Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
76.559exploits catalogados
34.978CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.899GitHub PoC 13.960VulnCheck XDB 8.542Nuclei 4.243Metasploit 3.472✓ só verificadosrecentespopularesrisco
76.313 exploits
GitHub PoC★ 3
WBW Product Table Pro <= 1.9.4 - Unauthenticated Arbitrary SQL Execution to RCE
WordPress WBW Product Table PRO plugin <= 1.9.4 - Unauthenticated Arbitrary SQL Query Execution vulnerability
48RISCO
abrir ↗GitHub PoC★ 2
vidura2/CVE-2024-46377
Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the save_settings() function
48RISCO
abrir ↗GitHub PoC★ 5
TheCyberguy-17/RCE_CVE-2024-7954
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISCO
abrir ↗GitHub PoC★ 2
vidura2/CVE-2024-46451
TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWiFiAclRules function via the de
48RISCO
abrir ↗GitHub PoC★ 3
vidura2/CVE-2024-46986
Arbitrary file write leading to RCE in Camaleon CMS
75RISCO
abrir ↗GitHub PoC
WonderCMS RCE CVE-2023-41425
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISCO
abrir ↗GitHub PoC
Kode Eksploitasi CVE-2024-38063
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC
CVE-2024-3273 - D-Link Remote Code Execution (RCE)
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISCO
abrir ↗GitHub PoC★ 3
Azrenom/CMS-Made-Simple-2.2.9-CVE-2019-9053
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir ↗VulnCheck XDB
initial-access
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISCO
abrir ↗VulnCheck XDB
initial-access
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir ↗GitHub PoC★ 1
teamcity-exploit-cve-2023-42793
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir ↗GitHub PoC
yashfren/CVE-2014-0160-HeartBleed
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir ↗VulnCheck XDB
infoleak
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir ↗VulnCheck XDB
initial-access
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir ↗VulnCheck XDB
infoleak
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RISCO
abrir ↗GitHub PoC
MAHajian/CVE-2019-9978
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir ↗GitHub PoC
btar1gan/exploit_CVE-2022-35914
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISCO
abrir ↗GitHub PoC★ 6
POC_CVE-2024-46256
A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add
48RISCO
abrir ↗GitHub PoC
CVE-2023-47253 | Qualitor <= 8.20 RCE
Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/reques
68RISCO
abrir ↗VulnCheck XDB
initial-access
Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/reques
68RISCO
abrir ↗VulnCheck XDB
initial-access
Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/reques
68RISCO
abrir ↗GitHub PoC
poc of cve-2024-8752(WebIQ 2.15.9)
WebIQ 2.15.9 Runtime on Windows - Directory Traversal Vulnerability
68RISCO
abrir ↗GitHub PoC
CVE-2023-47253 | Qualitor <= 8.20 RCE
Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/reques
68RISCO
abrir ↗GitHub PoC
Webrun <= 3.6.0.42 SQLi
WebRun 3.6.0.42 is vulnerable to SQL Injection via the P_0 parameter used to set the username during the login process.
23RISCO
abrir ↗GitHub PoC★ 2
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'
75RISCO
abrir ↗GitHub PoC★ 1
Modification of: PoC of CVE-2019-14322: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.
50RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.