Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.652exploits catalogados
34.545CVEs com exploração pública
24.695testados em laboratório
13.689 exploits
GitHub PoC39
hd3s5aa/CVE-2023-21674
CVE-2023-21674HIGHsob ataque07 mar 2024
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
83RISCO
abrir
GitHub PoC4
Phamchie/CVE-2023-3047
CVE-2023-3047CRITICAL07 mar 2024
SQLi in TMT's Lockcell
48RISCO
abrir
GitHub PoC
A PoC for CVE-2024-27198 written in Go
CVE-2024-27198CRITICALsob ataqueransomware07 mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir
GitHub PoC157
CVE-2024-27198 & CVE-2024-27199 Authentication Bypass --> RCE in JetBrains TeamCity Pre-2023.11.4
CVE-2024-27198CRITICALsob ataqueransomware06 mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir
GitHub PoC17
Progress OpenEdge Authentication Bypass
CVE-2024-1403CRITICAL06 mar 2024
Authentication Bypass in OpenEdge Authentication Gateway and AdminServer
48RISCO
abrir
GitHub PoC
Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c
CVE-2014-6287CRITICALsob ataque06 mar 2024
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir
GitHub PoC4
PoC Script for CVE-2024-25832: Exploit chain reverse shell, information disclosure (root password leak) + unrestricted file upload in DataCube3
CVE-2024-25832HIGH06 mar 2024
F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to
46RISCO
abrir
GitHub PoC
Shubham-2k1/Exploit-CVE-2011-2523
CVE-2011-252305 mar 2024
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
GitHub PoC37
Exploit for CVE-2024-27198 - TeamCity Server
CVE-2024-27198CRITICALsob ataqueransomware05 mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir
GitHub PoC43
ActiveMQ RCE (CVE-2023-46604) 回显利用工具
CVE-2023-46604CRITICALsob ataqueransomware05 mar 2024
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISCO
abrir
GitHub PoC1
This script will help you to scan for smbGhost vulnerability(CVE-2020-0796)
CVE-2020-0796CRITICALsob ataqueransomware04 mar 2024
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC3
CVE-2024-1071 with Docker
CVE-2024-1071CRITICAL04 mar 2024
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RISCO
abrir
GitHub PoC4
A PoC exploit for CVE-2021-43798 - Grafana Directory Traversal
CVE-2021-43798HIGHsob ataque04 mar 2024
Grafana path traversal
100RISCO
abrir
GitHub PoC6
Three go-exploits exploiting CVE-2023-22527 to execute arbitrary code in memory
CVE-2023-22527CRITICALsob ataqueransomware04 mar 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RISCO
abrir
GitHub PoC36
Proof of Concept for Authentication Bypass in JetBrains TeamCity Pre-2023.11.4
CVE-2024-27198CRITICALsob ataqueransomware04 mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir
GitHub PoC
RxRCoder/CVE-2023-2437
CVE-2023-2437CRITICAL02 mar 2024
UserPro <= 5.1.1 - Authentication Bypass to Administrator
63RISCO
abrir
GitHub PoC2
PoC for CVE-2024-1512 in MasterStudy LMS WordPress Plugin.
CVE-2024-1512CRITICAL01 mar 2024
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.5 - Unauthenticated SQL Injection
85RISCO
abrir
GitHub PoC2
abian2/CVE-2024-23652
CVE-2024-23652CRITICAL01 mar 2024
BuildKit possible host system access from mount stub cleaner
48RISCO
abrir
GitHub PoC3
(Mirorring)
CVE-2024-1651CRITICAL29 fev 2024
Torrentpier 2.4.1 - RCE
60RISCO
abrir
GitHub PoC3
(Mirorring)
CVE-2024-25600CRITICAL29 fev 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir
GitHub PoC2
dshabani96/CVE-2024-21413
CVE-2024-21413CRITICALsob ataque29 fev 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
letsr00t/CVE-2023-0386
CVE-2023-0386HIGHsob ataque29 fev 2024
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISCO
abrir
GitHub PoC
J3Ss0u/CVE-2023-41993
CVE-2023-41993HIGHsob ataque28 fev 2024
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to
76RISCO
abrir
GitHub PoC2
jakabakos/CVE-2023-39362-cacti-snmp-command-injection-poc
CVE-2023-39362HIGH28 fev 2024
Authenticated command injection in SNMP options of a Device
63RISCO
abrir
GitHub PoC6
CVE-2024-23334
CVE-2024-23334MEDIUM28 fev 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISCO
abrir
GitHub PoC107
Safely detect whether a FortiGate SSL VPN is vulnerable to CVE-2024-21762
CVE-2024-21762CRITICALsob ataqueransomware28 fev 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISCO
abrir
GitHub PoC
G01d3nW01f/CVE-2022-44877
CVE-2022-44877CRITICALsob ataque27 fev 2024
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISCO
abrir
GitHub PoC
letsr00t/CVE-2021-22555
CVE-2021-22555HIGHsob ataque27 fev 2024
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISCO
abrir
GitHub PoC8
Ultimate Member Unauthorized Database Access / SQLi
CVE-2024-1071CRITICAL27 fev 2024
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RISCO
abrir
GitHub PoC1
Exploit for CVE-2022-30525
CVE-2022-30525CRITICALsob ataque27 fev 2024
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RISCO
abrir
anteriorpágina 238 / 457próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.