Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.559exploits catalogados
34.978CVEs com exploração pública
24.695testados em laboratório
76.313 exploits
VulnCheck XDB
initial-access
CVE-2024-9593HIGH18 out 2024
Time Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Unauthenticated (Limited) Remote Code Execution
61RISCO
abrir
GitHub PoC2
Security Bulletin for CVE-2024-35133 - With PoC
CVE-2024-35133MEDIUM18 out 2024
IBM Security Verify Access HTTP open redirect
33RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-9234CRITICAL17 out 2024
GutenKit <= 2.1.0 - Unauthenticated Arbitrary File Upload
68RISCO
abrir
GitHub PoC11
tdonaworth/Firefox-CVE-2024-9680
CVE-2024-9680CRITICALsob ataqueransomware17 out 2024
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timeli
83RISCO
abrir
GitHub PoC2
GutenKit <= 2.1.0 - Unauthenticated Arbitrary File Upload
CVE-2024-9234CRITICAL17 out 2024
GutenKit <= 2.1.0 - Unauthenticated Arbitrary File Upload
68RISCO
abrir
GitHub PoC
Vulnerability Overview CVE-2023-38408 affects OpenSSH versions < 9.3p2 and stems from improper validation of data when SSH agent forwarding is enabled. When users connect to a remote server with ssh -A, they allow the agent on their local machine to be used for authentication to further systems
CVE-2023-38408CRITICAL17 out 2024
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISCO
abrir
VulnCheck XDB
local
CVE-2024-30090HIGH17 out 2024
Microsoft Streaming Service Elevation of Privilege Vulnerability
41RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-47176MEDIUM17 out 2024
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALsob ataqueransomware16 out 2024
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISCO
abrir
GitHub PoC
check and exploit for NTP vuln CVE-2013-5211
CVE-2013-521116 out 2024
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RISCO
abrir
GitHub PoC
Exploit and check CVE-2013-5211
CVE-2013-521116 out 2024
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-40539CRITICALsob ataqueransomware16 out 2024
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RISCO
abrir
GitHub PoC2
ADSelfService Plus RCE漏洞 检测工具 (二开)
CVE-2021-40539CRITICALsob ataqueransomware16 out 2024
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RISCO
abrir
GitHub PoC
cuanh2333/CVE-2023-46604
CVE-2023-46604CRITICALsob ataqueransomware16 out 2024
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISCO
abrir
GitHub PoC43
CVE-2024-40711-exp
CVE-2024-40711CRITICALsob ataqueransomware16 out 2024
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code exec
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-1709CRITICALsob ataqueransomware16 out 2024
Authentication bypass using an alternate path or channel
100RISCO
abrir
GitHub PoC2
Guide and theoretical code for CVE-2023-35674
CVE-2023-35674HIGHsob ataque15 out 2024
In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the cod
71RISCO
abrir
GitHub PoC
idkwastaken/CVE-2023-32560
CVE-2023-32560HIGH15 out 2024
An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disrup
78RISCO
abrir
GitHub PoC
idkwastaken/CVE-2023-38831
CVE-2023-38831HIGHsob ataqueransomware15 out 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2023-38831HIGHsob ataqueransomware15 out 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC3
Vulnerability CVE-2024-38063
CVE-2024-38063CRITICAL15 out 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC5
ssst0n3/poc-cve-2024-0132
CVE-2024-0132CRITICAL15 out 2024
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with de
60RISCO
abrir
GitHub PoC
idkwastaken/CVE-2024-38063
CVE-2024-38063CRITICAL14 out 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC
kkhackz0013/CVE-2024-36401
CVE-2024-36401CRITICALsob ataque14 out 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir
GitHub PoC5
longhoangth18/CVE-2024-4577
CVE-2024-4577CRITICALsob ataqueransomware14 out 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
a proof of concept of the CVE-2024-27198 which infect jetbrains teamCity
CVE-2024-27198CRITICALsob ataqueransomware14 out 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALsob ataque14 out 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2023-6000MEDIUM14 out 2024
Popup Builder < 4.2.3 - Unauthenticated Stored XSS
48RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-1698CRITICAL14 out 2024
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALsob ataqueransomware14 out 2024
Argument Injection in PHP-CGI
100RISCO
abrir
anteriorpágina 339 / 2.544próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.