Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.646exploits catalogados
37.382CVEs com exploração pública
24.695testados em laboratório
15.392 exploits
GitHub PoC2
NSE script that checks for CVE-2025-0108 vulnerability in Palo Alto Networks PAN-OS
CVE-2025-0108HIGHsob ataque19 fev 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RISCO
abrir
GitHub PoC
barcrange/CVE-2025-0108-Authentication-Bypass-checker
CVE-2025-0108HIGHsob ataque19 fev 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RISCO
abrir
GitHub PoC
This report details exploiting Trickster via an XSS in PrestaShop (CVE-2024-34716) to gain www-data access, extracting database credentials for SSH as james. A root shell in Docker is obtained via ChangeDetection.io (CVE-2024-32651), revealing adam’s credentials, followed by root escalation with CVE-2023-47268 in PrusaSlicer.
CVE-2023-47268MEDIUM19 fev 2025
In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrar
33RISCO
abrir
GitHub PoC
POC for CVE-2023-44487
CVE-2023-44487HIGHsob ataque19 fev 2025
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISCO
abrir
GitHub PoC
This report details exploiting Trickster via an XSS in PrestaShop (CVE-2024-34716) to gain www-data access, extracting database credentials for SSH as james. A root shell in Docker is obtained via ChangeDetection.io (CVE-2024-32651), revealing adam’s credentials, followed by root escalation with CVE-2023-47268 in PrusaSlicer.
CVE-2024-34716CRITICAL19 fev 2025
PrestaShop vulnerable to XSS via customer contact form in FO, through file upload
60RISCO
abrir
GitHub PoC
Exploit hecho en python para vsftpd 2.3.4 | CVE-2011-2523
CVE-2011-252319 fev 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
GitHub PoC
A fully functional exploit for a stack-based buffer overflow vulnerability in VideoLan’s VLC Media Player 0.9.4 when processing TiVo files.
CVE-2008-465419 fev 2025
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RISCO
abrir
GitHub PoC
CVE-2023-4911-Looney-Tunables
CVE-2023-4911HIGHsob ataque18 fev 2025
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISCO
abrir
GitHub PoC2
Detects an authentication bypass vulnerability in Palo Alto PAN-OS (CVE-2025-0108).
CVE-2025-0108HIGHsob ataque18 fev 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RISCO
abrir
GitHub PoC13
Proof of concept exploit for Ivanti EPM CVE-2024-13159 and others
CVE-2024-13159CRITICALsob ataque18 fev 2025
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
100RISCO
abrir
GitHub PoC1
Exploitation Script for CVE-2021-3560
CVE-2021-3560HIGHsob ataque18 fev 2025
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISCO
abrir
GitHub PoC3
sariamubeen/CVE-2023-7028
CVE-2023-7028CRITICALsob ataque17 fev 2025
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISCO
abrir
GitHub PoC1
skrkcb2/CVE-2025-0851
CVE-2025-0851CRITICAL17 fev 2025
Path traversal issue in Deep Java Library
53RISCO
abrir
GitHub PoC
sariamubeen/CVE-2024-10924
CVE-2024-10924CRITICAL17 fev 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir
GitHub PoC1
This Proof of Concept (PoC) demonstrates the exploitation of the CVE-2024-4367 vulnerability, which involves Cross-Site Scripting (XSS) attacks.
CVE-2024-4367MEDIUM17 fev 2025
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir
GitHub PoC
This repository provides an in-depth analysis of the Log4Shell vulnerability (CVE-2021-44228) and implements a machine learning-based approach to detect exploitation attempts in log data.
CVE-2021-44228CRITICALsob ataqueransomware17 fev 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
This repository contains a Python script to exploit two vulnerabilities: CVE-2019-18818 and CVE-2019-19609.
CVE-2019-1881816 fev 2025
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISCO
abrir
GitHub PoC
ModeBrutal/CVE-2024-5084-Auto-Exploit
CVE-2024-5084CRITICAL16 fev 2025
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
75RISCO
abrir
GitHub PoC9
POC for CVE-2024-42327: Zabbix Privilege Escalation -> RCE
CVE-2024-42327CRITICAL16 fev 2025
SQL injection in user.get API
70RISCO
abrir
GitHub PoC43
CVE-2025-24016: Wazuh Unsafe Deserialization Remote Code Execution (RCE)
CVE-2025-24016CRITICALsob ataque16 fev 2025
Remote code execution in Wazuh server
100RISCO
abrir
GitHub PoC
Explore CVE-2023-33580 (XSS) & CVE-2023-33584 (SQLI) discovered by me. Dive into vulnerabilities and exploits for insights.
CVE-2023-3358016 fev 2025
Phpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" f
23RISCO
abrir
GitHub PoC
hopsypopsy8/CVE-2020-1938-Exploitation
CVE-2020-1938CRITICALsob ataque15 fev 2025
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
GitHub PoC1
Browser exploitation framework for Chakra (Edge). Written as part of OSEE preparation. Demo bug: CVE-2019-0567
CVE-2019-056715 fev 2025
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RISCO
abrir
GitHub PoC2
A Proof-of-Concept (PoC) exploit for CVE-2024-10924, a vulnerability in the Really Simple SSL WordPress plugin that allows bypassing two-factor authentication (2FA). Includes mitigation techniques to secure affected WordPress sites.
CVE-2024-10924CRITICAL14 fev 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir
GitHub PoC
Didarul342/CVE-2024-4577
CVE-2024-4577CRITICALsob ataqueransomware14 fev 2025
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC8
PoC exploit for CVE-2025-0108 - PAN-OS Authentication Bypass
CVE-2025-0108HIGHsob ataque14 fev 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RISCO
abrir
GitHub PoC
php-cgi-cve-2024-4577
CVE-2024-4577CRITICALsob ataqueransomware14 fev 2025
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
CVE-2016-6914-UniFiVideo-LPE
CVE-2016-691413 fev 2025
Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local u
23RISCO
abrir
GitHub PoC
CMS Made Simple < 2.2.10 - SQL Injection python3
CVE-2019-905313 fev 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
GitHub PoC
Apache Struts CVE-2024-53677 Exploitation
CVE-2024-53677CRITICAL13 fev 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir
anteriorpágina 229 / 514próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.