Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.557exploits catalogados
37.313CVEs com exploração pública
24.695testados em laboratório
15.367 exploits
GitHub PoC7
CVE-2024-42009 Proof of Concept
CVE-2024-42009CRITICALsob ataque24 mai 2025
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RISCO
abrir
GitHub PoC
0xWhoami35/CVE-2025-2294
CVE-2025-2294CRITICAL24 mai 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISCO
abrir
GitHub PoC1
davidxbors/CVE-2025-25014
CVE-2025-25014CRITICAL24 mai 2025
Kibana arbitrary code execution via prototype pollution
53RISCO
abrir
GitHub PoC
enochgitgamefied/NextJS-CVE-2025-29927-Docker-Lab
CVE-2025-29927CRITICAL23 mai 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
Unauthenticated Arbitrary File Read via Absolute Path
CVE-2025-46822HIGH23 mai 2025
Unauthenticated Arbitrary File Read via Absolute Path
56RISCO
abrir
GitHub PoC
pouriam23/CVE-2024-12583
CVE-2024-12583CRITICAL23 mai 2025
Dynamics 365 Integration <= 1.3.23 - Authenticated (Contributor+) Remote Code Execution and Arbitrary File Read via Twig Server-Side Template Injection
48RISCO
abrir
GitHub PoC
fatkz/CVE-2022-24112
CVE-2022-24112CRITICALsob ataque23 mai 2025
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RISCO
abrir
GitHub PoC1
Shuhaib88/Baron-Samedit-Heap-Buffer-Overflow-CVE-2021-3156
CVE-2021-3156HIGHsob ataque23 mai 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC
encrypter15/CVE-2025-30400
CVE-2025-30400HIGHsob ataque23 mai 2025
Microsoft DWM Core Library Elevation of Privilege Vulnerability
71RISCO
abrir
GitHub PoC5
🛡️ CVE-2025-31161 - CrushFTP User Creation Authentication Bypass Exploit
CVE-2025-31161CRITICALsob ataqueransomware23 mai 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISCO
abrir
GitHub PoC1
Proof of Concept for CVE-2024-9463
CVE-2024-9463CRITICALsob ataque22 mai 2025
Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure
100RISCO
abrir
GitHub PoC58
Script to exploit Grafana CVE-2025-4123: XSS and Full-Read SSRF
CVE-2025-4123HIGH22 mai 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISCO
abrir
GitHub PoC1
Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover
CVE-2025-4322CRITICAL22 mai 2025
Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover
68RISCO
abrir
GitHub PoC2
Public disclosure of CVE-2025-31200 – Zero-click RCE in iOS 18.X via AudioConverterService and malicious audio file.
CVE-2025-31200CRITICALsob ataque22 mai 2025
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4
83RISCO
abrir
GitHub PoC2
Proof-of-concept scanner targeting CVE-2024-21762 in FortiOS SSL VPN’s /remote/hostcheck_validate endpoint with reverse shell payload delivery.
CVE-2024-21762CRITICALsob ataqueransomware22 mai 2025
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISCO
abrir
GitHub PoC
finn79426/CVE-2020-10199
CVE-2020-10199HIGHsob ataque21 mai 2025
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISCO
abrir
GitHub PoC
CVE-2021-34527 is a critical remote code execution and local privilege escalation vulnerability dubbed "PrintNightmare."
CVE-2021-34527HIGHsob ataqueransomware21 mai 2025
Windows Print Spooler Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
RdBBB3/SHELL-POC-CVE-2022-46169
CVE-2022-46169CRITICALsob ataque21 mai 2025
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC1
eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Upload via set_image Task
CVE-2025-5058CRITICAL21 mai 2025
eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Upload via set_image()
48RISCO
abrir
GitHub PoC5
Exploitation and Post-Exploitation Multitool for Palo Alto PAN-OS Systems affected by vulnerabilities CVE-2024-0012 and CVE-2024-9474
CVE-2024-0012CRITICALsob ataqueransomware21 mai 2025
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISCO
abrir
GitHub PoC1
IndominusRexes/CVE-2025-4322-Exploit
CVE-2025-4322CRITICAL20 mai 2025
Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover
68RISCO
abrir
GitHub PoC2
PoC and vulnerability report for CVE-2025-47827.
CVE-2025-47827MEDIUMsob ataque20 mai 2025
In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptograph
63RISCO
abrir
GitHub PoC
HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion (LFI)
CVE-2025-1661CRITICAL20 mai 2025
HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion
75RISCO
abrir
GitHub PoC
PoC for CVE-2025-47646 - WordPress PSW Front-end Login Registration Plugin ≤ 1.12 Unauthenticated Privilege Escalation
CVE-2025-47646CRITICAL20 mai 2025
WordPress PSW Front-end Login & Registration plugin <= 1.13 - Broken Authentication Vulnerability
68RISCO
abrir
GitHub PoC
CVE-2024-53677
CVE-2024-53677CRITICAL20 mai 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir
GitHub PoC
It was determined that malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. # It was determined that only certain operating systems and operating system versions were affected by this vulnerability.
CVE-2024-3094CRITICAL20 mai 2025
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC
The `swp_debug` parameter in `admin-post.php` allows remote attackers to include external files containing malicious PHP code, which are evaluated on the server. By supplying a crafted URL that hosts a reverse shell payload, an attacker can gain command execution.
CVE-2019-9978MEDIUMsob ataque19 mai 2025
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir
GitHub PoC
Automated path traversal testing tool for Grafana plugin endpoints using curl and Bash.
CVE-2021-43798HIGHsob ataque19 mai 2025
Grafana path traversal
100RISCO
abrir
GitHub PoC1
Vulnerabilidad NTLM (CVE-2025-24054) explotada para robo de hashes
CVE-2025-24054MEDIUMsob ataque19 mai 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RISCO
abrir
GitHub PoC
Um script automatizado melhorando o exploit do cve-2011-0762 postado no exploit-db
CVE-2011-076219 mai 2025
The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a deni
60RISCO
abrir
anteriorpágina 207 / 513próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.