Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.526exploits catalogados
34.478CVEs com exploração pública
24.695testados em laboratório
13.648 exploits
GitHub PoC5
longhoangth18/CVE-2024-4577
CVE-2024-4577CRITICALsob ataqueransomware14 out 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
shanglyu/CVE-2024-1698
CVE-2024-1698CRITICAL14 out 2024
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RISCO
abrir
GitHub PoC
kkhackz0013/CVE-2024-36401
CVE-2024-36401CRITICALsob ataque14 out 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir
GitHub PoC
a proof of concept of the CVE-2024-27198 which infect jetbrains teamCity
CVE-2024-27198CRITICALsob ataqueransomware14 out 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir
GitHub PoC
Gilospy/CVE-2022-26134
CVE-2022-26134CRITICALsob ataqueransomware13 out 2024
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC1
PoC for RCE in SQLPad (CVE-2022-0944)
CVE-2022-0944CRITICAL13 out 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISCO
abrir
GitHub PoC
lemonadern/poc-cve-2019-14287
CVE-2019-1428713 out 2024
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISCO
abrir
GitHub PoC2
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields'
CVE-2024-8529CRITICAL12 out 2024
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields'
68RISCO
abrir
GitHub PoC
intel365/CVE-2024-7593
CVE-2024-7593CRITICALsob ataque12 out 2024
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remo
100RISCO
abrir
GitHub PoC1
CVE-2021-40539:ADSelfService Plus RCE漏洞
CVE-2021-40539CRITICALsob ataqueransomware12 out 2024
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RISCO
abrir
GitHub PoC
CVE-2021-40539:ADSelfService Plus RCE漏洞
CVE-2021-40539CRITICALsob ataqueransomware12 out 2024
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RISCO
abrir
GitHub PoC1
OxLmahdi/cve-2024-5932
CVE-2024-5932CRITICAL11 out 2024
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RISCO
abrir
GitHub PoC1
Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
CVE-2024-9707CRITICAL11 out 2024
Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
63RISCO
abrir
GitHub PoC1
test_private_CVE
CVE-2024-23113CRITICALsob ataque11 out 2024
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RISCO
abrir
GitHub PoC
Checkpoint SQL Injection via Time-Based Attack (CVE-2024-9465)
CVE-2024-9465CRITICALsob ataque11 out 2024
Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure
100RISCO
abrir
GitHub PoC2
intel365/CVE-2024-29973
CVE-2024-29973CRITICAL10 out 2024
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RISCO
abrir
GitHub PoC5
is a PoC tool designed to exploit insecurely exposed debug logs from WordPress sites and extract session cookies
CVE-2024-44000CRITICAL10 out 2024
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RISCO
abrir
GitHub PoC6
p33d/CVE-2024-9441
CVE-2024-9441CRITICAL10 out 2024
Linear eMerge e3-Series Forgot Password Command Injection
60RISCO
abrir
GitHub PoC31
Proof of Concept Exploit for CVE-2024-9465
CVE-2024-9465CRITICALsob ataque09 out 2024
Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure
100RISCO
abrir
GitHub PoC17
CVE-2024-38077: Remote Code Execution Vulnerability in Windows Remote Desktop Licensing Service
CVE-2024-38077CRITICAL09 out 2024
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC27
Unauthenticated Remote Code Execution via Angular-Base64-Upload Library
CVE-2024-42640CRITICAL09 out 2024
angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Explo
75RISCO
abrir
GitHub PoC2
intel365/CVE-2024-2876
CVE-2024-2876CRITICAL09 out 2024
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RISCO
abrir
GitHub PoC44
Proof of Concept Exploit for CVE-2024-9464
CVE-2024-9464CRITICAL09 out 2024
Expedition: Authenticated OS Command Injection Vulnerability Leads to Firewall Admin Credential Disclosure
70RISCO
abrir
GitHub PoC1
intel365/CVE-2024-24919
CVE-2024-24919HIGHsob ataqueransomware09 out 2024
Information disclosure
100RISCO
abrir
GitHub PoC3
is a PoC tool that targets a vulnerability in the TeamCity server (CVE-2024-27198)
CVE-2024-27198CRITICALsob ataqueransomware09 out 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir
GitHub PoC
The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attac
CVE-2024-1207CRITICAL08 out 2024
Booking Calendar <= 9.9 - Unauthenticated SQL Injection
48RISCO
abrir
GitHub PoC1
Proof of Concept for the Log4Shell vulnerability (CVE-2021-44228), developed as part of the coursework for the curricular unit TPAS in the Master's degree in Information Security at FCUP.
CVE-2021-44228CRITICALsob ataqueransomware08 out 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
bka/magento-cve-2024-34102-exploit-cosmicstring
CVE-2024-34102CRITICALsob ataque08 out 2024
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir
GitHub PoC
wargame, CVE-2024-4367
CVE-2024-4367MEDIUM08 out 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir
GitHub PoC1
Performs an IPv6 vulnerability scan and packet flood attack on specified targets. The script simulates a SYN flood and ICMP flood attack and optionally sends exploit packets.
CVE-2024-38063CRITICAL08 out 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir
anteriorpágina 196 / 455próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.