Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.559exploits catalogados
34.978CVEs com exploração pública
24.695testados em laboratório
76.313 exploits
GitHub PoC
CVE Exploitation Reports: CVE-2007-3280, CVE-2017-0144, CVE-2019-0708
CVE-2019-0708CRITICALsob ataqueransomware11 set 2024
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC
Log4J exploit CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware11 set 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
OtisSymbos/CVE-2021-44228-Log4Shell-
CVE-2021-44228CRITICALsob ataqueransomware11 set 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
My proof of concept for CVE-2019 Microsoft-Edge
CVE-2019-056711 set 2024
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RISCO
abrir
GitHub PoC2
Spring Cloud Remote Code Execution
CVE-2024-37084CRITICAL11 set 2024
CVE-2024-37084: Remote code execution in Spring Cloud Data Flow
60RISCO
abrir
GitHub PoC1
Powershell script that checks for cert padding in the Windows Registry and adds it if it does not exist. Meant to resolve the WinTrustVerify Vulnerability.
CVE-2013-3900MEDIUMsob ataque11 set 2024
WinVerifyTrust Signature Validation Vulnerability
75RISCO
abrir
GitHub PoC
CVE Exploitation Reports: CVE-2007-3280, CVE-2017-0144, CVE-2019-0708
CVE-2017-0144HIGHsob ataqueransomware11 set 2024
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2017-0199HIGHsob ataqueransomware10 set 2024
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir
GitHub PoC
carradolly/CVE-2015-8660
CVE-2015-866010 set 2024
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op
43RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-28000CRITICAL10 set 2024
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISCO
abrir
GitHub PoC
Python3 toolkit update
CVE-2017-0199HIGHsob ataqueransomware10 set 2024
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir
GitHub PoC9
0xRoqeeb/sqlpad-rce-exploit-CVE-2022-0944
CVE-2022-0944CRITICAL10 set 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISCO
abrir
GitHub PoC1
Scanning CVE-2024-4577 vulnerability with a url list.
CVE-2024-4577CRITICALsob ataqueransomware10 set 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC3
Analysis , Demo exploit and poc about CVE-2024-37084
CVE-2024-37084CRITICAL10 set 2024
CVE-2024-37084: Remote code execution in Spring Cloud Data Flow
60RISCO
abrir
GitHub PoC1
Artemisxxx37/OverlayFS-PrivEsc-CVE-2022-0944
CVE-2022-0944CRITICAL10 set 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISCO
abrir
GitHub PoC5
CVE-2024-28000 Exploit for litespeed-cache =<6.3 allows Privilege Escalation with creation of administrator account
CVE-2024-28000CRITICAL10 set 2024
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISCO
abrir
GitHub PoC1
CVE-2024-38063 - Remotely Exploiting The Kernel Via IPv6
CVE-2024-38063CRITICAL10 set 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir
Metasploit600
VICIdial Authenticated Remote Code Execution
CVE-2024-8504HIGH10 set 2024
VICIdial Authenticated Remote Code Execution
58RISCO
abrir
Metasploit300
Vicidial SQL Injection Time-based Admin Credentials Enumeration
CVE-2024-8503CRITICAL10 set 2024
VICIdial Unauthenticated SQL Injection
85RISCO
abrir
GitHub PoC1
KaoXx/CVE-2022-37706
CVE-2022-37706HIGH10 set 2024
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALsob ataqueransomware10 set 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC3
JSON API User <= 3.9.3 - Unauthenticated Privilege Escalation
CVE-2024-6624CRITICAL10 set 2024
JSON API User <= 3.9.3 - Unauthenticated Privilege Escalation
48RISCO
abrir
GitHub PoC
LucasOneZ/CVE-2023-4966
CVE-2023-4966CRITICALsob ataqueransomware09 set 2024
Unauthenticated sensitive information disclosure
100RISCO
abrir
GitHub PoC5
SQLPad - Template injection (POC exploit for SQLPad RCE [CVE-2022-0944])
CVE-2022-0944CRITICAL09 set 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISCO
abrir
GitHub PoC4
CVE-2018-0834 full code exec
CVE-2018-083409 set 2024
Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remot
35RISCO
abrir
GitHub PoC1
CVE-2024-28000 LiteSpeed Cache Privilege Escalation Scan&Exp
CVE-2024-28000CRITICAL09 set 2024
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISCO
abrir
GitHub PoC
PoC code written for CVE-2022-0944 to make exploitation easier. Based on information found here: https://huntr.com/bounties/46630727-d923-4444-a421-537ecd63e7fb
CVE-2022-0944CRITICAL09 set 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISCO
abrir
GitHub PoC
CVE-2024-23897 분석
CVE-2024-23897CRITICALsob ataqueransomware09 set 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-4966CRITICALsob ataqueransomware09 set 2024
Unauthenticated sensitive information disclosure
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-28000CRITICAL09 set 2024
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISCO
abrir
anteriorpágina 348 / 2.544próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.