Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.020exploits catalogados
35.276CVEs com exploração pública
24.695testados em laboratório
77.020 exploits
GitHub PoC9
local poc for CVE-2024-32002
CVE-2024-32002CRITICAL18 mai 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
GitHub PoC
jakob-pennington/cve-2024-32002-submodule-rce
CVE-2024-32002CRITICAL18 mai 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
GitHub PoC109
CVE-2024-32002 RCE PoC
CVE-2024-32002CRITICAL18 mai 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
GitHub PoC1
jakob-pennington/cve-2024-32002-poc-rce
CVE-2024-32002CRITICAL18 mai 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
GitHub PoC7
Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.
CVE-2024-21338HIGHsob ataqueransomware18 mai 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISCO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALsob ataque18 mai 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC3
A PoC exploit for CVE-2014-6271 - Shellshock
CVE-2014-6271CRITICALsob ataque18 mai 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-29895CRITICAL17 mai 2024
Cacti command injection in cmd_realtime.php
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-27130HIGH17 mai 2024
QTS, QuTS hero
53RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL17 mai 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir
GitHub PoC1
0xYumeko/CVE-2024-32640-SQLI-MuraCMS
CVE-2024-32640CRITICAL17 mai 2024
MasaCMS SQL Injection vulnerability
85RISCO
abrir
GitHub PoC
A submodule for exploiting CVE-2024-32002 vulnerability.
CVE-2024-32002CRITICAL17 mai 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
GitHub PoC532
Exploit PoC for CVE-2024-32002
CVE-2024-32002CRITICAL17 mai 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
GitHub PoC2
A proof of concept for the git vulnerability CVE-2024-32002
CVE-2024-32002CRITICAL17 mai 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
GitHub PoC18
Hook for the PoC for exploiting CVE-2024-32002
CVE-2024-32002CRITICAL17 mai 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
GitHub PoC
10cks/CVE-2024-21111-del
CVE-2024-21111HIGH17 mai 2024
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
41RISCO
abrir
GitHub PoC
svchostmm/CVE-2024-25600-mass
CVE-2024-25600CRITICAL17 mai 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir
GitHub PoC9
(CVE-2024-33559) The XStore theme for WordPress is vulnerable to SQL Injection due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query
CVE-2024-33559CRITICAL17 mai 2024
WordPress XStore theme <= 9.3.5 - Unauthenticated SQL Injection vulnerability
48RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-32640CRITICAL17 mai 2024
MasaCMS SQL Injection vulnerability
85RISCO
abrir
GitHub PoC
CVE-2019-9054 exploit added support for python3 + bug fixes
CVE-2019-905317 mai 2024
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
GitHub PoC27
CVE-2023-34992: Fortinet FortiSIEM Command Injection Proof of Concept Exploit
CVE-2023-34992CRITICAL17 mai 2024
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
85RISCO
abrir
GitHub PoC5
CVE-2024-29895 | RCE on CACTI 1.3.X dev
CVE-2024-29895CRITICAL17 mai 2024
Cacti command injection in cmd_realtime.php
85RISCO
abrir
GitHub PoC78
CVE-2024-32640 | Automated SQLi Exploitation PoC
CVE-2024-32640CRITICAL16 mai 2024
MasaCMS SQL Injection vulnerability
85RISCO
abrir
GitHub PoC
Demonstration of CVE-2020-0601 aka curveball. Based on the PoC's available at https://github.com/kudelskisecurity/chainoffools and https://github.com/ly4k/CurveBall
CVE-2020-0601HIGHsob ataque16 mai 2024
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-32640CRITICAL16 mai 2024
MasaCMS SQL Injection vulnerability
85RISCO
abrir
GitHub PoC
ticofookfook/CVE-2024-29895.py
CVE-2024-29895CRITICAL16 mai 2024
Cacti command injection in cmd_realtime.php
85RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALsob ataqueransomware16 mai 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
GitHub PoC13
Poc para explotar la vulnerabilidad CVE-2024-23897 en versiones 2.441 y anteriores de Jenkins, mediante la cual podremos leer archivos internos del sistema sin estar autenticados
CVE-2024-23897CRITICALsob ataqueransomware16 mai 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
GitHub PoC
CVE-2016-10033 Wordpress 4.6 Exploit
CVE-2016-10033CRITICALsob ataque16 mai 2024
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2020-0601HIGHsob ataque16 mai 2024
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISCO
abrir
anteriorpágina 398 / 2.568próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.