE-2024-32370CRITICAL06 mai 2024
An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive info
48RISCO
abrir ↗
GitHub PoC
GalloLuigi/Analisi-CVE-2017-5715
CVE-2017-5715MEDIUM06 mai 2024
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
55RISCO
abrir ↗
Metasploit600
DIAEnergie SQL Injection (CVE-2024-4548)
CVE-2024-4548CRITICAL06 mai 2024
Delta Electronics DIAEnergie SQL Injection
48RISCO
abrir ↗
Metasploit600
Ollama Model Registry Path Traversal RCE
CVE-2024-37032HIGH05 mai 2024
Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path,
78RISCO
abrir ↗
GitHub PoC
Turvanõrkuse CVE 2024 3273 analüüs: D-Link seadmete käsusüst
CVE-2024-3273HIGHsob ataque05 mai 2024
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMsob ataque05 mai 2024
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗
GitHub PoC★ 2
PoC for the Untrusted Pointer Dereference in the appid.sys driver
CVE-2024-21338HIGHsob ataqueransomware05 mai 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISCO
abrir ↗
GitHub PoC★ 1
FoxyProxys/CVE-2024-27956
CVE-2024-27956CRITICAL05 mai 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2019-9670CRITICALsob ataque05 mai 2024
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RISCO
abrir ↗
GitHub PoC★ 1
Joomla! v4.2.8 - Unauthenticated information disclosure
CVE-2023-23752MEDIUMsob ataque04 mai 2024
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMsob ataque04 mai 2024
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗
GitHub PoC
Vignesh2712/Automation-for-Juniper-cve-2023-36845
CVE-2023-36845CRITICALsob ataque04 mai 2024
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISCO
abrir ↗
GitHub PoC★ 7
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
CVE-2024-4040CRITICALsob ataque03 mai 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALsob ataqueransomware03 mai 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-4040CRITICALsob ataque03 mai 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISCO
abrir ↗
GitHub PoC
Bypass for CVE-2007-4559 Trellix patch
CVE-2007-4559CRITICAL03 mai 2024
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows
53RISCO
abrir ↗
GitHub PoC
CVE-2024-27956 WORDPRESS RCE PLUGIN
CVE-2024-27956CRITICAL03 mai 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-27971HIGH03 mai 2024
WordPress Premmerce Permalink Manager for WooCommerce plugin <= 2.3.10 - Local File Inclusion vulnerability
41RISCO
abrir ↗
GitHub PoC★ 1
Jenkins CVE-2024-23897: Arbitrary File Read Vulnerability
CVE-2024-23897CRITICALsob ataqueransomware03 mai 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-27956CRITICAL03 mai 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-21413CRITICALsob ataque03 mai 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir ↗
GitHub PoC★ 2
CVE-2024-21413 Microsoft Outlook RCE Exploit
CVE-2024-21413CRITICALsob ataque03 mai 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir ↗
GitHub PoC★ 7
Exploit for Microsoft SmartScreen malicious execution (april 2024)
CVE-2024-29988HIGHsob ataque03 mai 2024
SmartScreen Prompt Security Feature Bypass Vulnerability
83RISCO
abrir ↗
GitHub PoC
xsxtw/CVE-2019-0232
CVE-2019-0232—02 mai 2024
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISCO
abrir ↗
← anteriorpágina 471 / 2.734próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.