Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

82.035exploits catalogados
38.336CVEs com exploração pública
24.695testados em laboratório
82.035 exploits
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALsob ataqueransomware24 abr 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir ↗
GitHub PoC★ 6
Simple honeypot for CVE-2024-3400 Palo Alto PAN-OS Command Injection Vulnerability
CVE-2024-3400CRITICALsob ataqueransomware24 abr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISCO
abrir ↗
GitHub PoC★ 11
JetBrains TeamCity 2023.05.3 - Remote Code Execution (RCE), CVE-2023-42793
CVE-2023-42793CRITICALsob ataqueransomware24 abr 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir ↗
GitHub PoC
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.
CVE-2019-9670CRITICALsob ataque24 abr 2024
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RISCO
abrir ↗
GitHub PoC★ 4
PoC exploit for GLPI - Command injection using a third-party library script
CVE-2022-35914CRITICALsob ataque24 abr 2024
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-35914CRITICALsob ataque24 abr 2024
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISCO
abrir ↗
GitHub PoC
Check to see if your Palo Alto firewall has been compromised by running script againt support bundle.
CVE-2024-3400CRITICALsob ataqueransomware24 abr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware24 abr 2024
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-3273HIGHsob ataque23 abr 2024
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISCO
abrir ↗
GitHub PoC
mrrobot0o/CVE-2024-3273-
CVE-2024-3273HIGHsob ataque23 abr 2024
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISCO
abrir ↗
Metasploit600
Flowmon Unauthenticated Command Injection
CVE-2024-2389CRITICAL23 abr 2024
Flowmon Unauthenticated Command Injection Vulnerability
85RISCO
abrir ↗
GitHub PoC
A basic script that exploits CVE-2011-2523
CVE-2011-2523—23 abr 2024
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir ↗
VulnCheck XDB
local
CVE-2024-21338HIGHsob ataqueransomware23 abr 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-4040CRITICALsob ataque23 abr 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-24716HIGH22 abr 2024
Path traversal in Icinga Web 2
78RISCO
abrir ↗
VulnCheck XDB
local
CVE-2023-0386HIGHsob ataque22 abr 2024
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISCO
abrir ↗
GitHub PoC★ 1
A final project for "Network Security" class at NYCU (National Yang Ming Chiao Tung University, Taiwan). Exploiting a CVE in "EasyAppointments" software.
CVE-2022-0482CRITICAL22 abr 2024
Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
75RISCO
abrir ↗
GitHub PoC★ 35
CVE-2024-27198 & CVE-2024-27199 PoC - RCE, Admin Account Creation, Enum Users, Server Information
CVE-2024-27198CRITICALsob ataqueransomware22 abr 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir ↗
Metasploit600
Apache HugeGraph Gremlin RCE
CVE-2024-27348CRITICALsob ataque22 abr 2024
Apache HugeGraph-Server: Command execution in gremlin
100RISCO
abrir ↗
GitHub PoC
CVE-2023-0386 包含所需运行库
CVE-2023-0386HIGHsob ataque22 abr 2024
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2018-14847CRITICALsob ataque22 abr 2024
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-27198CRITICALsob ataqueransomware22 abr 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-27199HIGHsob ataqueransomware22 abr 2024
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
100RISCO
abrir ↗
GitHub PoC
SOPlanning 1.52.00 CSRF/SQLi/XSS (CVE-2024-33722, CVE-2024-33724)
CVE-2024-33722MEDIUM22 abr 2024
SOPlanning 1.52.00 is vulnerable to SQL Injection by an authenticated user via projets.php with statut[].
33RISCO
abrir ↗
GitHub PoC★ 6
A PoC exploit for CVE-2018-14847 - MikroTik WinBox File Read
CVE-2018-14847CRITICALsob ataque22 abr 2024
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISCO
abrir ↗
GitHub PoC
CVE-2022-24716 (Arbitrary File Disclosure Icingaweb2)
CVE-2022-24716HIGH22 abr 2024
Path traversal in Icinga Web 2
78RISCO
abrir ↗
GitHub PoC
TYuan0816/cve-2023-44487
CVE-2023-44487HIGHsob ataque22 abr 2024
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISCO
abrir ↗
GitHub PoC★ 216
Oracle VirtualBox Elevation of Privilege (Local Privilege Escalation) Vulnerability
CVE-2024-21111HIGH22 abr 2024
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
41RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2022-0482CRITICAL22 abr 2024
Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
75RISCO
abrir ↗
GitHub PoC
PoC for CVE-2024-24576 vulnerability "BatBadBut"
CVE-2024-24576CRITICAL21 abr 2024
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
53RISCO
abrir ↗
← anteriorpágina 474 / 2.735próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.