Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.385exploits catalogados
36.532CVEs com exploração pública
24.695testados em laboratório
24.466 exploits
Exploit-DB
XWiki Platform 15.10.10 - Remote Code Execution
CVE-2025-24893CRITICALsob ataquewebappsmultiple07 abr 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
Exploit-DB
YesWiki 4.5.1 - Unauthenticated Path Traversal
CVE-2025-31131HIGHwebappsmultiple07 abr 2025
Path Traversal allowing arbitrary read of files in Yeswiki
56RISCO
abrir
Exploit-DB
Reservit Hotel 2.1 - Stored Cross-Site Scripting (XSS)
CVE-2024-9458MEDIUMwebappsphp06 abr 2025
Reservit Hotel < 3.0 - Admin+ Stored XSS
33RISCO
abrir
Exploit-DB
Backup and Staging by WP Time Capsule 1.22.21 - Unauthenticated Arbitrary File Upload
CVE-2024-8856CRITICALwebappsphp06 abr 2025
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RISCO
abrir
Exploit-DB
Watcharr 1.43.0 - Remote Code Execution (RCE)
CVE-2024-48827HIGHwebappsmultiple06 abr 2025
An issue in sbondCo Watcharr v.1.43.0 allows a remote attacker to execute arbitrary code and escalate privileges via the
41RISCO
abrir
Exploit-DB
DataEase 2.4.0 - Database Configuration Information Exposure
CVE-2024-30269MEDIUMwebappsjava06 abr 2025
DataEase has database configuration information exposure vulnerability
53RISCO
abrir
Exploit-DB
Palo Alto Networks Expedition 1.2.90.1 - Admin Account Takeover
CVE-2024-5910CRITICALsob ataquewebappsmultiple06 abr 2025
Expedition: Missing Authentication Leads to Admin Account Takeover
100RISCO
abrir
Exploit-DB
Next.js Middleware 15.2.2 - Authorization Bypass
CVE-2025-29927CRITICALwebappsmultiple05 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
Exploit-DB
IBM Security Verify Access 10.0.0 - Open Redirect during OAuth Flow
CVE-2024-35133MEDIUMwebappsmultiple05 abr 2025
IBM Security Verify Access HTTP open redirect
33RISCO
abrir
Exploit-DB
Kubio AI Page Builder 2.5.1 - Local File Inclusion (LFI)
CVE-2025-2294CRITICALwebappsmultiple05 abr 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISCO
abrir
Exploit-DB
Exclusive Addons for Elementor 2.6.9 - Stored Cross-Site Scripting (XSS)
CVE-2024-1234MEDIUMwebappsmultiple05 abr 2025
Exclusive Addons for Elementor <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
33RISCO
abrir
Exploit-DB
Microchip TimeProvider 4100 Grandmaster (Data plot modules) 2.4.6 - SQL Injection
CVE-2024-7801MEDIUMremotehardware05 abr 2025
SQL injection in get_chart_data in TimeProvider 4100
33RISCO
abrir
Exploit-DB
Royal Elementor Addons and Templates 1.3.78 - Unauthenticated Arbitrary File Upload
CVE-2023-5360webappsmultiple05 abr 2025
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RISCO
abrir
Exploit-DB
Microchip TimeProvider 4100 (Configuration modules) 2.4.6 - OS Command Injection
CVE-2024-9054HIGHremotehardware04 abr 2025
Remote code Execution inTimeProvider® 4100
46RISCO
abrir
Exploit-DB
Microchip TimeProvider 4100 Grandmaster (Banner Config Modules) 2.4.6 - Stored Cross-Site Scripting (XSS)
CVE-2024-43687HIGHremotehardware04 abr 2025
XSS vulnerability in bannerconfig endpoint in TimeProvider 4100
41RISCO
abrir
Exploit-DB
Angular-Base64-Upload Library 0.1.20 - Remote Code Execution (RCE)
CVE-2024-42640CRITICALremotemultiple04 abr 2025
angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Explo
75RISCO
abrir
Exploit-DB
AppSmith 1.47 - Remote Code Execution (RCE)
CVE-2024-55963MEDIUMwebappsjava03 abr 2025
An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the
45RISCO
abrir
Exploit-DB
Webmin Usermin 2.100 - Username Enumeration
CVE-2024-44762MEDIUMwebappsperl03 abr 2025
A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid
48RISCO
abrir
Exploit-DB
Vite 6.2.2 - Arbitrary File Read
CVE-2025-30208MEDIUMremotemultiple03 abr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir
Exploit-DB
ABB Cylon Aspect 3.07.01 - Hard-coded Default Credentials
CVE-2024-4007HIGHwebappsphp03 abr 2025
Hard coded default credential contained in install package
41RISCO
abrir
Exploit-DB
Microsoft Office 2019 MSO Build 1808 - NTLMv2 Hash Disclosure
CVE-2024-38200MEDIUMremotewindows03 abr 2025
Microsoft Office Spoofing Vulnerability
38RISCO
abrir
Exploit-DB
ABB Cylon Aspect 3.08.01 - Arbitrary File Delete
CVE-2024-6209CRITICALwebappsphp02 abr 2025
unauthorized file access
53RISCO
abrir
Exploit-DB
Elaine's Realtime CRM Automation 6.18.17 - Reflected XSS
CVE-2024-42831MEDIUMwebappsphp02 abr 2025
A reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to ex
33RISCO
abrir
Exploit-DB
ABB Cylon Aspect 3.08.01 - Remote Code Execution (RCE)
CVE-2024-6298CRITICALwebappsmultiple02 abr 2025
remote code execution
53RISCO
abrir
Exploit-DB
SAP NetWeaver - 7.53 - HTTP Request Smuggling
CVE-2022-22536CRITICALsob ataqueremotemultiple02 abr 2025
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RISCO
abrir
Exploit-DB
XWiki Standard 14.10 - Remote Code Execution (RCE)
CVE-2023-48292CRITICALwebappsphp29 mar 2025
XWiki Admin Tools Application Run Shell Command allows CSRF RCE attacks
53RISCO
abrir
Exploit-DB
Progress Telerik Report Server 2024 Q1 (10.0.24.305) - Authentication Bypass
CVE-2024-4358CRITICALsob ataquewebappsmultiple28 mar 2025
Registration Authentication Bypass Vulnerability
100RISCO
abrir
Exploit-DB
CodeCanyon RISE CRM 3.7.0 - SQL Injection
CVE-2024-8945MEDIUMwebappsphp28 mar 2025
CodeCanyon RISE Ultimate Project Manager save sql injection
38RISCO
abrir
Exploit-DB
Litespeed Cache 6.5.0.1 - Authentication Bypass
CVE-2024-44000CRITICALwebappsphp28 mar 2025
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RISCO
abrir
Exploit-DB
Sonatype Nexus Repository 3.53.0-01 - Path Traversal
CVE-2024-4956HIGHwebappsmultiple28 mar 2025
Nexus Repository 3 - Path Traversal
61RISCO
abrir
anteriorpágina 15 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.