Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.646exploits catalogados
37.382CVEs com exploração pública
24.695testados em laboratório
15.392 exploits
GitHub PoC1
Incorrect Privilege Assignment vulnerability in nssTheme Wp NssUser Register allows Privilege Escalation.This issue affects Wp NssUser Register: from n/a through 1.0.0.
CVE-2024-54363CRITICAL16 jan 2025
WordPress Wp NssUser Register plugin <= 1.0.0 - Privilege Escalation vulnerability
48RISCO
abrir
GitHub PoC87
Research repository tracking affected IPs from the Fortigate CVE-2022-40684 configuration leak by Belsen Group
CVE-2022-40684CRITICALsob ataqueransomware16 jan 2025
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir
GitHub PoC1
Palo Alto RCE Vuln
CVE-2024-9474MEDIUMsob ataqueransomware16 jan 2025
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RISCO
abrir
GitHub PoC1
A Python tool leveraging Shodan and Scapy to identify and exploit Windows systems vulnerable to CVE-2024-38063, enabling targeted Denial of Service attacks
CVE-2024-38063CRITICAL16 jan 2025
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC1
Proof of concept for CVE-2022-31814
CVE-2022-31814CRITICAL16 jan 2025
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISCO
abrir
GitHub PoC1
Proof of concept for CVE-2022-31814
CVE-2022-31814CRITICAL16 jan 2025
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISCO
abrir
GitHub PoC66
watchtowrlabs/fortios-auth-bypass-check-CVE-2024-55591
CVE-2024-55591CRITICALsob ataqueransomware16 jan 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISCO
abrir
GitHub PoC271
POC exploit for CVE-2024-49138
CVE-2024-49138HIGHsob ataque15 jan 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC31
Ivanti Connect Secure IFT TLS Stack Overflow pre-auth RCE (CVE-2025-0282)
CVE-2025-0282CRITICALsob ataqueransomware15 jan 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RISCO
abrir
GitHub PoC1
Parses the System Snapshot from an Ivanti Connect Secure applicance to identify possible IOCs related to CVE-2023-46805, CVE-2024-21887 and CVE-2025-0282.
CVE-2025-0282CRITICALsob ataqueransomware14 jan 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RISCO
abrir
GitHub PoC1
Parses the System Snapshot from an Ivanti Connect Secure applicance to identify possible IOCs related to CVE-2023-46805, CVE-2024-21887 and CVE-2025-0282.
CVE-2024-21887CRITICALsob ataqueransomware14 jan 2025
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,
100RISCO
abrir
GitHub PoC1
Parses the System Snapshot from an Ivanti Connect Secure applicance to identify possible IOCs related to CVE-2023-46805, CVE-2024-21887 and CVE-2025-0282.
CVE-2023-46805HIGHsob ataqueransomware14 jan 2025
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RISCO
abrir
GitHub PoC3
CVE-2024-35250 PoC - Optimized & Condensed Form of Varwara's PoC
CVE-2024-35250HIGHsob ataque13 jan 2025
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
91RISCO
abrir
GitHub PoC1
Chartify – WordPress Chart Plugin <= 2.9.5 - Unauthenticated Local File Inclusion via source
CVE-2024-10571CRITICAL13 jan 2025
Chartify – WordPress Chart Plugin <= 2.9.5 - Unauthenticated Local File Inclusion via source
63RISCO
abrir
GitHub PoC1
VRPConnector <= 2.0.1 - Unauthenticated PHP Object Injection
CVE-2024-56058CRITICAL13 jan 2025
WordPress VRPConnector plugin <= 2.0.1 - PHP Object Injection vulnerability
48RISCO
abrir
GitHub PoC1
Partners <= 0.2.0 - Unauthenticated PHP Object Injection
CVE-2024-56059CRITICAL13 jan 2025
WordPress Partners plugin <= 0.2.0 - PHP Object Injection vulnerability
48RISCO
abrir
GitHub PoC1
CVE-2024-11972 in Hunk Companion <1.9.0 allows unauthenticated attackers to exploit insecure REST API endpoints and install vulnerable plugins, risking RCE, SQLi, XSS, and backdoors.
CVE-2024-11972CRITICAL13 jan 2025
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
75RISCO
abrir
GitHub PoC1
RSVP ME <= 1.9.9 - Unauthenticated SQL Injection
CVE-2024-50491CRITICAL12 jan 2025
WordPress RSVP ME plugin <= 1.9.9 - SQL Injection vulnerability
48RISCO
abrir
GitHub PoC
he Hunk Companion Plugin for WordPress: Vulnerable to Unauthorized Plugin Installation/Activation (Versions Up to and Including 1.8.4)
CVE-2024-9707CRITICAL12 jan 2025
Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
63RISCO
abrir
GitHub PoC1
WP Hotel Booking <= 2.1.0 - Unauthenticated SQL Injection
CVE-2024-3605CRITICAL12 jan 2025
WP Hotel Booking <= 2.1.0 - Unauthenticated SQL Injection
63RISCO
abrir
GitHub PoC17
CVE-2024-50603: Aviatrix Controller Unauthenticated Command Injection
CVE-2024-50603CRITICALsob ataque12 jan 2025
An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutraliza
100RISCO
abrir
GitHub PoC1
Subscribe to Category <= 2.7.4 - Unauthenticated SQL Injection
CVE-2023-32590CRITICAL12 jan 2025
WordPress Subscribe to Category Plugin <= 2.7.4 is vulnerable to SQL Injection
63RISCO
abrir
GitHub PoC2
kcfg bypass example - CVE-2024-21338
CVE-2024-21338HIGHsob ataqueransomware12 jan 2025
Windows Kernel Elevation of Privilege Vulnerability
83RISCO
abrir
GitHub PoC4
# CVE-2025-0282: Remote Code Execution Vulnerability in [StorkS]
CVE-2025-0282CRITICALsob ataqueransomware12 jan 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RISCO
abrir
GitHub PoC
Nxploited/CVE-2024-10586-Poc
CVE-2024-10586CRITICAL12 jan 2025
Debug Tool <= 2.2 - Unauthenticated Arbitrary File Creation
48RISCO
abrir
GitHub PoC1
Bludit 3.9.2 - Auth Bruteforce Bypass CVE:2019-17240 Refurbish In bash
CVE-2019-17240LOW11 jan 2025
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RISCO
abrir
GitHub PoC
Nxploited/CVE-2024-49328-exploit
CVE-2024-49328CRITICAL11 jan 2025
WordPress WP REST API FNS Plugin plugin <= 1.0.0 - Account Takeover vulnerability
48RISCO
abrir
GitHub PoC
poc-cve-2023-3824
CVE-2023-3824CRITICAL11 jan 2025
Buffer overflow and overread in phar_dir_read()
53RISCO
abrir
GitHub PoC1
GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection
CVE-2024-12877CRITICAL11 jan 2025
GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection
48RISCO
abrir
GitHub PoC53
CVE-2025-0282 is a critical vulnerability found in Ivanti Connect Secure, allowing Remote Command Execution (RCE) through a buffer overflow exploit.
CVE-2025-0282CRITICALsob ataqueransomware11 jan 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RISCO
abrir
anteriorpágina 234 / 514próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.