Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.402exploits catalogados
34.906CVEs com exploração pública
24.695testados em laboratório
76.107 exploits
GitHub PoC3
CVE-2023-40028 PoC Exploit
CVE-2023-40028MEDIUM28 dez 2024
Arbitrary file read via symlinks in Ghost
45RISCO
abrir
GitHub PoC
Citrix Virtual Apps and Desktops (XEN) Unauthenticated RCE
CVE-2024-8069MEDIUMsob ataque28 dez 2024
Limited remote code execution with privilege of a NetworkService Account access
68RISCO
abrir
GitHub PoC
Nxploited/CVE-2024-9933
CVE-2024-9933CRITICAL27 dez 2024
WatchTowerHQ <= 3.10.1 - Authentication Bypass to Administrator due to Missing Empty Value Check
48RISCO
abrir
Metasploit600
Netis Router Exploit Chain Reactor (CVE-2024-48455, CVE-2024-48456 and CVE-2024-48457).
CVE-2024-48457HIGH27 dez 2024
An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi
36RISCO
abrir
Metasploit600
Netis Router Exploit Chain Reactor (CVE-2024-48455, CVE-2024-48456 and CVE-2024-48457).
CVE-2024-48455LOW27 dez 2024
An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi
23RISCO
abrir
Metasploit600
Netis Router Exploit Chain Reactor (CVE-2024-48455, CVE-2024-48456 and CVE-2024-48457).
CVE-2024-48456HIGH27 dez 2024
An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi
41RISCO
abrir
GitHub PoC
Testing the latset Apache Tomcat CVE-2024-50379 Vuln
CVE-2024-50379CRITICAL26 dez 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RISCO
abrir
GitHub PoC2
Drupal CVE-2024-45440
CVE-2024-45440MEDIUM26 dez 2024
core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash
48RISCO
abrir
GitHub PoC
AleksaZatezalo/CVE-2020-14882
CVE-2020-14882CRITICALsob ataque26 dez 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-2291126 dez 2024
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALsob ataque26 dez 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC
Malware Analysis CVE-2017-11882
CVE-2017-11882HIGHsob ataqueransomware26 dez 2024
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir
GitHub PoC
yoohhuu/Rocket-Chat-3.12.1-PoC-CVE-2021-22911-
CVE-2021-2291126 dez 2024
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISCO
abrir
GitHub PoC1
UnionTech-Software/libtheora-CVE-2024-56431-PoC
CVE-2024-56431CRITICAL25 dez 2024
oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: th
48RISCO
abrir
GitHub PoC
A proof of concept of the path traversal vulnerability in the python AioHTTP library =< 3.9.1
CVE-2024-23334MEDIUM25 dez 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-23334MEDIUM25 dez 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISCO
abrir
GitHub PoC5
WordPress File Upload插件任意文件读取漏洞(CVE-2024-9047)批量检测脚本
CVE-2024-9047CRITICAL25 dez 2024
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
85RISCO
abrir
GitHub PoC4
This repository contains a Python script designed to exploit CVE-2024-50379, a vulnerability that allows attackers to upload a JSP shell to a vulnerable server and execute arbitrary commands remotely. This exploit is particularly useful when the /uploads directory is either unprotected or not present on the target server.
CVE-2024-50379CRITICAL25 dez 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-9047CRITICAL25 dez 2024
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-10914CRITICAL24 dez 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir
GitHub PoC3
Unauthenticated Local File Inclusion
CVE-2024-12209CRITICAL24 dez 2024
WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion
68RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-32113CRITICALsob ataque24 dez 2024
Apache OFBiz: Path traversal leading to RCE
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-920624 dez 2024
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-12209CRITICAL24 dez 2024
WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion
68RISCO
abrir
GitHub PoC1
The tool targets WordPress websites that use the Super Backup & Clone plugin and are vulnerable to arbitrary file upload.
CVE-2024-9290CRITICAL24 dez 2024
Super Backup & Clone - Migrate for WordPress <= 2.3.3 - Unauthenticated Arbitrary File Upload
48RISCO
abrir
GitHub PoC
A PoC exploit for CVE-2024-10914 - D-Link Remote Code Execution (RCE)
CVE-2024-10914CRITICAL24 dez 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir
GitHub PoC83
tomcat CVE-2024-50379/CVE-2024-56337 条件竞争文件上传exp
CVE-2024-50379CRITICAL23 dez 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RISCO
abrir
GitHub PoC1
CVE-2024-50379利用
CVE-2024-50379CRITICAL23 dez 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-50623CRITICALsob ataqueransomware23 dez 2024
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file up
100RISCO
abrir
GitHub PoC
hiteshpatra/CVE-2024-53677
CVE-2024-53677CRITICAL23 dez 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir
anteriorpágina 316 / 2.537próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.