Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.526exploits catalogados
34.478CVEs com exploração pública
24.695testados em laboratório
13.627 exploits
GitHub PoC
guigui237/Expoitation-de-la-vuln-rabilit-CVE-2022-22965
CVE-2022-22965CRITICALsob ataque05 nov 2024
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC3
Wux Blog Editor <= 3.0.0 - Unauthenticated Arbitrary File Upload
CVE-2024-9932CRITICAL05 nov 2024
Wux Blog Editor <= 3.0.0 - Unauthenticated Arbitrary File Upload
60RISCO
abrir
GitHub PoC
1-Click Login: Passwordless Authentication 1.4.5 - Authentication Bypass via Account Takeover
CVE-2024-50478CRITICAL05 nov 2024
WordPress 1-Click Login: Passwordless Authentication plugin 1.4.5 - Broken Authentication vulnerability
48RISCO
abrir
GitHub PoC
GRÜN spendino Spendenformular <= 1.0.1 - Unauthenticated Arbitrary Options Update
CVE-2024-50476CRITICAL04 nov 2024
WordPress GRÜN spendino Spendenformular plugin <= 1.0.1 - Arbitrary Option Update to Privilege Escalation vulnerability
48RISCO
abrir
GitHub PoC
Signup Page <= 1.0 - Unauthenticated Arbitrary Options Update
CVE-2024-50475CRITICAL04 nov 2024
WordPress Signup Page plugin <= 1.0 - Arbitrary Option Update to Privilege Escalation vulnerability
48RISCO
abrir
GitHub PoC3
WP Query Console <= 1.0 - Unauthenticated Remote Code Execution
CVE-2024-50498CRITICAL04 nov 2024
WordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability
75RISCO
abrir
GitHub PoC
ahmetramazank/CVE-2024-4577
CVE-2024-4577CRITICALsob ataqueransomware03 nov 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
Roundcube mail server exploit for CVE-2024-37383 (Stored XSS)
CVE-2024-37383MEDIUMsob ataque03 nov 2024
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
85RISCO
abrir
GitHub PoC
POC firewall with rules designed to detect and block Spring4Shell vulnerability (CVE-2022-22965) exploit
CVE-2022-22965CRITICALsob ataque02 nov 2024
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC
CVE-2023-4220 Chamilo Exploit
CVE-2023-4220HIGH02 nov 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir
GitHub PoC
77Philly/CVE-2024-7456scripts
CVE-2024-7456CRITICAL02 nov 2024
SQL Injection in lunary-ai/lunary
48RISCO
abrir
GitHub PoC1
JAckLosingHeart/CVE-2024-51132-POC
CVE-2024-51132CRITICAL02 nov 2024
An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information o
48RISCO
abrir
GitHub PoC2
wp/ultimate-member - SQL Injection Vulnerability Exploit Script.
CVE-2024-1071CRITICAL01 nov 2024
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RISCO
abrir
GitHub PoC
GodOfServer/CVE-2021-3129
CVE-2021-3129CRITICALsob ataqueransomware31 out 2024
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
GitHub PoC1
puckiestyle/CVE-2024-23113
CVE-2024-23113CRITICALsob ataque31 out 2024
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RISCO
abrir
GitHub PoC
hualy13/CVE-2019-0708-Check
CVE-2019-0708CRITICALsob ataqueransomware31 out 2024
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC5
CVE-2024-51567 is a Python PoC exploit targeting an RCE vulnerability in CyberPanel v2.3.6’s upgrademysqlstatus endpoint, bypassing CSRF protections.
CVE-2024-51567CRITICALsob ataqueransomware31 out 2024
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas
100RISCO
abrir
GitHub PoC2
sxyrxyy/CVE-2024-21320-POC
CVE-2024-21320MEDIUM30 out 2024
Windows Themes Spoofing Vulnerability
38RISCO
abrir
GitHub PoC
Writing one because the one I found isn't working
CVE-2023-41425MEDIUM30 out 2024
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISCO
abrir
GitHub PoC1
chsxthwik/CVE-2024-27954
CVE-2024-27954CRITICAL30 out 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability
85RISCO
abrir
GitHub PoC2
cve-2024-38821
CVE-2024-38821CRITICAL30 out 2024
Authorization Bypass of Static Resources in WebFlux Applications
48RISCO
abrir
GitHub PoC1
CVE-2024-48359 PoC
CVE-2024-48359CRITICAL30 out 2024
Qualitor v8.24 was discovered to contain a remote code execution (RCE) vulnerability via the gridValoresPopHidden parame
48RISCO
abrir
GitHub PoC4
Automatic Plugin for WordPress < 3.92.1 Multiples Vulnerabilities
CVE-2024-27954CRITICAL29 out 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability
85RISCO
abrir
GitHub PoC23
Exploit for CyberPanel Pre-Auth RCE via Command Injection
CVE-2024-51378CRITICALsob ataqueransomware29 out 2024
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
100RISCO
abrir
GitHub PoC1
0xDTC/Prestashop-CVE-2024-34716
CVE-2024-34716CRITICAL28 out 2024
PrestaShop vulnerable to XSS via customer contact form in FO, through file upload
60RISCO
abrir
GitHub PoC
It's Proof of Concept on CVE-2024-24919-POC , i made it after it's discoverd
CVE-2024-24919HIGHsob ataqueransomware28 out 2024
Information disclosure
100RISCO
abrir
GitHub PoC2
Stack-Overflow on TendaAC8
CVE-2023-33669CRITICAL28 out 2024
Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the timeZone parameter in the sub_44db3c funct
48RISCO
abrir
GitHub PoC
CVE-2023-41425 Refurbish
CVE-2023-41425MEDIUM27 out 2024
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISCO
abrir
GitHub PoC
Refurbish Chamilo LMS CVE-2023-4220 exploit written in bash
CVE-2023-4220HIGH27 out 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir
GitHub PoC
Refurbish
CVE-2022-0944CRITICAL27 out 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISCO
abrir
anteriorpágina 193 / 455próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.