Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.589exploits catalogados
34.508CVEs com exploração pública
24.695testados em laboratório
13.689 exploits
GitHub PoC
The TL;DR for the learnings of Windows Vulnerability CVE-2023-28252
CVE-2023-28252HIGHsob ataqueransomware16 jun 2024
Windows Common Log File System Driver Elevation of Privilege Vulnerability
98RISCO
abrir
GitHub PoC19
PoC for iTerm2 CVEs CVE-2024-38396 and CVE-2024-38395 which allow code execution
CVE-2024-38396CRITICAL16 jun 2024
An issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in
48RISCO
abrir
GitHub PoC
SolarWinds Serv-U Directory Traversal Vulnerability (CVE-2024-28995) POC
CVE-2024-28995HIGHsob ataque16 jun 2024
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISCO
abrir
GitHub PoC
CVE-2024-23692 exp
CVE-2024-23692CRITICALsob ataque16 jun 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISCO
abrir
GitHub PoC
Shadow-Spinner/CVE-2012-2982_python
CVE-2012-298215 jun 2024
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISCO
abrir
GitHub PoC
snapcreek_duplicator file read vulnerability https://www.cvedetails.com/cve/CVE-2020-11738/
CVE-2020-11738HIGHsob ataque15 jun 2024
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traver
100RISCO
abrir
GitHub PoC13
Argument injection vulnerability in PHP
CVE-2024-4577CRITICALsob ataqueransomware15 jun 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
cve-2024/CVE-2024-27956-RCE
CVE-2024-27956CRITICAL14 jun 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISCO
abrir
GitHub PoC2
ggfzx/CVE-2024-28995
CVE-2024-28995HIGHsob ataque14 jun 2024
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISCO
abrir
GitHub PoC14
CVE-2024-28995 POC Vulnerability Scanner
CVE-2024-28995HIGHsob ataque14 jun 2024
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISCO
abrir
GitHub PoC1
huseyinstif/CVE-2024-28995-Nuclei-Template
CVE-2024-28995HIGHsob ataque14 jun 2024
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISCO
abrir
GitHub PoC2
Exploit for CVE-2024-28995
CVE-2024-28995HIGHsob ataque14 jun 2024
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISCO
abrir
GitHub PoC
cve-2024/CVE-2024-4898-Poc
CVE-2024-4898CRITICAL14 jun 2024
InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.38 - Missing Authorization to Unauthenticated API setup/Arbitrary Options Update/Administrative User Creation
63RISCO
abrir
GitHub PoC
cve-2024/CVE-2024-4295-Poc
CVE-2024-4295CRITICAL14 jun 2024
Email Subscribers by Icegram Express <= 5.7.20 - Unauthenticated SQL Injection via hash
68RISCO
abrir
GitHub PoC
TikiWiki CMS Groupware v8.3 - Open Redirect
CVE-2012-532114 jun 2024
tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frame
43RISCO
abrir
GitHub PoC1
qinzhu111/uWSGI-CVE-2018-7490-POC
CVE-2018-749014 jun 2024
uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversa
50RISCO
abrir
GitHub PoC
Rejetto HFS (HTTP File Server) is a simple web file server that facilitates file sharing over a network or the internet.
CVE-2024-23692CRITICALsob ataque14 jun 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISCO
abrir
GitHub PoC
Ieakd/0day-POC-for-CVE-2024-27173
CVE-2024-27173CRITICAL14 jun 2024
insecure upload
48RISCO
abrir
GitHub PoC
CVE-2024-28995 PoC
CVE-2024-28995HIGHsob ataque14 jun 2024
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISCO
abrir
GitHub PoC20
PoC for the Veeam Recovery Orchestrator Authentication CVE-2024-29855
CVE-2024-29855CRITICAL13 jun 2024
Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator
53RISCO
abrir
GitHub PoC16
Unauthenticated RCE Flaw in Rejetto HTTP File Server (CVE-2024-23692)
CVE-2024-23692CRITICALsob ataque13 jun 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISCO
abrir
GitHub PoC4
Fixed and minimalist PoC of the CVE-2024-4577
CVE-2024-4577CRITICALsob ataqueransomware13 jun 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
Users of JetBrains IDEs at risk of GitHub access token compromise (CVE-2024-37051)
CVE-2024-37051CRITICAL13 jun 2024
GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ
48RISCO
abrir
GitHub PoC
Valve Press - CVE-2024-27956-RCE - SQL Injection
CVE-2024-27956CRITICAL13 jun 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISCO
abrir
GitHub PoC
Fix for CVE-2018-15473
CVE-2018-15473MEDIUM13 jun 2024
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC12
PDF.js是由Mozilla维护的基于JavaScript的PDF查看器。此漏洞允许攻击者在打开恶意 PDF 文件后立即执行任意 JavaScript 代码。这会影响所有 Firefox 用户 (<126),因为 Firefox 使用 PDF.js 来显示 PDF 文件,但也严重影响了许多基于 Web 和 Electron 的应用程序,这些应用程序(间接)使用 PDF.js 进行预览功能。
CVE-2024-4367MEDIUM13 jun 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir
GitHub PoC11
vanboomqi/CVE-2024-23692
CVE-2024-23692CRITICALsob ataque13 jun 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISCO
abrir
GitHub PoC
WanLiChangChengWanLiChang/CVE-2024-23692-RCE
CVE-2024-23692CRITICALsob ataque13 jun 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISCO
abrir
GitHub PoC
raytran54/CVE-2018-7600
CVE-2018-7600CRITICALsob ataqueransomware12 jun 2024
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC
Rejetto http File Server 2.3.x (Reverse shell)
CVE-2014-6287CRITICALsob ataque12 jun 2024
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir
anteriorpágina 218 / 457próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.