Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.526exploits catalogados
34.478CVEs com exploração pública
24.695testados em laboratório
13.627 exploits
GitHub PoC
In December 2021, the world of cybersecurity was shaken by the discovery of the Log4Shell vulnerability (CVE-2021-44228), embedded within the widely-used Apache Log4j library. With a CVSS score of 10
CVE-2021-44228CRITICALsob ataqueransomware10 nov 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC48
POC - CVE-2024–10914- Command Injection Vulnerability in `name` parameter for D-Link NAS
CVE-2024-10914CRITICAL10 nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir
GitHub PoC1
oxapavan/CVE-2023-4220-HTB-PermX
CVE-2023-4220HIGH10 nov 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir
GitHub PoC1
Debug Tool <= 2.2 - Unauthenticated Arbitrary File Creation
CVE-2024-10586CRITICAL10 nov 2024
Debug Tool <= 2.2 - Unauthenticated Arbitrary File Creation
48RISCO
abrir
GitHub PoC
Automatic Translation <= 1.0.4 - Unauthenticated Arbitrary File Upload
CVE-2024-50493CRITICAL10 nov 2024
WordPress Automatic Translation plugin <= 1.0.4 - Arbitrary File Upload vulnerability
48RISCO
abrir
GitHub PoC
To test elasticsearch vulnerabillity on newer version of debian
CVE-2015-1427CRITICALsob ataque10 nov 2024
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RISCO
abrir
GitHub PoC1
Proof of concept of the parh traversal in python AioHTTP library =< 3.9.1
CVE-2024-23334MEDIUM09 nov 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISCO
abrir
GitHub PoC
Ajar in5 Embed <= 3.1.3 - Unauthenticated Arbitrary File Upload
CVE-2024-50473CRITICAL09 nov 2024
WordPress Ajar in5 Embed plugin <= 3.1.3 - Arbitrary File Upload vulnerability
48RISCO
abrir
GitHub PoC
sea-middle/cve-2023-25813
CVE-2023-25813CRITICAL09 nov 2024
SQL Injection via replacements in sequelize
48RISCO
abrir
GitHub PoC3
WP Sessions Time Monitoring Full Automatic <= 1.0.9 - Unauthenticated SQL Injection
CVE-2024-49681CRITICAL09 nov 2024
WordPress WP Sessions Time Monitoring Full Automatic plugin <= 1.0.9 - SQL Injection vulnerability
48RISCO
abrir
GitHub PoC14
Exploit for cve-2024-10914: D-Link DNS-320, DNS-320LW, DNS-325, DNS-340L Version 1.00, Version 1.01.0914.2012, Version 1.01, Version 1.02, Version 1.08 Command Injection
CVE-2024-10914CRITICAL09 nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir
GitHub PoC
WP Dropbox Dropins <= 1.0 - Unauthenticated Arbitrary File Upload
CVE-2024-49607CRITICAL09 nov 2024
WordPress WP Dropbox Dropins plugin <= 1.0 - Arbitrary File Upload vulnerability
48RISCO
abrir
GitHub PoC
WPLMS Learning Management System for WordPress <= 4.962 – Unauthenticated Arbitrary File Read and Deletion
CVE-2024-10470CRITICAL08 nov 2024
WPLMS Learning Management System for WordPress <= 4.962 - Unauthenticated Arbitrary File Read and Deletion
60RISCO
abrir
GitHub PoC
Stacks Mobile App Builder <= 5.2.3 - Authentication Bypass via Account Takeover
CVE-2024-50477CRITICAL08 nov 2024
WordPress Stacks Mobile App Builder plugin <= 5.2.3 - Account Takeover vulnerability
63RISCO
abrir
GitHub PoC
CVE-2024-4898 InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.38 - Missing Authorization to Unauthenticated API setup/Arbitrary Options Update/Administrative User Creation
CVE-2024-4898CRITICAL08 nov 2024
InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.38 - Missing Authorization to Unauthenticated API setup/Arbitrary Options Update/Administrative User Creation
63RISCO
abrir
GitHub PoC
SurveyJS: Drag & Drop WordPress Form Builder <= 1.9.136 - Authenticated (Subscriber+) Arbitrary File Upload
CVE-2024-50427CRITICAL08 nov 2024
WordPress SurveyJS plugin <= 1.9.136 - Arbitrary File Upload vulnerability
48RISCO
abrir
GitHub PoC
Exploit Development for CVE-2023-6553 on Backup Plugin in Wordpress
CVE-2023-6553CRITICAL07 nov 2024
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RISCO
abrir
GitHub PoC
CVE-2023-25813 Vulnerability Reproduction - SQL Injection in Sequelize
CVE-2023-25813CRITICAL07 nov 2024
SQL Injection via replacements in sequelize
48RISCO
abrir
GitHub PoC98
Fortinet Fortimanager Unauthenticated Remote Code Execution AKA FortiJump CVE-2024-47575
CVE-2024-47575CRITICALsob ataque07 nov 2024
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2
100RISCO
abrir
GitHub PoC1
cbyerpanel rce exploit
CVE-2024-51567CRITICALsob ataqueransomware07 nov 2024
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas
100RISCO
abrir
GitHub PoC1
AliHj98/cve-2024-38063-Anonyvader
CVE-2024-38063CRITICAL07 nov 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC1
0xR00/CVE-2024-23334
CVE-2024-23334MEDIUM07 nov 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISCO
abrir
GitHub PoC25
CVE-2024-4577 RCE PoC
CVE-2024-4577CRITICALsob ataqueransomware06 nov 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
pbj2647/CVE-2023-25813
CVE-2023-25813CRITICAL06 nov 2024
SQL Injection via replacements in sequelize
48RISCO
abrir
GitHub PoC6
WP REST API FNS <= 1.0.0 - Privilege Escalation
CVE-2024-49328CRITICAL06 nov 2024
WordPress WP REST API FNS Plugin plugin <= 1.0.0 - Account Takeover vulnerability
48RISCO
abrir
GitHub PoC
pedrochalegre7/CVE-2024-4367-pdf-sample
CVE-2024-4367MEDIUM06 nov 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir
GitHub PoC
guigui237/Expoitation-de-la-vuln-rabilit-CVE-2022-22965
CVE-2022-22965CRITICALsob ataque05 nov 2024
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC
WatchTowerHQ <= 3.10.1 - Authentication Bypass to Administrator due to Missing Empty Value Check
CVE-2024-9933CRITICAL05 nov 2024
WatchTowerHQ <= 3.10.1 - Authentication Bypass to Administrator due to Missing Empty Value Check
48RISCO
abrir
GitHub PoC
1-Click Login: Passwordless Authentication 1.4.5 - Authentication Bypass via Account Takeover
CVE-2024-50478CRITICAL05 nov 2024
WordPress 1-Click Login: Passwordless Authentication plugin 1.4.5 - Broken Authentication vulnerability
48RISCO
abrir
GitHub PoC
Woocommerce Product Design <= 1.0.0 - Unauthenticated Arbitrary File Upload
CVE-2024-50482CRITICAL05 nov 2024
WordPress Woocommerce Product Design plugin <= 1.0.0 - Arbitrary File Upload vulnerability
48RISCO
abrir
anteriorpágina 192 / 455próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.