Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.647exploits catalogados
34.986CVEs com exploração pública
24.695testados em laboratório
76.605 exploits
VulnCheck XDB
initial-access
CVE-2024-4879CRITICALsob ataque16 jul 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISCO
abrir
GitHub PoC
On October 4, 2021, Apache HTTP Server Project released Security advisory on a Path traversal and File disclosure vulnerability in Apache HTTP Server 2.4.49 and 2.4.50 tracked as CVE-2021-41773 and CVE-2021-42013. In the advisory, Apache also highlighted “the issue is known to be exploited in the wild” and later it was identified that the vulnerabi
CVE-2021-42013CRITICALsob ataqueransomware16 jul 2024
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC
Laravel Debug Mode and Payload
CVE-2021-3129CRITICALsob ataqueransomware16 jul 2024
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
GitHub PoC1
Exploit for CVE-2024-4879 affecting Vancouver, Washington DC Now and Utah Platform releases
CVE-2024-4879CRITICALsob ataque16 jul 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALsob ataqueransomware16 jul 2024
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALsob ataqueransomware16 jul 2024
Argument Injection in PHP-CGI
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHsob ataqueransomware16 jul 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALsob ataqueransomware16 jul 2024
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
GitHub PoC
Automated PHP remote code execution scanner for CVE-2024-4577
CVE-2024-4577CRITICALsob ataqueransomware16 jul 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
khanhtranngoccva/cve-2023-38831-poc
CVE-2023-38831HIGHsob ataqueransomware16 jul 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC
LMS Chamilo 1.11.24 CVE-2023-4220 Exploit
CVE-2023-4220HIGH15 jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALsob ataqueransomware15 jul 2024
Argument Injection in PHP-CGI
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-4879CRITICALsob ataque15 jul 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISCO
abrir
VulnCheck XDB
local
CVE-2024-30088HIGHsob ataqueransomware15 jul 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-4220HIGH15 jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir
GitHub PoC3
OpenSSH RCE Massive Vulnerable Scanner
CVE-2024-6387HIGH15 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir
GitHub PoC525
Kernel exploit for Xbox SystemOS using CVE-2024-30088
CVE-2024-30088HIGHsob ataqueransomware15 jul 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISCO
abrir
GitHub PoC
OpenSSH a publié un avis de sécurité concernant la vulnérabilité critique CVE-2024-6387. Cette vulnérabilité permet à un attaquant non authentifié d'exécuter du code arbitraire
CVE-2024-6387HIGH14 jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir
GitHub PoC1
Phantom-IN/CVE-2024-34102
CVE-2024-34102CRITICALsob ataque14 jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir
GitHub PoC1
Exploit para abusar de la vulnerabilidad Shellshock (CVE-2014-6271).
CVE-2014-6271CRITICALsob ataque14 jul 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-24919HIGHsob ataqueransomware14 jul 2024
Information disclosure
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALsob ataque14 jul 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC1
Prueba de concepto para abusar de la vulnerabilidad Shellshock (CVE-2014-6271).
CVE-2014-6271CRITICALsob ataque14 jul 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-34102CRITICALsob ataque13 jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-34102CRITICALsob ataque13 jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir
GitHub PoC76
CVE-2024-41570: Havoc C2 0.7 Teamserver SSRF exploit
CVE-2024-41570CRITICAL13 jul 2024
An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send
48RISCO
abrir
GitHub PoC5
Exploitation CVE-2024-34102
CVE-2024-34102CRITICALsob ataque13 jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir
GitHub PoC1
CVE-2024-39250 TimeTrax SQLi
CVE-2024-39250CRITICAL13 jul 2024
EfroTech Timetrax v8.3 was discovered to contain an unauthenticated SQL injection vulnerability via the q parameter in t
63RISCO
abrir
GitHub PoC
jakabakos/CVE-2024-36401-GeoServer-RCE
CVE-2024-36401CRITICALsob ataque12 jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-4879CRITICALsob ataque12 jul 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISCO
abrir
anteriorpágina 367 / 2.554próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.