Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.589exploits catalogados
34.508CVEs com exploração pública
24.695testados em laboratório
13.654 exploits
GitHub PoC1
rdoix/cve-2024-21762-checker
CVE-2024-21762CRITICALsob ataqueransomware20 jun 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISCO
abrir
GitHub PoC3
This is a Python 3 version of this exploit. Hope it works!!!
CVE-2019-13272HIGHsob ataque20 jun 2024
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir
GitHub PoC10
NanoWraith/CVE-2024-29973
CVE-2024-29973CRITICAL20 jun 2024
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RISCO
abrir
GitHub PoC6
This script is a modified version of the original exploit by Daniele Scanu which exploits an unauthenticated SQL injection vulnerability in CMS Made Simple <= 2.2.10 (CVE-2019-9053).
CVE-2019-905320 jun 2024
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
GitHub PoC4
CVE-2024-29275.yaml
CVE-2024-29275CRITICAL20 jun 2024
SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code an
48RISCO
abrir
GitHub PoC1
WanLiChangChengWanLiChang/CVE-2024-29972
CVE-2024-29972CRITICAL20 jun 2024
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326
85RISCO
abrir
GitHub PoC
CVE-2022-22947 exploit script
CVE-2022-22947CRITICALsob ataque19 jun 2024
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC
MalekAlthubiany/CVE-2021-43798
CVE-2021-43798HIGHsob ataque19 jun 2024
Grafana path traversal
100RISCO
abrir
GitHub PoC72
CVE-2024-28397: js2py sandbox escape, bypass pyimport restriction.
CVE-2024-28397MEDIUM19 jun 2024
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISCO
abrir
GitHub PoC6
PoC - Prueba de Concepto de CVE-2024-4367 en conjunto al CVE-2023-38831 en un solo Script
CVE-2023-38831HIGHsob ataqueransomware19 jun 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC6
PoC - Prueba de Concepto de CVE-2024-4367 en conjunto al CVE-2023-38831 en un solo Script
CVE-2024-4367MEDIUM19 jun 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir
GitHub PoC10
POC for CVE-2024-29973
CVE-2024-29973CRITICAL19 jun 2024
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RISCO
abrir
GitHub PoC3
momika233/CVE-2024-29973
CVE-2024-29973CRITICAL19 jun 2024
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RISCO
abrir
GitHub PoC1
A small tool to create a PoC for CVE-2000-0649.
CVE-2000-064918 jun 2024
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page w
60RISCO
abrir
GitHub PoC
Redfox-Security/Digisol-DG-GR1321-s-Password-Policy-Bypass-CVE-2024-2257
CVE-2024-2257CRITICAL18 jun 2024
Password Policy Bypass Vulnerability in Digisol Router
48RISCO
abrir
GitHub PoC
jakabakos/CVE-2024-4577-PHP-CGI-argument-injection-RCE
CVE-2024-4577CRITICALsob ataqueransomware18 jun 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC1
Ivanti EPM SQL Injection Remote Code Execution Vulnerability(Optimized version based on h3)
CVE-2024-29824CRITICALsob ataque18 jun 2024
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att
100RISCO
abrir
GitHub PoC
This script is the Proof of Concept (PoC) of the CVE-2024-21413, a significant security vulnerability discovered in the Microsoft Windows Outlook having a strong 9.8 critical CVSS score. Named as #MonikerLink Bug, this vulnerability allows the attacker to execute the arbitrary code remotely on the victim's machine, thus becomes a full-fledged RCE.
CVE-2024-21413CRITICALsob ataque18 jun 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC13
CVE-2024-23692 Exploit
CVE-2024-23692CRITICALsob ataque18 jun 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISCO
abrir
GitHub PoC
WinRAR漏洞测试复现。详参:https://flowus.cn/share/a3b35db0-ab5e-4abc-b8d3-5ff284e82e7b
CVE-2023-38831HIGHsob ataqueransomware17 jun 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC10
This project is intended to serve as a proof of concept to demonstrate exploiting the vulnerability in the PDF.js (pdfjs-dist) library reported in CVE-2024-4367
CVE-2024-4367MEDIUM17 jun 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir
GitHub PoC
Expolit for CVE-2024-23334 (aiohttp >= 1.0.5> && <=3.9.1)
CVE-2024-23334MEDIUM17 jun 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISCO
abrir
GitHub PoC7
CVE-2024-23692
CVE-2024-23692CRITICALsob ataque17 jun 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISCO
abrir
GitHub PoC2
ggfzx/CVE-2024-36104
CVE-2024-36104CRITICAL17 jun 2024
Apache OFBiz: Path traversal leading to a RCE
85RISCO
abrir
GitHub PoC2
CVE-2024-4577 POC
CVE-2024-4577CRITICALsob ataqueransomware17 jun 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
The TL;DR for the learnings of Windows Vulnerability CVE-2023-28252
CVE-2023-28252HIGHsob ataqueransomware16 jun 2024
Windows Common Log File System Driver Elevation of Privilege Vulnerability
98RISCO
abrir
GitHub PoC
SolarWinds Serv-U Directory Traversal Vulnerability (CVE-2024-28995) POC
CVE-2024-28995HIGHsob ataque16 jun 2024
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISCO
abrir
GitHub PoC19
PoC for iTerm2 CVEs CVE-2024-38396 and CVE-2024-38395 which allow code execution
CVE-2024-38396CRITICAL16 jun 2024
An issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in
48RISCO
abrir
GitHub PoC
CVE-2024-23692 exp
CVE-2024-23692CRITICALsob ataque16 jun 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISCO
abrir
GitHub PoC
snapcreek_duplicator file read vulnerability https://www.cvedetails.com/cve/CVE-2020-11738/
CVE-2020-11738HIGHsob ataque15 jun 2024
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traver
100RISCO
abrir
anteriorpágina 216 / 456próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.