Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.386exploits catalogados
36.533CVEs com exploração pública
24.695testados em laboratório
24.466 exploits
Exploit-DB
Progress Telerik Report Server 2024 Q1 (10.0.24.305) - Authentication Bypass
CVE-2024-4358CRITICALsob ataquewebappsmultiple28 mar 2025
Registration Authentication Bypass Vulnerability
100RISCO
abrir
Exploit-DB
X2CRM 8.5 - Stored Cross-Site Scripting (XSS)
CVE-2024-48120MEDIUMwebappsphp27 mar 2025
X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module. An attacker can inject ma
33RISCO
abrir
Exploit-DB
KubeSphere 3.4.0 - Insecure Direct Object Reference (IDOR)
CVE-2024-46528MEDIUMwebappsmultiple27 mar 2025
An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSp
33RISCO
abrir
Exploit-DB
MoziloCMS 3.0 - Remote Code Execution (RCE)
CVE-2024-44871HIGHwebappsphp27 mar 2025
An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute a
46RISCO
abrir
Exploit-DB
NVIDIA Container Toolkit 1.16.1 - Time-of-check Time-of-Use (TOCTOU)
CVE-2024-0132CRITICALlocallinux26 mar 2025
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with de
60RISCO
abrir
Exploit-DB
Microsoft Windows - NTLM Hash Leak Malicious Windows Theme
CVE-2024-21320MEDIUMremotewindows22 mar 2025
Windows Themes Spoofing Vulnerability
38RISCO
abrir
Exploit-DB
TeamPass 3.0.0.21 - SQL Injection
CVE-2023-1545HIGHwebappsphp22 mar 2025
SQL Injection in nilsteampassnet/teampass
41RISCO
abrir
Exploit-DB
JUX Real Estate 3.4.0 - SQL Injection
CVE-2025-2126MEDIUMwebappsphp20 mar 2025
JoomlaUX JUX Real Estate GET Parameter realties sql injection
38RISCO
abrir
Exploit-DB
Extensive VC Addons for WPBakery page builder 1.9.0 - Remote Code Execution (RCE)
CVE-2023-0159webappsphp19 mar 2025
Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCE
50RISCO
abrir
Exploit-DB
Chamilo LMS 1.11.24 - Remote Code Execution (RCE)
CVE-2023-4220HIGHwebappsphp18 mar 2025
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir
Exploit-DB
openSIS 9.1 - SQLi (Authenticated)
CVE-2024-46626HIGHwebappsphp01 out 2024
OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload.
41RISCO
abrir
Exploit-DB
Devika v1 - Path Traversal via 'snapshot_path'
CVE-2024-40422CRITICALwebappspython04 ago 2024
The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path tr
68RISCO
abrir
Exploit-DB
SolarWinds Platform 2024.1 SR1 - Race Condition
CVE-2024-28999MEDIUMwebappsmultiple26 jun 2024
SolarWinds Platform Race Condition Vulnerability
38RISCO
abrir
Exploit-DB
htmlLawed 1.2.5 - Remote Code Execution (RCE)
CVE-2022-35914CRITICALsob ataquewebappsphp19 mai 2024
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISCO
abrir
Exploit-DB
Rocket LMS 1.9 - Persistent Cross Site Scripting (XSS)
CVE-2024-34241MEDIUMwebappsphp19 mai 2024
A cross-site scripting (XSS) vulnerability in Rocketsoft Rocket LMS 1.9 allows an administrator to store a JavaScript pa
33RISCO
abrir
Exploit-DB
Apache OFBiz 18.12.12 - Directory Traversal
CVE-2024-32113CRITICALsob ataquewebappsjava19 mai 2024
Apache OFBiz: Path traversal leading to RCE
100RISCO
abrir
Exploit-DB
Wordpress Theme XStore 9.3.8 - SQLi
CVE-2024-33559CRITICALwebappsphp19 mai 2024
WordPress XStore theme <= 9.3.5 - Unauthenticated SQL Injection vulnerability
48RISCO
abrir
Exploit-DB
Apache mod_proxy_cluster 1.2.6 - Stored XSS
CVE-2023-6710MEDIUMwebappsphp13 mai 2024
Mod_cluster/mod_proxy_cluster: stored cross site scripting
33RISCO
abrir
Exploit-DB
Laravel Framework 11 - Credential Leakage
CVE-2024-29291webappsphp21 abr 2024
An issue in Laravel Framework 8 through 11 might allow a remote attacker to discover database credentials in storage/log
23RISCO
abrir
Exploit-DB
Palo Alto PAN-OS < v11.1.2-h3 - Command Injection and Arbitrary File Creation
CVE-2024-3400CRITICALsob ataqueransomwareremotelinux_x86-6421 abr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISCO
abrir
Exploit-DB
Jenkins 2.441 - Local File Inclusion
CVE-2024-23897CRITICALsob ataqueransomwarewebappsjava15 abr 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
Exploit-DB
OpenClinic GA 5.247.01 - Information Disclosure
CVE-2023-40278HIGHwebappsphp15 abr 2024
An issue was discovered in OpenClinic GA 5.247.01. An Information Disclosure vulnerability has been identified in the pr
41RISCO
abrir
Exploit-DB
OpenClinic GA 5.247.01 - Path Traversal (Authenticated)
CVE-2023-40279HIGHwebappsphp15 abr 2024
An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page param
41RISCO
abrir
Exploit-DB
djangorestframework-simplejwt 5.3.1 - Information Disclosure
CVE-2024-22513MEDIUMwebappspython15 abr 2024
djangorestframework-simplejwt version 5.3.1 and before is vulnerable to information disclosure. A user can access web ap
33RISCO
abrir
Exploit-DB
GUnet OpenEclass E-learning platform 3.15 - 'certbadge.php' Unrestricted File Upload
CVE-2024-31777CRITICALwebappsphp12 abr 2024
File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted fil
48RISCO
abrir
Exploit-DB
MinIO < 2024-01-31T20-20-33Z - Privilege Escalation
CVE-2024-24747HIGHremotego12 abr 2024
MinIO unsafe default: Access keys inherit `admin` of root user, allowing privilege escalation
53RISCO
abrir
Exploit-DB
Ray OS v2.6.3 - Command Injection RCE(Unauthorized)
CVE-2023-6019CRITICALwebappspython12 abr 2024
Ray Command Injection in cpu_profile Parameter
85RISCO
abrir
Exploit-DB
Daily Habit Tracker 1.0 - Stored Cross-Site Scripting (XSS)
CVE-2024-24494MEDIUMwebappsphp02 abr 2024
Cross Site Scripting vulnerability in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via t
38RISCO
abrir
Exploit-DB
GL-iNet MT6000 4.5.5 - Arbitrary File Download
CVE-2024-27356HIGHremotehardware02 abr 2024
An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially
46RISCO
abrir
Exploit-DB
Employee Management System 1.0 - _txtusername_ and _txtpassword_ SQL Injection (Admin Login)
CVE-2024-24497webappsphp02 abr 2024
20RISCO
abrir
anteriorpágina 16 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.