Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
82.081exploits catalogados
38.339CVEs com exploração pública
24.695testados em laboratório
TodosReferência 24.566Exploit-DB 24.485GitHub PoC 15.863VulnCheck XDB 9.205Nuclei 4.449Metasploit 3.513✓ só verificadosrecentespopularesrisco
82.081 exploits
VulnCheck XDB
initial-access
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗GitHub PoC★ 2
adhikara13/CVE-2024-2389
Flowmon Unauthenticated Command Injection Vulnerability
85RISCO
abrir ↗GitHub PoC★ 50
CVE-2023-6319 proof of concept
Command injection in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service
48RISCO
abrir ↗GitHub PoC★ 3
0xWhoami35/CVE-2023-23752
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗VulnCheck XDB
initial-access
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISCO
abrir ↗GitHub PoC★ 5
D-Link NAS Command Execution Exploit
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISCO
abrir ↗GitHub PoC★ 9
brains93/CVE-2024-24576-PoC-Python
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
53RISCO
abrir ↗GitHub PoC★ 20
CVE-2024-24576 Proof of Concept
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
53RISCO
abrir ↗GitHub PoC★ 1
Ray OS Command Injection RCE(Unauthorized)
Ray Command Injection in cpu_profile Parameter
85RISCO
abrir ↗VulnCheck XDB
initial-access
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISCO
abrir ↗Metasploit600
Chaos RAT XSS to RCE
Cross Site Scripting vulnerability in tiagorlampert CHAOS v.5.0.1 allows a remote attacker to escalate privileges via th
28RISCO
abrir ↗Metasploit600
AVideo WWBNIndex Plugin Unauthenticated RCE
An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath
68RISCO
abrir ↗GitHub PoC★ 1
The script is from https://github.com/JohnHammond/msdt-follina, just make it simple for me to use it and this script aim at generating the payload for more information refer the johnn hammond link
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir ↗VulnCheck XDB
initial-access
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISCO
abrir ↗GitHub PoC★ 5
A PoC exploit for CVE-2024-3273 - D-Link Remote Code Execution RCE
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISCO
abrir ↗VulnCheck XDB
client-side
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC★ 59
Example of CVE-2024-24576 use case.
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
53RISCO
abrir ↗GitHub PoC★ 23
CVE-2024-2879 - LayerSlider 7.9.11 - 7.10.0 - Unauthenticated SQL Injection
The LayerSlider plugin for WordPress is vulnerable to SQL Injection via the ls_get_popup_markup action in versions 7.9.1
68RISCO
abrir ↗VulnCheck XDB
infoleak
The LayerSlider plugin for WordPress is vulnerable to SQL Injection via the ls_get_popup_markup action in versions 7.9.1
68RISCO
abrir ↗GitHub PoC
CVE-2020-12641: Command Injection via “_im_convert_path” Parameter in Roundcube Webmail
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in
100RISCO
abrir ↗GitHub PoC★ 13
Exploit for CVE-2024-3273, supports single and multiple hosts
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISCO
abrir ↗GitHub PoC
Quick and dirty honeypot for CVE-2024-3273
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISCO
abrir ↗GitHub PoC★ 101
D-Link NAS CVE-2024-3273 Exploit Tool
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISCO
abrir ↗VulnCheck XDB
initial-access
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir ↗VulnCheck XDB
local
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RISCO
abrir ↗VulnCheck XDB
initial-access
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISCO
abrir ↗VulnCheck XDB
initial-access
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.