Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.559exploits catalogados
34.978CVEs com exploração pública
24.695testados em laboratório
76.313 exploits
GitHub PoC17
CVE-2024-38077: Remote Code Execution Vulnerability in Windows Remote Desktop Licensing Service
CVE-2024-38077CRITICAL09 out 2024
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC27
Unauthenticated Remote Code Execution via Angular-Base64-Upload Library
CVE-2024-42640CRITICAL09 out 2024
angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Explo
75RISCO
abrir
GitHub PoC44
Proof of Concept Exploit for CVE-2024-9464
CVE-2024-9464CRITICAL09 out 2024
Expedition: Authenticated OS Command Injection Vulnerability Leads to Firewall Admin Credential Disclosure
70RISCO
abrir
GitHub PoC3
is a PoC tool that targets a vulnerability in the TeamCity server (CVE-2024-27198)
CVE-2024-27198CRITICALsob ataqueransomware09 out 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-24919HIGHsob ataqueransomware09 out 2024
Information disclosure
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-27198CRITICALsob ataqueransomware09 out 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir
Metasploit600
Palo Alto Expedition Remote Code Execution (CVE-2024-5910 and CVE-2024-9464)
CVE-2024-5910CRITICALsob ataque09 out 2024
Expedition: Missing Authentication Leads to Admin Account Takeover
100RISCO
abrir
Metasploit600
Palo Alto Expedition Remote Code Execution (CVE-2024-5910 and CVE-2024-9464)
CVE-2024-24809HIGH09 out 2024
Traccar vulnerable to Path Traversal: 'dir/../../filename' and Unrestricted Upload of File with Dangerous Type
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-42640CRITICAL09 out 2024
angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Explo
75RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-9465CRITICALsob ataque09 out 2024
Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-2876CRITICAL09 out 2024
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RISCO
abrir
GitHub PoC31
Proof of Concept Exploit for CVE-2024-9465
CVE-2024-9465CRITICALsob ataque09 out 2024
Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-34102CRITICALsob ataque08 out 2024
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir
GitHub PoC
The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attac
CVE-2024-1207CRITICAL08 out 2024
Booking Calendar <= 9.9 - Unauthenticated SQL Injection
48RISCO
abrir
GitHub PoC1
Proof of Concept for the Log4Shell vulnerability (CVE-2021-44228), developed as part of the coursework for the curricular unit TPAS in the Master's degree in Information Security at FCUP.
CVE-2021-44228CRITICALsob ataqueransomware08 out 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-24706CRITICALsob ataque08 out 2024
Remote Code Execution Vulnerability in Packaging
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALsob ataqueransomware08 out 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir
GitHub PoC1
Performs an IPv6 vulnerability scan and packet flood attack on specified targets. The script simulates a SYN flood and ICMP flood attack and optionally sends exploit packets.
CVE-2024-38063CRITICAL08 out 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-7029HIGH08 out 2024
Command Injection in AVTech AVM1203 (IP Camera)
68RISCO
abrir
GitHub PoC
bka/magento-cve-2024-34102-exploit-cosmicstring
CVE-2024-34102CRITICALsob ataque08 out 2024
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir
GitHub PoC
wargame, CVE-2024-4367
CVE-2024-4367MEDIUM08 out 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir
GitHub PoC
TeamCity server scanner to detect CVE-2023-42793
CVE-2023-42793CRITICALsob ataqueransomware08 out 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir
GitHub PoC1
Agilevatester/FlaskCache_CVE-2021-33026_POC
CVE-2021-33026CRITICAL08 out 2024
The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code e
48RISCO
abrir
GitHub PoC
Apache CouchDB 3.2.1 - Remote Code Execution (RCE) Checker
CVE-2022-24706CRITICALsob ataque08 out 2024
Remote Code Execution Vulnerability in Packaging
100RISCO
abrir
Metasploit600
Ivanti Connect Secure Authenticated Remote Code Execution via OpenSSL CRLF Injection
CVE-2024-37404CRITICAL08 out 2024
Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Se
65RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-7269CRITICALsob ataque07 out 2024
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-47176MEDIUM07 out 2024
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-47176MEDIUM07 out 2024
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISCO
abrir
VulnCheck XDB
infoleak
CVE-2022-241407 out 2024
Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a
60RISCO
abrir
GitHub PoC83
Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409) exploit
CVE-2024-45409CRITICAL07 out 2024
The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selector
53RISCO
abrir
anteriorpágina 341 / 2.544próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.