Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.589exploits catalogados
34.508CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.554GitHub PoC 13.689VulnCheck XDB 8.216Nuclei 4.223Metasploit 3.464✓ só verificadosrecentespopularesrisco
13.654 exploits
GitHub PoC★ 1
rdoix/cve-2024-21762-checker
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISCO
abrir ↗GitHub PoC★ 3
This is a Python 3 version of this exploit. Hope it works!!!
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir ↗GitHub PoC★ 10
NanoWraith/CVE-2024-29973
** UNSUPPORTED WHEN ASSIGNED **
The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RISCO
abrir ↗GitHub PoC★ 6
This script is a modified version of the original exploit by Daniele Scanu which exploits an unauthenticated SQL injection vulnerability in CMS Made Simple <= 2.2.10 (CVE-2019-9053).
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir ↗GitHub PoC★ 4
CVE-2024-29275.yaml
SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code an
48RISCO
abrir ↗GitHub PoC★ 1
WanLiChangChengWanLiChang/CVE-2024-29972
** UNSUPPORTED WHEN ASSIGNED **
The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326
85RISCO
abrir ↗GitHub PoC
CVE-2022-22947 exploit script
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir ↗GitHub PoC★ 72
CVE-2024-28397: js2py sandbox escape, bypass pyimport restriction.
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISCO
abrir ↗GitHub PoC★ 6
PoC - Prueba de Concepto de CVE-2024-4367 en conjunto al CVE-2023-38831 en un solo Script
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir ↗GitHub PoC★ 6
PoC - Prueba de Concepto de CVE-2024-4367 en conjunto al CVE-2023-38831 en un solo Script
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir ↗GitHub PoC★ 10
POC for CVE-2024-29973
** UNSUPPORTED WHEN ASSIGNED **
The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RISCO
abrir ↗GitHub PoC★ 3
momika233/CVE-2024-29973
** UNSUPPORTED WHEN ASSIGNED **
The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RISCO
abrir ↗GitHub PoC★ 1
A small tool to create a PoC for CVE-2000-0649.
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page w
60RISCO
abrir ↗GitHub PoC
Redfox-Security/Digisol-DG-GR1321-s-Password-Policy-Bypass-CVE-2024-2257
Password Policy Bypass Vulnerability in Digisol Router
48RISCO
abrir ↗GitHub PoC
jakabakos/CVE-2024-4577-PHP-CGI-argument-injection-RCE
Argument Injection in PHP-CGI
100RISCO
abrir ↗GitHub PoC★ 1
Ivanti EPM SQL Injection Remote Code Execution Vulnerability(Optimized version based on h3)
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att
100RISCO
abrir ↗GitHub PoC
This script is the Proof of Concept (PoC) of the CVE-2024-21413, a significant security vulnerability discovered in the Microsoft Windows Outlook having a strong 9.8 critical CVSS score. Named as #MonikerLink Bug, this vulnerability allows the attacker to execute the arbitrary code remotely on the victim's machine, thus becomes a full-fledged RCE.
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC★ 13
CVE-2024-23692 Exploit
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISCO
abrir ↗GitHub PoC
WinRAR漏洞测试复现。详参:https://flowus.cn/share/a3b35db0-ab5e-4abc-b8d3-5ff284e82e7b
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir ↗GitHub PoC★ 10
This project is intended to serve as a proof of concept to demonstrate exploiting the vulnerability in the PDF.js (pdfjs-dist) library reported in CVE-2024-4367
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir ↗GitHub PoC
Expolit for CVE-2024-23334 (aiohttp >= 1.0.5> && <=3.9.1)
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISCO
abrir ↗GitHub PoC
The TL;DR for the learnings of Windows Vulnerability CVE-2023-28252
Windows Common Log File System Driver Elevation of Privilege Vulnerability
98RISCO
abrir ↗GitHub PoC
SolarWinds Serv-U Directory Traversal Vulnerability (CVE-2024-28995) POC
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISCO
abrir ↗GitHub PoC★ 19
PoC for iTerm2 CVEs CVE-2024-38396 and CVE-2024-38395 which allow code execution
An issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in
48RISCO
abrir ↗GitHub PoC
snapcreek_duplicator file read vulnerability https://www.cvedetails.com/cve/CVE-2020-11738/
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traver
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.