Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

82.114exploits catalogados
38.372CVEs com exploração pública
24.695testados em laboratório
82.114 exploits
GitHub PoC
m-y-mo: https://github.com/github/securitylab/tree/main/SecurityExploits/Chrome/v8/CVE-2021-30632
CVE-2021-30632HIGHsob ataque31 jan 2024
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap c
83RISCO
abrir ↗
GitHub PoC★ 2
Es una vulnerabilidad para escalar privilegios en linux.
CVE-2019-13272HIGHsob ataque31 jan 2024
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir ↗
GitHub PoC★ 1
Juniper RCE (Remote Code Execution) CVE-2023-36845 is a vulnerability that has been identified within Juniper's software. This particular flaw allows for remote code execution, meaning an attacker could run arbitrary code on a system without needing physical access to the device.
CVE-2023-36845CRITICALsob ataque30 jan 2024
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-36845CRITICALsob ataque30 jan 2024
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISCO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2023-6700HIGH30 jan 2024
Cookie Information | Free GDPR Consent Solution <= 2.0.22 - Authenticated (Subscriber+) Arbitrary Options Update
41RISCO
abrir ↗
GitHub PoC★ 19
Simple Automation script for juniper cve-2023-36845
CVE-2023-36845CRITICALsob ataque29 jan 2024
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-41892CRITICAL29 jan 2024
Craft CMS Remote Code Execution vulnerability
85RISCO
abrir ↗
GitHub PoC★ 5
CVE-2023-41892 Reverse Shell
CVE-2023-41892CRITICAL29 jan 2024
Craft CMS Remote Code Execution vulnerability
85RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2023-36845CRITICALsob ataque29 jan 2024
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISCO
abrir ↗
GitHub PoC★ 6
Jenkins POC of Arbitrary file read vulnerability through the CLI can lead to RCE
CVE-2024-23897CRITICALsob ataqueransomware29 jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗
GitHub PoC★ 1
jopraveen/CVE-2024-23897
CVE-2024-23897CRITICALsob ataqueransomware29 jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALsob ataqueransomware29 jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALsob ataqueransomware29 jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALsob ataqueransomware29 jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALsob ataqueransomware29 jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALsob ataqueransomware28 jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗
GitHub PoC
132231g/CVE-2019-3398
CVE-2019-3398HIGHsob ataque28 jan 2024
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote at
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2019-3398HIGHsob ataque28 jan 2024
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote at
100RISCO
abrir ↗
GitHub PoC
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.
CVE-2024-23897CRITICALsob ataqueransomware28 jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗
GitHub PoC★ 18
This repository presents a proof-of-concept of CVE-2024-23897
CVE-2024-23897CRITICALsob ataqueransomware28 jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-6933HIGH28 jan 2024
Better Search Replace <= 1.4.4 - Unauthenticated PHP Object Injection
68RISCO
abrir ↗
GitHub PoC★ 1
GitLab CVE-2023-7028
CVE-2023-7028CRITICALsob ataque28 jan 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISCO
abrir ↗
GitHub PoC
Samba 3.0.0 - 3.0.25rc3
CVE-2007-2447—28 jan 2024
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-38646—28 jan 2024
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALsob ataque28 jan 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISCO
abrir ↗
GitHub PoC★ 15
CVE-2024-23897 jenkins-cli
CVE-2024-23897CRITICALsob ataqueransomware27 jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗
GitHub PoC
gy741/CVE-2023-30258-setup
CVE-2023-30258CRITICAL27 jan 2024
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISCO
abrir ↗
GitHub PoC★ 6
Scanner for CVE-2024-23897 - Jenkins
CVE-2024-23897CRITICALsob ataqueransomware27 jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗
GitHub PoC★ 5
on this git you can find all information on the CVE-2024-23897
CVE-2024-23897CRITICALsob ataqueransomware27 jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗
GitHub PoC★ 86
CVE-2024-23897 - Jenkins 任意文件读取 利用工具
CVE-2024-23897CRITICALsob ataqueransomware27 jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗
← anteriorpágina 498 / 2.738próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.