Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.058exploits catalogados
35.300CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.175GitHub PoC 14.096VulnCheck XDB 8.607Nuclei 4.255Metasploit 3.474✓ só verificadosrecentespopularesrisco
77.020 exploits
GitHub PoC
This repository contains a proof of concept about the exploitation of the aiohttp library for the reported vulnerability CVE-2024-23334.
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISCO
abrir ↗GitHub PoC
LamSonBinh/CVE-2018-20250
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir ↗GitHub PoC★ 2
NSE script for checking the presence of CVE-2023-22515
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISCO
abrir ↗GitHub PoC
activemq-rce-cve-2023-46604
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISCO
abrir ↗GitHub PoC
libertycityhacker/CVE-2023-43364-Exploit-CVE
main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution.
48RISCO
abrir ↗VulnCheck XDB
client-side
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir ↗VulnCheck XDB
infoleak
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISCO
abrir ↗VulnCheck XDB
infoleak
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISCO
abrir ↗VulnCheck XDB
initial-access
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISCO
abrir ↗VulnCheck XDB
infoleak
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISCO
abrir ↗VulnCheck XDB
infoleak
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISCO
abrir ↗VulnCheck XDB
initial-access
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISCO
abrir ↗GitHub PoC★ 6
POC for SQLi vulnerability in Icegram express
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RISCO
abrir ↗GitHub PoC★ 6
0xr2r/CVE-2024-3400-Palo-Alto-OS-Command-Injection
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISCO
abrir ↗GitHub PoC★ 63
CVE-2024-4040 CrushFTP SSTI LFI & Auth Bypass | Full Server Takeover | Wordlist Support
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISCO
abrir ↗VulnCheck XDB
infoleak
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RISCO
abrir ↗GitHub PoC★ 14
rbih-boulanouar/CVE-2024-4040
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISCO
abrir ↗GitHub PoC
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISCO
abrir ↗GitHub PoC★ 42
CVE-2023-20198-RCE, support adding/deleting users and executing cli commands/system commands.
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISCO
abrir ↗GitHub PoC
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RISCO
abrir ↗VulnCheck XDB
initial-access
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir ↗VulnCheck XDB
initial-access
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISCO
abrir ↗GitHub PoC★ 4
PoC exploit for GLPI - Command injection using a third-party library script
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISCO
abrir ↗GitHub PoC★ 11
JetBrains TeamCity 2023.05.3 - Remote Code Execution (RCE), CVE-2023-42793
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir ↗GitHub PoC
Check to see if your Palo Alto firewall has been compromised by running script againt support bundle.
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISCO
abrir ↗VulnCheck XDB
initial-access
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗GitHub PoC★ 6
Simple honeypot for CVE-2024-3400 Palo Alto PAN-OS Command Injection Vulnerability
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISCO
abrir ↗GitHub PoC
mrrobot0o/CVE-2024-3273-
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISCO
abrir ↗VulnCheck XDB
initial-access
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.