Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.607exploits catalogados
34.986CVEs com exploração pública
24.695testados em laboratório
76.559 exploits
GitHub PoC1
CVE-2024-6387-checker is a tool or script designed to detect the security vulnerability known as CVE-2024-6387 OpenSSH. CVE-2024-6387 OpenSSH is an entry in the Common Vulnerabilities and Exposures (CVE) that documents security weaknesses discovered in certain software or systems.
CVE-2023-4596CRITICAL06 ago 2024
Forminator <= 1.24.6 - Unauthenticated Arbitrary File Upload
68RISCO
abrir
GitHub PoC1
This Python application scans for the CVE-2023-38831 vulnerability in WinRAR.
CVE-2023-38831HIGHsob ataqueransomware06 ago 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-7339MEDIUM05 ago 2024
TVT DVR TD-2104TS-CL queryDevInfo information disclosure
60RISCO
abrir
Metasploit300
Ivanti Virtual Traffic Manager Authentication Bypass (CVE-2024-7593)
CVE-2024-7593CRITICALsob ataque05 ago 2024
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remo
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-38856HIGHsob ataque05 ago 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISCO
abrir
VulnCheck XDB
local
CVE-2019-1609805 ago 2024
The driver in Micro-Star MSI Afterburner 4.6.2.15658 (aka RTCore64.sys and RTCore32.sys) allows any authenticated user t
28RISCO
abrir
VulnCheck XDB
local
CVE-2024-26229HIGH04 ago 2024
Windows CSC Service Elevation of Privilege Vulnerability
41RISCO
abrir
Exploit-DB
Devika v1 - Path Traversal via 'snapshot_path'
CVE-2024-40422CRITICALwebappspython04 ago 2024
The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path tr
68RISCO
abrir
GitHub PoC
Abdurahmon3236/CVE-2024-6366
CVE-2024-6366CRITICAL03 ago 2024
User Profile Builder < 3.11.8 - Unauthenticated Media Upload
68RISCO
abrir
GitHub PoC
Abdurahmon3236/CVE-2024-36539
CVE-2024-36539CRITICAL03 ago 2024
Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining t
48RISCO
abrir
GitHub PoC
nastar-id/CVE-2024-32700
CVE-2024-32700CRITICAL03 ago 2024
WordPress Kognetiks Chatbot for WordPress plugin <= 2.0.0 - Arbitrary File Upload vulnerability
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-29973CRITICAL03 ago 2024
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RISCO
abrir
GitHub PoC2
A Simple Python Program that uses gets a Remote Root Shell on the Target Device by exploiting a Vulnerability (CVE-2011-2523) present in vsFTP 2.3.4
CVE-2011-252303 ago 2024
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
GitHub PoC
Abdurahmon3236/CVE-2024-40110
CVE-2024-40110CRITICAL02 ago 2024
Sourcecodester Poultry Farm Management System v1.0 contains an Unauthenticated Remote Code Execution (RCE) vulnerability
48RISCO
abrir
GitHub PoC
This is a script written in Python that allows the exploitation of the Chamilo's LMS software security flaw described in CVE-2023-4220
CVE-2023-4220HIGH02 ago 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir
GitHub PoC2
Vulnerability Scanner for CVE-2024-37085 and Exploits ( For Educational Purpose only)
CVE-2024-37085MEDIUMsob ataqueransomware02 ago 2024
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) per
68RISCO
abrir
GitHub PoC1
Proof of concept exploit for CVE-2021-21551
CVE-2021-21551HIGHsob ataque02 ago 2024
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RISCO
abrir
GitHub PoC
adapting CVE-2024-32002 for running offline and locally
CVE-2024-32002CRITICAL02 ago 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-4220HIGH02 ago 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir
VulnCheck XDB
local
CVE-2021-21551HIGHsob ataque02 ago 2024
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RISCO
abrir
VulnCheck XDB
client-side
CVE-2024-21412HIGHsob ataqueransomware02 ago 2024
Internet Shortcut Files Security Feature Bypass Vulnerability
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALsob ataque01 ago 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir
GitHub PoC
y1s4s/CVE-2024-36401-PoC
CVE-2024-36401CRITICALsob ataque01 ago 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir
GitHub PoC
Exploit script for CVE-2022-41544 in GetSimple CMS, with enhanced error handling and detailed usage instructions.
CVE-2022-41544HIGH31 jul 2024
GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file paramete
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALsob ataqueransomware31 jul 2024
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
Metasploit600
Calibre Python Code Injection (CVE-2024-6782)
CVE-2024-6782CRITICAL31 jul 2024
Calibre Remote Code Execution
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALsob ataqueransomware31 jul 2024
Argument Injection in PHP-CGI
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALsob ataqueransomware31 jul 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC1
An exploit for CVE-2024-6387, targeting a signal handler race condition in OpenSSH's server
CVE-2024-6387HIGH31 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir
GitHub PoC
批量验证POC和EXP
CVE-2024-4577CRITICALsob ataqueransomware31 jul 2024
Argument Injection in PHP-CGI
100RISCO
abrir
anteriorpágina 362 / 2.552próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.