Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.058exploits catalogados
35.300CVEs com exploração pública
24.695testados em laboratório
77.058 exploits
GitHub PoC
CVE-2023-0386 包含所需运行库
CVE-2023-0386HIGHsob ataque22 abr 2024
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISCO
abrir
Metasploit600
Apache HugeGraph Gremlin RCE
CVE-2024-27348CRITICALsob ataque22 abr 2024
Apache HugeGraph-Server: Command execution in gremlin
100RISCO
abrir
GitHub PoC1
A final project for "Network Security" class at NYCU (National Yang Ming Chiao Tung University, Taiwan). Exploiting a CVE in "EasyAppointments" software.
CVE-2022-0482CRITICAL22 abr 2024
Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
75RISCO
abrir
GitHub PoC
CVE-2022-24716 (Arbitrary File Disclosure Icingaweb2)
CVE-2022-24716HIGH22 abr 2024
Path traversal in Icinga Web 2
78RISCO
abrir
GitHub PoC36
CVE-2024-27198 & CVE-2024-27199 PoC - RCE, Admin Account Creation, Enum Users, Server Information
CVE-2024-27198CRITICALsob ataqueransomware22 abr 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir
GitHub PoC216
Oracle VirtualBox Elevation of Privilege (Local Privilege Escalation) Vulnerability
CVE-2024-21111HIGH22 abr 2024
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-27199HIGHsob ataqueransomware22 abr 2024
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
100RISCO
abrir
GitHub PoC
TYuan0816/cve-2023-44487
CVE-2023-44487HIGHsob ataque22 abr 2024
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISCO
abrir
GitHub PoC6
A PoC exploit for CVE-2018-14847 - MikroTik WinBox File Read
CVE-2018-14847CRITICALsob ataque22 abr 2024
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-14847CRITICALsob ataque22 abr 2024
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISCO
abrir
VulnCheck XDB
local
CVE-2023-0386HIGHsob ataque22 abr 2024
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-27198CRITICALsob ataqueransomware22 abr 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir
GitHub PoC
SOPlanning 1.52.00 CSRF/SQLi/XSS (CVE-2024-33722, CVE-2024-33724)
CVE-2024-33722MEDIUM22 abr 2024
SOPlanning 1.52.00 is vulnerable to SQL Injection by an authenticated user via projets.php with statut[].
33RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-3400CRITICALsob ataqueransomware21 abr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALsob ataqueransomware21 abr 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir
GitHub PoC
bde574786/Sequelize-1day-CVE-2023-25813
CVE-2023-25813CRITICAL21 abr 2024
SQL Injection via replacements in sequelize
48RISCO
abrir
GitHub PoC2
JetBrains TeamCity Unauthenticated Remote Code Execution - Python3 Implementation
CVE-2023-42793CRITICALsob ataqueransomware21 abr 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir
GitHub PoC2
Python POC for CVE-2023-6019 taken from https://huntr.com/bounties/d0290f3c-b302-4161-89f2-c13bb28b4cfe
CVE-2023-6019CRITICAL21 abr 2024
Ray Command Injection in cpu_profile Parameter
85RISCO
abrir
GitHub PoC
Python exploit and checker script for CVE-2024-3400 Palo Alto Command Injection and Arbitrary File Creation
CVE-2024-3400CRITICALsob ataqueransomware21 abr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISCO
abrir
Exploit-DB
Laravel Framework 11 - Credential Leakage
CVE-2024-29291webappsphp21 abr 2024
An issue in Laravel Framework 8 through 11 might allow a remote attacker to discover database credentials in storage/log
23RISCO
abrir
Exploit-DB
Palo Alto PAN-OS < v11.1.2-h3 - Command Injection and Arbitrary File Creation
CVE-2024-3400CRITICALsob ataqueransomwareremotelinux_x86-6421 abr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISCO
abrir
GitHub PoC
PoC for CVE-2024-24576 vulnerability "BatBadBut"
CVE-2024-24576CRITICAL21 abr 2024
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
53RISCO
abrir
Metasploit600
FortiNet FortiClient Endpoint Management Server FCTID SQLi to RCE
CVE-2023-48788CRITICALsob ataqueransomware21 abr 2024
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS versio
100RISCO
abrir
GitHub PoC1
WORDPRESS-CVE-2024-25600-EXPLOIT-RCE - WordPress Bricks Builder Remote Code Execution (RCE)
CVE-2024-25600CRITICAL20 abr 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir
GitHub PoC
Gaurav1020/CVE-2024-24576-PoC-Rust
CVE-2024-24576CRITICAL20 abr 2024
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
53RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL20 abr 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir
GitHub PoC
asdfjkl11/CVE-2024-32238
CVE-2024-32238CRITICAL20 abr 2024
H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accesse
75RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-32238CRITICAL20 abr 2024
H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accesse
75RISCO
abrir
GitHub PoC1
H3C ER8300G2-X config download
CVE-2024-32238CRITICAL20 abr 2024
H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accesse
75RISCO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHsob ataque19 abr 2024
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
anteriorpágina 405 / 2.569próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.