Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.652exploits catalogados
34.545CVEs com exploração pública
24.695testados em laboratório
13.708 exploits
GitHub PoC
semcms存在SQL注入(CVE-2024-25422 )
CVE-2024-25422CRITICAL04 fev 2024
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive info
48RISCO
abrir
GitHub PoC
Shellshock exploit (CVE-2014-6271)
CVE-2014-6271CRITICALsob ataque04 fev 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC5
Exploit for CVE-2019-2215 (bad binder) for Huawei P20 Lite
CVE-2019-2215HIGHsob ataque04 fev 2024
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISCO
abrir
GitHub PoC1
Triggering the famous libweb 0day vuln with libfuzzer
CVE-2023-4863HIGHsob ataque04 fev 2024
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RISCO
abrir
GitHub PoC
CharonDefalt/Juniper-exploit-CVE-2023-36845
CVE-2023-36845CRITICALsob ataque03 fev 2024
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISCO
abrir
GitHub PoC27
CVE-2024-21893 to CVE-2024-21887 Exploit Toolkit
CVE-2024-21893HIGHsob ataqueransomware03 fev 2024
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy
100RISCO
abrir
GitHub PoC
CVE-2023-22527 Batch scanning
CVE-2023-22527CRITICALsob ataqueransomware02 fev 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RISCO
abrir
GitHub PoC94
CVE-2024-21893: SSRF Vulnerability in Ivanti Connect Secure
CVE-2024-21893HIGHsob ataqueransomware02 fev 2024
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy
100RISCO
abrir
GitHub PoC
Trinadh465/external_zlib_android-6.0.1_r22_CVE-2022-37434
CVE-2022-37434CRITICAL02 fev 2024
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header
53RISCO
abrir
GitHub PoC
Trinadh465/external_zlib_CVE-2022-37434
CVE-2022-37434CRITICAL02 fev 2024
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header
53RISCO
abrir
GitHub PoC
cyb3rzest/Juniper-Bug-Automation-CVE-2023-36845
CVE-2023-36845CRITICALsob ataque01 fev 2024
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISCO
abrir
GitHub PoC1
PoC for Jenkins CVE-2024-23897
CVE-2024-23897CRITICALsob ataqueransomware01 fev 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
GitHub PoC1
POC about Web3 – Crypto wallet Login & NFT token gating < 3.0.0 - Authentication Bypass Wordpress plugin
CVE-2023-6036CRITICAL31 jan 2024
Web3 – Crypto wallet Login & NFT token gating < 3.0.0 - Authentication Bypass
48RISCO
abrir
GitHub PoC
m-y-mo: https://github.com/github/securitylab/tree/main/SecurityExploits/Chrome/v8/CVE-2021-30632
CVE-2021-30632HIGHsob ataque31 jan 2024
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap c
83RISCO
abrir
GitHub PoC2
Es una vulnerabilidad para escalar privilegios en linux.
CVE-2019-13272HIGHsob ataque31 jan 2024
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir
GitHub PoC1
Juniper RCE (Remote Code Execution) CVE-2023-36845 is a vulnerability that has been identified within Juniper's software. This particular flaw allows for remote code execution, meaning an attacker could run arbitrary code on a system without needing physical access to the device.
CVE-2023-36845CRITICALsob ataque30 jan 2024
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISCO
abrir
GitHub PoC1
jopraveen/CVE-2024-23897
CVE-2024-23897CRITICALsob ataqueransomware29 jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
GitHub PoC5
CVE-2023-41892 Reverse Shell
CVE-2023-41892CRITICAL29 jan 2024
Craft CMS Remote Code Execution vulnerability
85RISCO
abrir
GitHub PoC5
Jenkins POC of Arbitrary file read vulnerability through the CLI can lead to RCE
CVE-2024-23897CRITICALsob ataqueransomware29 jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
GitHub PoC19
Simple Automation script for juniper cve-2023-36845
CVE-2023-36845CRITICALsob ataque29 jan 2024
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISCO
abrir
GitHub PoC
132231g/CVE-2019-3398
CVE-2019-3398HIGHsob ataque28 jan 2024
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote at
100RISCO
abrir
GitHub PoC1
GitLab CVE-2023-7028
CVE-2023-7028CRITICALsob ataque28 jan 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISCO
abrir
GitHub PoC
Samba 3.0.0 - 3.0.25rc3
CVE-2007-244728 jan 2024
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir
GitHub PoC17
This repository presents a proof-of-concept of CVE-2024-23897
CVE-2024-23897CRITICALsob ataqueransomware28 jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
GitHub PoC
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.
CVE-2024-23897CRITICALsob ataqueransomware28 jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
GitHub PoC4
on this git you can find all information on the CVE-2024-23897
CVE-2024-23897CRITICALsob ataqueransomware27 jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
GitHub PoC5
Scanner for CVE-2024-23897 - Jenkins
CVE-2024-23897CRITICALsob ataqueransomware27 jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
GitHub PoC15
CVE-2024-23897 jenkins-cli
CVE-2024-23897CRITICALsob ataqueransomware27 jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
GitHub PoC86
CVE-2024-23897 - Jenkins 任意文件读取 利用工具
CVE-2024-23897CRITICALsob ataqueransomware27 jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
GitHub PoC
FancySauce/PwnKit-CVE-2021-4034
CVE-2021-4034HIGHsob ataque27 jan 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
anteriorpágina 242 / 457próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.