Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

72.018exploits catalogados
32.219CVEs com exploração pública
1.932testados em laboratório
13.334 exploits
GitHub PoC5
🛡️ CVE-2025-31161 - CrushFTP User Creation Authentication Bypass Exploit
CVE-2025-31161CRITICALsob ataqueransomware23 mai 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISCO
abrir
GitHub PoC
Unauthenticated Arbitrary File Read via Absolute Path
CVE-2025-46822HIGH23 mai 2025
Unauthenticated Arbitrary File Read via Absolute Path
56RISCO
abrir
GitHub PoC
Shuhaib88/Baron-Samedit-Heap-Buffer-Overflow-CVE-2021-3156
CVE-2021-3156HIGHsob ataque23 mai 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC1
Proof of Concept for CVE-2024-9463
CVE-2024-9463CRITICALsob ataque22 mai 2025
Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure
100RISCO
abrir
GitHub PoC2
Proof-of-concept scanner targeting CVE-2024-21762 in FortiOS SSL VPN’s /remote/hostcheck_validate endpoint with reverse shell payload delivery.
CVE-2024-21762CRITICALsob ataqueransomware22 mai 2025
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISCO
abrir
GitHub PoC2
Public disclosure of CVE-2025-31200 – Zero-click RCE in iOS 18.X via AudioConverterService and malicious audio file.
CVE-2025-31200CRITICALsob ataque22 mai 2025
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4
83RISCO
abrir
GitHub PoC1
Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover
CVE-2025-4322CRITICAL22 mai 2025
Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover
68RISCO
abrir
GitHub PoC56
Script to exploit Grafana CVE-2025-4123: XSS and Full-Read SSRF
CVE-2025-4123HIGH22 mai 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISCO
abrir
GitHub PoC1
eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Upload via set_image Task
CVE-2025-5058CRITICAL21 mai 2025
eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Upload via set_image()
48RISCO
abrir
GitHub PoC5
Exploitation and Post-Exploitation Multitool for Palo Alto PAN-OS Systems affected by vulnerabilities CVE-2024-0012 and CVE-2024-9474
CVE-2024-0012CRITICALsob ataqueransomware21 mai 2025
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISCO
abrir
GitHub PoC
CVE-2021-34527 is a critical remote code execution and local privilege escalation vulnerability dubbed "PrintNightmare."
CVE-2021-34527HIGHsob ataqueransomware21 mai 2025
Windows Print Spooler Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
RdBBB3/SHELL-POC-CVE-2022-46169
CVE-2022-46169CRITICALsob ataque21 mai 2025
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC2
PoC and vulnerability report for CVE-2025-47827.
CVE-2025-47827MEDIUMsob ataque20 mai 2025
In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptograph
63RISCO
abrir
GitHub PoC1
IndominusRexes/CVE-2025-4322-Exploit
CVE-2025-4322CRITICAL20 mai 2025
Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover
68RISCO
abrir
GitHub PoC
HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion (LFI)
CVE-2025-1661CRITICAL20 mai 2025
HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion
75RISCO
abrir
GitHub PoC
It was determined that malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. # It was determined that only certain operating systems and operating system versions were affected by this vulnerability.
CVE-2024-3094CRITICAL20 mai 2025
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC
CVE-2024-53677
CVE-2024-53677CRITICAL20 mai 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir
GitHub PoC
PoC for CVE-2025-47646 - WordPress PSW Front-end Login Registration Plugin ≤ 1.12 Unauthenticated Privilege Escalation
CVE-2025-47646CRITICAL20 mai 2025
WordPress PSW Front-end Login & Registration plugin <= 1.13 - Broken Authentication Vulnerability
68RISCO
abrir
GitHub PoC
Um script automatizado melhorando o exploit do cve-2011-0762 postado no exploit-db
CVE-2011-076219 mai 2025
The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a deni
60RISCO
abrir
GitHub PoC
Vulnerabilidad NTLM (CVE-2025-24054) explotada para robo de hashes
CVE-2025-24054MEDIUMsob ataque19 mai 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RISCO
abrir
GitHub PoC
Automated path traversal testing tool for Grafana plugin endpoints using curl and Bash.
CVE-2021-43798HIGHsob ataque19 mai 2025
Grafana path traversal
100RISCO
abrir
GitHub PoC
The `swp_debug` parameter in `admin-post.php` allows remote attackers to include external files containing malicious PHP code, which are evaluated on the server. By supplying a crafted URL that hosts a reverse shell payload, an attacker can gain command execution.
CVE-2019-9978MEDIUMsob ataque19 mai 2025
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir
GitHub PoC4
Designed for Demonstration of Deep Exploitation.
CVE-2025-32756CRITICALsob ataque18 mai 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RISCO
abrir
GitHub PoC
Mitel MiCollab Authentication Bypass to Arbitrary File Read
CVE-2024-41713CRITICALsob ataqueransomware18 mai 2025
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could
100RISCO
abrir
GitHub PoC
tdevworks/CVE-2020-1472-ZeroLogon-Demo-Detection-Mitigation
CVE-2020-1472MEDIUMsob ataqueransomware17 mai 2025
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC200
CVE-2025-31200 is a zero-day, zero-click RCE in iOS CoreAudio’s AudioConverterService, triggered by a malicious audio file via iMessage/SMS. Exploitation bypassed Blastdoor, enabled kernel escalation (CVE-2025-31201), and allowed token theft until patched in iOS 18.4.1 (Apr 16, 2025).
CVE-2025-31200CRITICALsob ataque17 mai 2025
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4
83RISCO
abrir
GitHub PoC4
Eventin <= 4.0.26 - Missing Authorization to Unauthenticated Privilege Escalation
CVE-2025-47539CRITICAL17 mai 2025
WordPress Eventin plugin <= 4.0.26 - Privilege Escalation Vulnerability
75RISCO
abrir
GitHub PoC
Automation Exploit
CVE-2021-4034HIGHsob ataque17 mai 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
tdevworks/CVE-2020-0796-SMBGhost-Exploit-Demo
CVE-2020-0796CRITICALsob ataqueransomware17 mai 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC
CyprianAtsyor/LetsDefend-CVE-2022-41082-Exploitation-Attempt
CVE-2022-41082HIGHsob ataqueransomware16 mai 2025
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
anteriorpágina 148 / 445próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.