Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.445exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
13.627 exploits
GitHub PoC
This repository provides an in-depth analysis of the Log4Shell vulnerability (CVE-2021-44228) and implements a machine learning-based approach to detect exploitation attempts in log data.
CVE-2021-44228CRITICALsob ataqueransomware17 fev 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC43
CVE-2025-24016: Wazuh Unsafe Deserialization Remote Code Execution (RCE)
CVE-2025-24016CRITICALsob ataque16 fev 2025
Remote code execution in Wazuh server
100RISCO
abrir
GitHub PoC
ModeBrutal/CVE-2024-5084-Auto-Exploit
CVE-2024-5084CRITICAL16 fev 2025
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
75RISCO
abrir
GitHub PoC9
POC for CVE-2024-42327: Zabbix Privilege Escalation -> RCE
CVE-2024-42327CRITICAL16 fev 2025
SQL injection in user.get API
70RISCO
abrir
GitHub PoC
This repository contains a Python script to exploit two vulnerabilities: CVE-2019-18818 and CVE-2019-19609.
CVE-2019-1881816 fev 2025
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISCO
abrir
GitHub PoC
Explore CVE-2023-33580 (XSS) & CVE-2023-33584 (SQLI) discovered by me. Dive into vulnerabilities and exploits for insights.
CVE-2023-3358016 fev 2025
Phpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" f
23RISCO
abrir
GitHub PoC1
Browser exploitation framework for Chakra (Edge). Written as part of OSEE preparation. Demo bug: CVE-2019-0567
CVE-2019-056715 fev 2025
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RISCO
abrir
GitHub PoC
hopsypopsy8/CVE-2020-1938-Exploitation
CVE-2020-1938CRITICALsob ataque15 fev 2025
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
GitHub PoC8
PoC exploit for CVE-2025-0108 - PAN-OS Authentication Bypass
CVE-2025-0108HIGHsob ataque14 fev 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RISCO
abrir
GitHub PoC2
A Proof-of-Concept (PoC) exploit for CVE-2024-10924, a vulnerability in the Really Simple SSL WordPress plugin that allows bypassing two-factor authentication (2FA). Includes mitigation techniques to secure affected WordPress sites.
CVE-2024-10924CRITICAL14 fev 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir
GitHub PoC
Didarul342/CVE-2024-4577
CVE-2024-4577CRITICALsob ataqueransomware14 fev 2025
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
php-cgi-cve-2024-4577
CVE-2024-4577CRITICALsob ataqueransomware14 fev 2025
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
CVE-2016-6914-UniFiVideo-LPE
CVE-2016-691413 fev 2025
Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local u
23RISCO
abrir
GitHub PoC
Apache Struts CVE-2024-53677 Exploitation
CVE-2024-53677CRITICAL13 fev 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir
GitHub PoC1
This Proof of Concept (PoC) demonstrates an exploit for CVE-2024-42009, leveraging a cross-site scripting (XSS) vulnerability to extract emails from a target webmail application. The attack injects a malicious payload that exfiltrates email content to an attacker-controlled listener.
CVE-2024-42009CRITICALsob ataque13 fev 2025
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RISCO
abrir
GitHub PoC2
POC for Roundcube vulnerabilities CVE-2024-42008 and CVE-2024-42010
CVE-2024-42008CRITICAL13 fev 2025
A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7
60RISCO
abrir
GitHub PoC
luke0x90/CVE-2021-21551
CVE-2021-21551HIGHsob ataque13 fev 2025
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RISCO
abrir
GitHub PoC4
huseyinstif/CVE-2025-24016-Nuclei-Template
CVE-2025-24016CRITICALsob ataque13 fev 2025
Remote code execution in Wazuh server
100RISCO
abrir
GitHub PoC
CMS Made Simple < 2.2.10 - SQL Injection python3
CVE-2019-905313 fev 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
GitHub PoC32
Palo Alto Networks PAN-OS 身份验证绕过漏洞批量检测脚本(CVE-2025-0108)
CVE-2025-0108HIGHsob ataque13 fev 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RISCO
abrir
GitHub PoC
qnole000/CVE-2024-51378
CVE-2024-51378CRITICALsob ataqueransomware12 fev 2025
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
100RISCO
abrir
GitHub PoC
An unauthenticated attacker can force server points to a shell file like ‘/bin/sh’ and execute arbitrary commands due to the failure in verifying the URL which leads to path traversal to any file that exists in the system. Nostromo’s versions such as 1.9.6 fail to verify this URL
CVE-2019-16278CRITICALsob ataque12 fev 2025
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISCO
abrir
GitHub PoC
Active Exploitation of Atlassian’s Questions for Confluence App CVE-2022-26134
CVE-2022-26134CRITICALsob ataqueransomware12 fev 2025
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC
Modified exploit for CVE-2021-43798 compatible with both Windows and Linux hosts.
CVE-2021-43798HIGHsob ataque12 fev 2025
Grafana path traversal
100RISCO
abrir
GitHub PoC1
Exploit for Apache OFBiz - CVE-2024-38856
CVE-2024-38856HIGHsob ataque11 fev 2025
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISCO
abrir
GitHub PoC1
yenyangmjaze/cve-2024-10914
CVE-2024-10914CRITICAL11 fev 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir
GitHub PoC4
This script exploits a stored XSS vulnerability (CVE-2024-42009) in Roundcube Webmail version 1.6.7. It injects a malicious payload into the webmail system, which, when triggered, exfiltrates email content from the victim’s inbox.
CVE-2024-42009CRITICALsob ataque11 fev 2025
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RISCO
abrir
GitHub PoC
Alienfader/CVE-2020-29607
CVE-2020-2960711 fev 2025
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access
35RISCO
abrir
GitHub PoC2
demonstriert, wie mittels missbräuchlicher Nutzung eines Swap-Cookies eine VPN-Session übernommen werden kann. Wichtig: Dieses Projekt dient ausschliesslich zu Bildungs- und Forschungszwecken – bitte nur in Umgebungen verwenden, in denen Du explizit authorisiert bist.
CVE-2024-53704HIGHsob ataqueransomware11 fev 2025
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe
100RISCO
abrir
GitHub PoC
This is a repository for Apache HugeGraph Remote Code Execution vulnerability(CVE-2024-27348))
CVE-2024-27348CRITICALsob ataque10 fev 2025
Apache HugeGraph-Server: Command execution in gremlin
100RISCO
abrir
anteriorpágina 178 / 455próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.