Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.526exploits catalogados
34.478CVEs com exploração pública
24.695testados em laboratório
13.654 exploits
GitHub PoC23
LiteSpeed Cache Privilege Escalation PoC
CVE-2024-28000CRITICAL24 ago 2024
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISCO
abrir
GitHub PoC
CVE-2023-4220 PoC Chamilo RCE
CVE-2023-4220HIGH24 ago 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir
GitHub PoC695
poc for CVE-2024-38063 (RCE in tcpip.sys)
CVE-2024-38063CRITICAL24 ago 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC3
Telerik Report Server deserialization and authentication bypass exploit chain for CVE-2024-4358/CVE-2024-1800
CVE-2024-4358CRITICALsob ataque24 ago 2024
Registration Authentication Bypass Vulnerability
100RISCO
abrir
GitHub PoC4
SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.
CVE-2024-28995HIGHsob ataque24 ago 2024
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISCO
abrir
GitHub PoC1
Python exploit for Chamilo Unrestricted File Upload Vuln - CVE-2023-4220
CVE-2023-4220HIGH24 ago 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir
GitHub PoC2
CVE-2024-38063 research so you don't have to.
CVE-2024-38063CRITICAL23 ago 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC19
Scripts for Analysis of a RCE in Moodle Calculated Questions (CVE-2024-43425)
CVE-2024-43425HIGH23 ago 2024
Moodle: remote code execution via calculated question types
78RISCO
abrir
GitHub PoC2
Windows远程桌面授权服务CVE-2024-38077检测工具
CVE-2024-38077CRITICAL23 ago 2024
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC
Research
CVE-2023-41425MEDIUM22 ago 2024
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISCO
abrir
GitHub PoC9
CVE-2024-38856 Exploit
CVE-2024-38856HIGHsob ataque22 ago 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISCO
abrir
GitHub PoC1
CVE-2023-7028 POC && Exploit
CVE-2023-7028CRITICALsob ataque21 ago 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISCO
abrir
GitHub PoC
exr viewer
CVE-2023-50245CRITICAL21 ago 2024
OpenEXR-viewer memory overflow vulnerability
48RISCO
abrir
GitHub PoC3
Proof-of-Concept for CVE-2024-5932 GiveWP PHP Object Injection
CVE-2024-8353CRITICAL21 ago 2024
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection
68RISCO
abrir
GitHub PoC
MLflow LFI/RFI Vulnerability -CVE-2023-1177 - Reproduced
CVE-2023-1177CRITICAL21 ago 2024
Path Traversal: '\..\filename' in mlflow/mlflow
75RISCO
abrir
GitHub PoC
A PowerShell script to temporarily mitigate the CVE-2024-38063 vulnerability by disabling IPv6 on Windows systems. This workaround modifies the registry to reduce the risk of exploitation without needing the immediate installation of the official Microsoft KB update. Intended as a temporary fix
CVE-2024-38063CRITICAL20 ago 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC
A Bash script to mitigate the CVE-2024-6387 vulnerability in OpenSSH by providing an option to upgrade to a secure version or apply a temporary workaround. This repository helps secure systems against potential remote code execution risks associated with affected OpenSSH versions.
CVE-2024-6387HIGH20 ago 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir
GitHub PoC
Unauthenticated Remote Code Execution – Bricks
CVE-2024-25600CRITICAL20 ago 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir
GitHub PoC
Reproducing the following CVEs with dockerfile:CVE-2024-33644 CVE-2024-34370 CVE-2024-22120
CVE-2024-33644CRITICAL20 ago 2024
WordPress Customify Site Library plugin <= 0.0.9 - Remote Code Execution (RCE) vulnerability
48RISCO
abrir
GitHub PoC25
PHP CGI Argument Injection (CVE-2024-4577) RCE
CVE-2024-4577CRITICALsob ataqueransomware20 ago 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
CVE-2023-29384 Auto Exploiter on WordPress Job Board and Recruitment Plugin
CVE-2023-29384CRITICAL20 ago 2024
WordPress WordPress Job Board and Recruitment Plugin – JobWP Plugin <= 2.0 is vulnerable to Arbitrary File Upload
48RISCO
abrir
GitHub PoC
RedTeam-Rediron/CVE-2020-1938
CVE-2020-1938CRITICALsob ataque20 ago 2024
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
GitHub PoC
adobe commerce
CVE-2024-34102CRITICALsob ataque19 ago 2024
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir
GitHub PoC
s1d6point7bugcrowd/CVE-2024-6387-Race-Condition-in-Signal-Handling-for-OpenSSH
CVE-2024-6387HIGH19 ago 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir
GitHub PoC
dweger-scripts/CVE-2024-38063-Remediation
CVE-2024-38063CRITICAL19 ago 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC
PoC
CVE-2022-27925HIGHsob ataqueransomware19 ago 2024
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISCO
abrir
GitHub PoC1
jeyabalaji711/CVE-2024-42919
CVE-2024-42919CRITICAL19 ago 2024
eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.
48RISCO
abrir
GitHub PoC1
anmolksachan/CVE-2020-2733
CVE-2020-2733CRITICAL19 ago 2024
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics)
68RISCO
abrir
GitHub PoC
WTN-arny/CVE-2024-37085
CVE-2024-37085MEDIUMsob ataqueransomware18 ago 2024
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) per
68RISCO
abrir
GitHub PoC1
Exploit for CVE-2024-38856 affecting Apache OFBiz versions before 18.12.15
CVE-2024-38856HIGHsob ataque18 ago 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISCO
abrir
anteriorpágina 204 / 456próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.