Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
82.081exploits catalogados
38.339CVEs com exploração pública
24.695testados em laboratório
TodosReferência 24.566Exploit-DB 24.485GitHub PoC 15.863VulnCheck XDB 9.205Nuclei 4.449Metasploit 3.513✓ só verificadosrecentespopularesrisco
82.081 exploits
GitHub PoC
Em fevereiro de 2024, foi identificado duas novas vulnerabilidades que afetam o servidor JetBrains TeamCity (CVE-2024-27198 e CVE-2024-27199)
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir ↗GitHub PoC★ 3
apocalypxze: xz backdoor (2024) AKA CVE-2024-3094 related links
Xz: malicious code in distributed source
70RISCO
abrir ↗GitHub PoC★ 14
Dockerfile and Kubernetes manifests for reproduce CVE-2024-3094
Xz: malicious code in distributed source
70RISCO
abrir ↗GitHub PoC
Script en bash para revisar si tienes la vulnerabilidad CVE-2024-3094.
Xz: malicious code in distributed source
70RISCO
abrir ↗GitHub PoC★ 1
cjybao/CVE-2024-1709-and-CVE-2024-1708
Authentication bypass using an alternate path or channel
100RISCO
abrir ↗Exploit-DB
Employee Management System 1.0 - _txtusername_ and _txtpassword_ SQL Injection (Admin Login)
20RISCO
abrir ↗VulnCheck XDB
initial-access
Improper limitation of a pathname to a restricted directory (“path traversal”)
100RISCO
abrir ↗GitHub PoC★ 3
CVE-2024-3094 - Checker (fix for arch etc)
Xz: malicious code in distributed source
70RISCO
abrir ↗GitHub PoC★ 1
This Repository Includes Kubernetes manifest files for configuration of Honeypot system and Falco IDS in K8s environment. There are also Demo Application written with Node.js which is containing Remote Code Execution Vulnerability (CVE-2023-32314) for demonstrating all addvantages of this architecture to manage Honeypot systems
Sandbox Escape
48RISCO
abrir ↗Exploit-DB
Daily Habit Tracker 1.0 - Stored Cross-Site Scripting (XSS)
Cross Site Scripting vulnerability in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via t
38RISCO
abrir ↗GitHub PoC
YangHyperData/LOGJ4_PocShell_CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗Exploit-DB
Axigen < 10.5.7 - Persistent Cross-Site Scripting
Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges
48RISCO
abrir ↗VulnCheck XDB
initial-access
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗Exploit-DB
Daily Habit Tracker 1.0 - Broken Access Control
An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php,
53RISCO
abrir ↗GitHub PoC★ 1
Exploit for CVE-2024-20767 affecting Adobe ColdFusion
ColdFusion | Improper Access Control (CWE-284)
100RISCO
abrir ↗GitHub PoC
This is my malware
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir ↗GitHub PoC★ 1
Exploit for CVE-2024-20767 affecting Adobe ColdFusion
ColdFusion | Improper Access Control (CWE-284)
100RISCO
abrir ↗GitHub PoC★ 4
Education purpose for CVE-2018-10933
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir ↗GitHub PoC★ 17
XZ Backdoor Extract(Test on Ubuntu 23.10)
Xz: malicious code in distributed source
70RISCO
abrir ↗GitHub PoC★ 1
galacticquest/cve-2024-3094-detect
Xz: malicious code in distributed source
70RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.