Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.646exploits catalogados
37.382CVEs com exploração pública
24.695testados em laboratório
15.392 exploits
GitHub PoC1
Bludit 3.9.2 - Auth Bruteforce Bypass CVE:2019-17240 Refurbish In bash
CVE-2019-17240LOW11 jan 2025
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RISCO
abrir
GitHub PoC
Nxploited/CVE-2024-49328-exploit
CVE-2024-49328CRITICAL11 jan 2025
WordPress WP REST API FNS Plugin plugin <= 1.0.0 - Account Takeover vulnerability
48RISCO
abrir
GitHub PoC
Exploit implementation for CVE-2021-21551
CVE-2021-21551HIGHsob ataque11 jan 2025
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RISCO
abrir
GitHub PoC
XSS Test Swagger 3.14.1 to 3.37.0
CVE-2025-8191MEDIUM10 jan 2025
macrozheng mall Swagger UI index.html cross site scripting
33RISCO
abrir
GitHub PoC2
Exploit For: CVE-2024-36840: SQL Injection Vulnerability in Boelter Blue System Management (Version 1.3)
CVE-2024-36840CRITICAL10 jan 2025
SQL Injection vulnerability in Boelter Blue System Management v.1.3 allows a remote attacker to execute arbitrary code a
48RISCO
abrir
GitHub PoC3
Vulnerable Environment and Exploit for CVE-2024-53677
CVE-2024-53677CRITICAL10 jan 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir
GitHub PoC
CVE-2024-4577 POC
CVE-2024-4577CRITICALsob ataqueransomware08 jan 2025
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
The **Dirty Pipe exploit (CVE-2022-0847)** is a Linux kernel vulnerability (v5.8+) allowing unprivileged attackers to overwrite arbitrary files via a flaw in the pipe mechanism. This leads to privilege escalation, granting root access. Similar to Dirty Cow but easier to exploit. Fix: Update to a patched kernel version.
CVE-2022-0847HIGHsob ataque08 jan 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC12
CVE-2024-49112 LDAP RCE PoC and Metasploit Module
CVE-2024-49112CRITICAL08 jan 2025
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC1
punitdarji/Apache-struts-cve-2024-53677
CVE-2024-53677CRITICAL08 jan 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir
GitHub PoC5
Fuel CMS 1.4.1 - Remote Code Execution
CVE-2018-1676308 jan 2025
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir
GitHub PoC
Taldrid1/cve-2021-41773
CVE-2021-41773HIGHsob ataqueransomware07 jan 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC121
GeoServer(CVE-2024-36401/CVE-2024-36404)漏洞利用工具
CVE-2024-36401CRITICALsob ataque07 jan 2025
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir
GitHub PoC
JustinYe377/CTF-CVE-2022-0847
CVE-2022-0847HIGHsob ataque07 jan 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC3
An rewritten POC on the CVE-2014-3704
CVE-2014-370406 jan 2025
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISCO
abrir
GitHub PoC1
POC exploit for CVE-2024-25641
CVE-2024-25641CRITICAL05 jan 2025
Cacti RCE vulnerability when importing packages
85RISCO
abrir
GitHub PoC6
CRUNZEX/CVE-2025-22968
CVE-2025-22968CRITICAL05 jan 2025
An issue in D-Link DWR-M972V 1.05SSG allows a remote attacker to execute arbitrary code via SSH using root account witho
48RISCO
abrir
GitHub PoC3
CVE-2024-4367 is a critical vulnerability (CVSS 9.8) in PDF.js, allowing arbitrary JavaScript code execution due to insufficient type checks on the FontMatrix object within PDF files.
CVE-2024-4367MEDIUM05 jan 2025
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir
GitHub PoC
oalieno/CVE-2022-41924
CVE-2022-41924CRITICAL04 jan 2025
Tailscale Windows daemon is vulnerable to RCE via CSRF
48RISCO
abrir
GitHub PoC
Cacti v1.2.22: Unauthenticated Command Injection Vulnerability (CVE-2022-46169)
CVE-2022-46169CRITICALsob ataque04 jan 2025
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC
Powershell Script to build token for CVE-2019-1619
CVE-2019-1619CRITICAL04 jan 2025
Cisco Data Center Network Manager Authentication Bypass Vulnerability
85RISCO
abrir
GitHub PoC17
YassDEV221608/CVE-2024-6387_PoC
CVE-2024-6387HIGH04 jan 2025
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir
GitHub PoC
Nxploited/CVE-2023-51409
CVE-2023-51409CRITICAL03 jan 2025
WordPress AI Engine plugin <= 1.9.98 - Unauthenticated Arbitrary File Upload vulnerability
75RISCO
abrir
GitHub PoC
MASS CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware03 jan 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
Exploiting CVE-2023-2825 on a VM
CVE-2023-2825CRITICAL02 jan 2025
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RISCO
abrir
GitHub PoC48
Zabbix CVE-2024-42327 PoC
CVE-2024-42327CRITICAL01 jan 2025
SQL injection in user.get API
70RISCO
abrir
GitHub PoC5
Cleo 远程代码执行漏洞批量检测脚本(CVE-2024-50623)
CVE-2024-50623CRITICALsob ataqueransomware31 dez 2024
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file up
100RISCO
abrir
GitHub PoC3
CVE-2023-38831 (PoC) - WinRAR Exploit
CVE-2023-38831HIGHsob ataqueransomware30 dez 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC4
AutoBlue - Automated EternalBlue (CVE-2017-0144 / MS17-010) exploitation tool leveraging Nmap and Metasploit for ethical hacking, penetration testing, and CTF challenges. Strictly for authorized and educational use only!
CVE-2017-0144HIGHsob ataqueransomware30 dez 2024
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
GitHub PoC12
math-x-io/CVE-2024-54152-poc
CVE-2024-54152CRITICAL30 dez 2024
Angular Expressions - Remote Code Execution when using locals
48RISCO
abrir
anteriorpágina 235 / 514próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.