Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.647exploits catalogados
34.986CVEs com exploração pública
24.695testados em laboratório
76.647 exploits
GitHub PoC1
WanLiChangChengWanLiChang/CVE-2024-29972
CVE-2024-29972CRITICAL20 jun 2024
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326
85RISCO
abrir
GitHub PoC6
This script is a modified version of the original exploit by Daniele Scanu which exploits an unauthenticated SQL injection vulnerability in CMS Made Simple <= 2.2.10 (CVE-2019-9053).
CVE-2019-905320 jun 2024
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
GitHub PoC3
momika233/CVE-2024-29973
CVE-2024-29973CRITICAL19 jun 2024
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RISCO
abrir
GitHub PoC6
PoC - Prueba de Concepto de CVE-2024-4367 en conjunto al CVE-2023-38831 en un solo Script
CVE-2023-38831HIGHsob ataqueransomware19 jun 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC10
POC for CVE-2024-29973
CVE-2024-29973CRITICAL19 jun 2024
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RISCO
abrir
VulnCheck XDB
client-side
CVE-2023-38831HIGHsob ataqueransomware19 jun 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-29973CRITICAL19 jun 2024
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RISCO
abrir
GitHub PoC
MalekAlthubiany/CVE-2021-43798
CVE-2021-43798HIGHsob ataque19 jun 2024
Grafana path traversal
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALsob ataque19 jun 2024
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-43798HIGHsob ataque19 jun 2024
Grafana path traversal
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-29973CRITICAL19 jun 2024
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RISCO
abrir
GitHub PoC6
PoC - Prueba de Concepto de CVE-2024-4367 en conjunto al CVE-2023-38831 en un solo Script
CVE-2024-4367MEDIUM19 jun 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir
GitHub PoC72
CVE-2024-28397: js2py sandbox escape, bypass pyimport restriction.
CVE-2024-28397MEDIUM19 jun 2024
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISCO
abrir
GitHub PoC
CVE-2022-22947 exploit script
CVE-2022-22947CRITICALsob ataque19 jun 2024
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC
Redfox-Security/Digisol-DG-GR1321-s-Password-Policy-Bypass-CVE-2024-2257
CVE-2024-2257CRITICAL18 jun 2024
Password Policy Bypass Vulnerability in Digisol Router
48RISCO
abrir
GitHub PoC1
A small tool to create a PoC for CVE-2000-0649.
CVE-2000-064918 jun 2024
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page w
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-23692CRITICALsob ataqueransomware18 jun 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALsob ataqueransomware18 jun 2024
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC13
CVE-2024-23692 Exploit
CVE-2024-23692CRITICALsob ataqueransomware18 jun 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-29824CRITICALsob ataque18 jun 2024
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att
100RISCO
abrir
GitHub PoC
jakabakos/CVE-2024-4577-PHP-CGI-argument-injection-RCE
CVE-2024-4577CRITICALsob ataqueransomware18 jun 2024
Argument Injection in PHP-CGI
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2024-21413CRITICALsob ataque18 jun 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
This script is the Proof of Concept (PoC) of the CVE-2024-21413, a significant security vulnerability discovered in the Microsoft Windows Outlook having a strong 9.8 critical CVSS score. Named as #MonikerLink Bug, this vulnerability allows the attacker to execute the arbitrary code remotely on the victim's machine, thus becomes a full-fledged RCE.
CVE-2024-21413CRITICALsob ataque18 jun 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir
Metasploit500
vCenter Sudo Privilege Escalation
CVE-2024-37081HIGH18 jun 2024
The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An auth
36RISCO
abrir
GitHub PoC1
Ivanti EPM SQL Injection Remote Code Execution Vulnerability(Optimized version based on h3)
CVE-2024-29824CRITICALsob ataque18 jun 2024
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att
100RISCO
abrir
GitHub PoC
Expolit for CVE-2024-23334 (aiohttp >= 1.0.5> && <=3.9.1)
CVE-2024-23334MEDIUM17 jun 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISCO
abrir
VulnCheck XDB
client-side
CVE-2023-38831HIGHsob ataqueransomware17 jun 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-23334MEDIUM17 jun 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-23692CRITICALsob ataqueransomware17 jun 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISCO
abrir
GitHub PoC7
CVE-2024-23692
CVE-2024-23692CRITICALsob ataqueransomware17 jun 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISCO
abrir
anteriorpágina 379 / 2.555próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.