Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.445exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
13.627 exploits
GitHub PoC
dorattias/CVE-2025-26319
CVE-2025-26319CRITICAL02 fev 2025
FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.
75RISCO
abrir
GitHub PoC2
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
CVE-2024-10924CRITICAL02 fev 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir
GitHub PoC2
CVE-2024-56901 - A Cross-Site Request Forgery (CSRF) vulnerability in Geovision GV-ASManager web application with the version 6.1.1.0 or less that allows attackers to arbitrarily create Admin accounts via a crafted POST request.
CVE-2024-56901HIGH02 fev 2025
A Cross-Site Request Forgery (CSRF) vulnerability in Geovision GV-ASWeb application with the version 6.1.1.0 or less tha
41RISCO
abrir
GitHub PoC
CVE-2017-8869 - MediaCoder 0.8.48.5888 - Local Buffer Overflow (SEH)
CVE-2017-886902 fev 2025
Buffer overflow in MediaCoder 0.8.48.5888 allows remote attackers to execute arbitrary code via a crafted .m3u file.
43RISCO
abrir
GitHub PoC
This repository contains a Proof-of-Concept for the CVE-2021-41773. This CVE contains a LFI and RCE vulnerablity.
CVE-2021-41773HIGHsob ataqueransomware02 fev 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC1
## About The script has been made for exploiting the Laravel RCE (CVE-2021-3129) vulnerability.<br> This script allows you to write/execute commands on a website running <b>Laravel <= v8.4.2</b>, that has "APP_DEBUG" set to "true" in its ".env" file.
CVE-2021-3129CRITICALsob ataqueransomware30 jan 2025
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
GitHub PoC
lukwagoasuman/-home-lukewago-Downloads-CVE-2021-23017-Nginx-1.14
CVE-2021-2301730 jan 2025
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t
35RISCO
abrir
GitHub PoC
asepsaepdin/CVE-2021-42013
CVE-2021-42013CRITICALsob ataqueransomware30 jan 2025
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC15
CVE-2024-8381: A SpiderMonkey Interpreter Type Confusion Bug.
CVE-2024-8381CRITICAL30 jan 2025
A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as t
48RISCO
abrir
GitHub PoC6
Proof of Concept for CVE-2022-45460
CVE-2022-45460CRITICAL30 jan 2025
Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C74311
48RISCO
abrir
GitHub PoC
asepsaepdin/CVE-2022-36804
CVE-2022-36804HIGHsob ataque30 jan 2025
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
GitHub PoC
asepsaepdin/CVE-2023-32315
CVE-2023-32315HIGHsob ataque30 jan 2025
Openfire administration console authentication bypass
100RISCO
abrir
GitHub PoC50
An XNU kernel race condition bug
CVE-2025-24118CRITICAL30 jan 2025
The issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.4, macOS Sequoia 15.3, macOS S
48RISCO
abrir
GitHub PoC4
honeyb33z/cve-2020-11023-scanner
CVE-2020-11023MEDIUMsob ataque30 jan 2025
Potential XSS vulnerability in jQuery
85RISCO
abrir
GitHub PoC
asepsaepdin/CVE-2022-33891
CVE-2022-33891HIGHsob ataque30 jan 2025
Apache Spark shell command injection vulnerability via Spark UI
100RISCO
abrir
GitHub PoC1
bsec404/CVE-2020-0796
CVE-2020-0796CRITICALsob ataqueransomware29 jan 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC1
A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.
CVE-2024-12084CRITICAL29 jan 2025
Rsync: heap buffer overflow in rsync due to improper checksum length handling
70RISCO
abrir
GitHub PoC11
A comprehensive all-in-one Python-based Proof of Concept script to discover and exploit a critical authentication bypass vulnerability (CVE-2024-55591) in certain Fortinet devices.
CVE-2024-55591CRITICALsob ataqueransomware29 jan 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISCO
abrir
GitHub PoC
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
CVE-2024-11972CRITICAL29 jan 2025
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
75RISCO
abrir
GitHub PoC3
watchtowrlabs/nakivo-arbitrary-file-read-poc-CVE-2024-48248
CVE-2024-48248HIGHsob ataque28 jan 2025
NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /
100RISCO
abrir
GitHub PoC2
Ivanti Connect Secure, Policy Secure & ZTA Gateways - CVE-2025-0282
CVE-2025-0282CRITICALsob ataqueransomware28 jan 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RISCO
abrir
GitHub PoC1
7-Zip Mark-of-the-Web绕过漏洞PoC(CVE-2025-0411)
CVE-2025-0411HIGHsob ataque27 jan 2025
7-Zip Mark-of-the-Web Bypass Vulnerability
83RISCO
abrir
GitHub PoC77
watchtowrlabs/fortios-auth-bypass-poc-CVE-2024-55591
CVE-2024-55591CRITICALsob ataqueransomware27 jan 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISCO
abrir
GitHub PoC289
针对JWT渗透开发的漏洞验证/密钥爆破工具,针对CVE-2015-9235/空白密钥/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ,也可使用字典/字符枚举(包括JJWT)的方式进行爆破(JWT Crack)
CVE-2018-011427 jan 2025
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISCO
abrir
GitHub PoC
A rewrite of the Polkit vulnerability.
CVE-2021-4034HIGHsob ataque27 jan 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
CVE-2021-43798 working exploit
CVE-2021-43798HIGHsob ataque26 jan 2025
Grafana path traversal
100RISCO
abrir
GitHub PoC
Repository for internship test task.
CVE-2024-25600CRITICAL26 jan 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir
GitHub PoC1
CVE-2016-2555 Exploit
CVE-2016-255526 jan 2025
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbi
60RISCO
abrir
GitHub PoC4
Exploit for WordPress File Upload Plugin - All versions up to 4.24.11 are vulnerable.
CVE-2024-9047CRITICAL25 jan 2025
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
85RISCO
abrir
GitHub PoC1
Exploit for CVE-2023-4220
CVE-2023-4220HIGH24 jan 2025
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir
anteriorpágina 180 / 455próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.