Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.432exploits catalogados
34.424CVEs com exploração pública
24.695testados em laboratório
13.618 exploits
GitHub PoC
POC for CVE-2025-24813 using Spring-Boot
CVE-2025-24813CRITICALsob ataque20 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC1
CVE-2012-1823 exploit for https user password website.
CVE-2012-1823CRITICALsob ataque20 mar 2025
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RISCO
abrir
GitHub PoC1
minhluannguyen/CVE-2020-7247-reproducer
CVE-2020-7247CRITICALsob ataque20 mar 2025
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISCO
abrir
GitHub PoC
PoC tool designed to exploit an authenticated Remote Code Execution (RCE) vulnerability in certain versions of PostgreSQL (9.3 - 11.7)
CVE-2019-919320 mar 2025
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISCO
abrir
GitHub PoC
The POC and Lab setup documentation of CVE 2021 41773
CVE-2021-41773HIGHsob ataqueransomware20 mar 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware19 mar 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
Resources for teh Apache Tomcat CVE lab
CVE-2025-24813CRITICALsob ataque19 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC
Apache Tomcat Vulnerability POC (CVE-2025-24813)
CVE-2025-24813CRITICALsob ataque19 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC
CVE-2018-7600.
CVE-2018-7600CRITICALsob ataqueransomware19 mar 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC
Windows File Explorer Spoofing Vulnerability (CVE-2025-24071)
CVE-2025-24071MEDIUM19 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
GitHub PoC2
Alternativa CVE-2025-24071_PoC
CVE-2025-24071MEDIUM19 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
GitHub PoC2
Koha CVE-2025-22954: SQL Injection in lateissues-export.pl
CVE-2025-22954CRITICAL19 mar 2025
GetLateOrMissingIssues in C4/Serials.pm in Koha before 24.11.02 allows SQL Injection in /serials/lateissues-export.pl vi
53RISCO
abrir
GitHub PoC25
Metasploit module for CVE-2025-24071 - Windows NTLM Hash Leak via .library-ms
CVE-2025-24071MEDIUM18 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
GitHub PoC
HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion (LFI)
CVE-2025-1661CRITICAL18 mar 2025
HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion
75RISCO
abrir
GitHub PoC6
Apache Tomcat Remote Code Execution (RCE) Exploit - CVE-2025-24813
CVE-2025-24813CRITICALsob ataque18 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC1
Checkmarx/Checkmarx-CVE-2025-30066-Detection-Tool
CVE-2025-30066HIGHsob ataque18 mar 2025
tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 thr
93RISCO
abrir
GitHub PoC2
CVE-2024-57040 is a security vulnerability found in certain TP-Link TL-WR845N router models. Specifically, it involves a "hardcoded" password for the router's root account. This means a default, unchanging password is built into the router's software.
CVE-2024-57040CRITICAL18 mar 2025
TP-Link TL-WR845N devices with firmware TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a
48RISCO
abrir
GitHub PoC1
iOS/macOS library that exploits CVE-2023-41991 for signing iOS applications.
CVE-2023-41991MEDIUMsob ataque18 mar 2025
A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A mal
63RISCO
abrir
GitHub PoC7
Otsmane-Ahmed/cve-2025-29384-poc
CVE-2025-29384CRITICAL18 mar 2025
In Tenda AC9 v1.0 V15.03.05.14_multi, the wanMTU parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability
48RISCO
abrir
GitHub PoC1
WordPress WPMasterToolKit plugin <= 1.13.1 - Arbitrary File Upload vulnerability
CVE-2024-56249CRITICAL18 mar 2025
WordPress WPMasterToolKit plugin <= 1.13.1 - Arbitrary File Upload vulnerability
48RISCO
abrir
GitHub PoC
regantemudo/CVE-2024-25641-Exploit-for-Cacti-1.2.26
CVE-2024-25641CRITICAL17 mar 2025
Cacti RCE vulnerability when importing packages
85RISCO
abrir
GitHub PoC
KillReal01/CVE-2023-4911
CVE-2023-4911HIGHsob ataque17 mar 2025
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISCO
abrir
GitHub PoC1
orilevy8/cve-2023-0386
CVE-2023-0386HIGHsob ataque17 mar 2025
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISCO
abrir
GitHub PoC3
Nuclei Template CVE-2025–24813
CVE-2025-24813CRITICALsob ataque17 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC1
Jimmy01240397/CVE-2024-12641_12642_12645
CVE-2024-12641CRITICAL17 mar 2025
Chunghwa Telecom TenderDocTransfer - Reflected Cross-site Scripting to RCE
48RISCO
abrir
GitHub PoC16
CVE-2025-24813利用工具
CVE-2025-24813CRITICALsob ataque16 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC2
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.
CVE-2023-30258CRITICAL16 mar 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISCO
abrir
GitHub PoC
RCE, Citirx ADC and Gateway Directory Traversal
CVE-2019-19781CRITICALsob ataqueransomware16 mar 2025
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
GitHub PoC
DavidBr27/CVE-2013-3900-Remediation-Script
CVE-2013-3900MEDIUMsob ataque16 mar 2025
WinVerifyTrust Signature Validation Vulnerability
75RISCO
abrir
GitHub PoC405
CVE-2025-24071: NTLM Hash Leak via RAR/ZIP Extraction and .library-ms File
CVE-2025-24071MEDIUM16 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
anteriorpágina 173 / 454próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.