Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.008exploits catalogados
34.638CVEs com exploração pública
24.695testados em laboratório
21.662 exploits
Referência
CVE-2024-27199
CVE-2024-27199HIGHsob ataqueransomware
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
100RISCO
abrir
Referência
CVE-2022-44877
CVE-2022-44877CRITICALsob ataque
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISCO
abrir
Referência
CVE-2022-44877
CVE-2022-44877CRITICALsob ataque
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISCO
abrir
Referência
CVE-2022-44877
CVE-2022-44877CRITICALsob ataque
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISCO
abrir
Referência
CVE-2017-12617
CVE-2017-12617HIGHsob ataque
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISCO
abrir
Referência
CVE-2019-9670
CVE-2019-9670CRITICALsob ataque
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RISCO
abrir
Referência
CVE-2023-46805
CVE-2023-46805HIGHsob ataqueransomware
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RISCO
abrir
Referência
CVE-2023-22527
CVE-2023-22527CRITICALsob ataqueransomware
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RISCO
abrir
Referência
CVE-2023-42793
CVE-2023-42793CRITICALsob ataqueransomware
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir
Referência
CVE-2024-24919
CVE-2024-24919HIGHsob ataqueransomware
Information disclosure
100RISCO
abrir
Referência
CVE-2024-45519
CVE-2024-45519CRITICALsob ataque
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RISCO
abrir
Referência
CVE-2014-8361
CVE-2014-8361CRITICALsob ataque
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClien
100RISCO
abrir
Referência
CVE-2014-3704
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISCO
abrir
Referência
CVE-2017-2445
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISCO
abrir
Referência
CVE-2022-47986
CVE-2022-47986CRITICALsob ataqueransomware
IBM Aspera Faspex code execution
100RISCO
abrir
Referência
CVE-2026-8213
OSGeo gdal Grid File GDapi.c GDSDfldsrch heap-based overflow
33RISCO
abrir
Referência
CVE-2022-41082
CVE-2022-41082HIGHsob ataqueransomware
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
Referência
CVE-2025-59287
CVE-2025-59287CRITICALsob ataque
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISCO
abrir
Referência
CVE-2019-10149
CVE-2019-10149CRITICALsob ataque
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISCO
abrir
Referência
CVE-2018-15961
CVE-2018-15961CRITICALsob ataque
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RISCO
abrir
Referência
CVE-2023-38035
CVE-2023-38035CRITICALsob ataqueransomware
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an
100RISCO
abrir
Referência
CVE-2021-27065
CVE-2021-27065HIGHsob ataqueransomware
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
Referência
CVE-2021-27065
CVE-2021-27065HIGHsob ataqueransomware
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
Referência
CVE-2025-24813
CVE-2025-24813CRITICALsob ataque
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
Referência
CVE-2022-41040
CVE-2022-41040HIGHsob ataqueransomware
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISCO
abrir
Referência
CVE-2021-3129
CVE-2021-3129CRITICALsob ataqueransomware
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
Referência
CVE-2021-3129
CVE-2021-3129CRITICALsob ataqueransomware
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
Referência
CVE-2020-10189
CVE-2020-10189CRITICALsob ataque
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted d
100RISCO
abrir
Referência
CVE-2026-7292
o2oa NodeAgent NodeAgent.java syncFile improper authorization
33RISCO
abrir
Referência
CVE-2026-7290
JeecgBoot loadDict Endpoint SqlInjectionUtil.java SqlInjectionUtil sql injection
33RISCO
abrir
anteriorpágina 263 / 723próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.