Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.058exploits catalogados
35.300CVEs com exploração pública
24.695testados em laboratório
77.058 exploits
GitHub PoC
YangHyperData/LOGJ4_PocShell_CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware02 abr 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC14
Dockerfile and Kubernetes manifests for reproduce CVE-2024-3094
CVE-2024-3094CRITICAL02 abr 2024
Xz: malicious code in distributed source
70RISCO
abrir
Exploit-DB
Gibbon LMS v26.0.00 - SSTI vulnerability
CVE-2024-24724CRITICALwebappsphp02 abr 2024
Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Re
53RISCO
abrir
Exploit-DB
Daily Habit Tracker 1.0 - SQL Injection
CVE-2024-24495CRITICALwebappsphp02 abr 2024
SQL Injection vulnerability in delete-tracker.php in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbit
48RISCO
abrir
Exploit-DB
Employee Management System 1.0 - _txtusername_ and _txtpassword_ SQL Injection (Admin Login)
CVE-2024-24497webappsphp02 abr 2024
20RISCO
abrir
Exploit-DB
Employee Management System 1.0 - _txtfullname_ and _txtphone_ SQL Injection
CVE-2024-24499webappsphp02 abr 2024
20RISCO
abrir
Exploit-DB
GL-iNet MT6000 4.5.5 - Arbitrary File Download
CVE-2024-27356HIGHremotehardware02 abr 2024
An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially
46RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALsob ataqueransomware02 abr 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC3
apocalypxze: xz backdoor (2024) AKA CVE-2024-3094 related links
CVE-2024-3094CRITICAL02 abr 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC3
CVE-2024-3094 - Checker (fix for arch etc)
CVE-2024-3094CRITICAL02 abr 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC2
Detectar CVE-2024-3094
CVE-2024-3094CRITICAL02 abr 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC
CVE-2024-3094 XZ Backdoor Detector
CVE-2024-3094CRITICAL02 abr 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC
Script en bash para revisar si tienes la vulnerabilidad CVE-2024-3094.
CVE-2024-3094CRITICAL02 abr 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC1
This Repository Includes Kubernetes manifest files for configuration of Honeypot system and Falco IDS in K8s environment. There are also Demo Application written with Node.js which is containing Remote Code Execution Vulnerability (CVE-2023-32314) for demonstrating all addvantages of this architecture to manage Honeypot systems
CVE-2023-32314CRITICAL02 abr 2024
Sandbox Escape
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-1708HIGHsob ataqueransomware02 abr 2024
Improper limitation of a pathname to a restricted directory (“path traversal”)
100RISCO
abrir
Exploit-DB
Axigen < 10.5.7 - Persistent Cross-Site Scripting
CVE-2023-48974CRITICALwebappsphp02 abr 2024
Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges
48RISCO
abrir
GitHub PoC1
cjybao/CVE-2024-1709-and-CVE-2024-1708
CVE-2024-1709CRITICALsob ataqueransomware02 abr 2024
Authentication bypass using an alternate path or channel
100RISCO
abrir
GitHub PoC
XZ-Utils工具库恶意后门植入漏洞(CVE-2024-3094)
CVE-2024-3094CRITICAL01 abr 2024
Xz: malicious code in distributed source
70RISCO
abrir
VulnCheck XDB
local
CVE-2023-32233HIGH01 abr 2024
In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused
46RISCO
abrir
GitHub PoC
mightysai1997/CVE-2024-3094
CVE-2024-3094CRITICAL01 abr 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC
ackemed/detectar_cve-2024-3094
CVE-2024-3094CRITICAL01 abr 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC
This is my malware
CVE-2023-38831HIGHsob ataqueransomware01 abr 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC1
galacticquest/cve-2024-3094-detect
CVE-2024-3094CRITICAL01 abr 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC
mightysai1997/CVE-2024-3094-info
CVE-2024-3094CRITICAL01 abr 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC
dah4k/CVE-2024-3094
CVE-2024-3094CRITICAL01 abr 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC3
Herramientas de linux para diferentes funciones.
CVE-2024-3094CRITICAL01 abr 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC17
XZ Backdoor Extract(Test on Ubuntu 23.10)
CVE-2024-3094CRITICAL01 abr 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC
CVE-2024-3094
CVE-2024-3094CRITICAL01 abr 2024
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC4
Education purpose for CVE-2018-10933
CVE-2018-10933CRITICAL01 abr 2024
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC1
Exploit for CVE-2024-20767 affecting Adobe ColdFusion
CVE-2024-20767HIGHsob ataque01 abr 2024
ColdFusion | Improper Access Control (CWE-284)
100RISCO
abrir
anteriorpágina 411 / 2.569próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.