Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.270exploits catalogados
37.818CVEs com exploração pública
24.695testados em laboratório
81.003 exploits
GitHub PoC★ 14
A detailed walkthrough of TryHackMe's Billing room exploiting CVE-2023-30258 and escalating via fail2ban misconfig
CVE-2023-30258CRITICAL13 jul 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISCO
abrir ↗
GitHub PoC★ 14
A detailed walkthrough of Billing room exploiting CVE-2023-30258 and escalating via fail2ban misconfig
CVE-2023-30258CRITICAL13 jul 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISCO
abrir ↗
GitHub PoC
JayVillain/Scan-CVE-2025-6058
CVE-2025-6058CRITICAL13 jul 2025
WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload
63RISCO
abrir ↗
GitHub PoC
r0otk3r/CVE-2022-1388
CVE-2022-1388CRITICALsob ataqueransomware12 jul 2025
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir ↗
GitHub PoC
r0otk3r/CVE-2024-1212
CVE-2024-1212CRITICALsob ataque12 jul 2025
LoadMaster Pre-Authenticated OS Command Injection
100RISCO
abrir ↗
GitHub PoC★ 1
imbas007/CVE-2025-25257
CVE-2025-25257CRITICALsob ataque12 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISCO
abrir ↗
GitHub PoC
Tool for detecting and exploiting CVE-2025-25257 in Fortinet FortiWeb.
CVE-2025-25257CRITICALsob ataque12 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISCO
abrir ↗
GitHub PoC
WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload
CVE-2025-6058CRITICAL12 jul 2025
WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload
63RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-25257CRITICALsob ataque12 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALsob ataqueransomware12 jul 2025
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir ↗
GitHub PoC★ 1
Proof of Concept for CVE-2025-24813, a Remote Code Execution vulnerability in Apache Tomcat. This PoC exploits unsafe deserialization via crafted session files uploaded through HTTP PUT requests, allowing attackers to execute arbitrary code remotely on vulnerable Tomcat servers.
CVE-2025-24813CRITICALsob ataque12 jul 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗
GitHub PoC★ 1
Exploiting the CVE-2025-25257 vulnerability in FortiWeb. This repository demonstrates secure pre-authenticated SQL injection.
CVE-2025-25257CRITICALsob ataque12 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISCO
abrir ↗
GitHub PoC
pkblanks/Remediating-CVE-2013-3900-EnableCertPaddingCheck-
CVE-2013-3900MEDIUMsob ataque12 jul 2025
WinVerifyTrust Signature Validation Vulnerability
75RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-25257CRITICALsob ataque12 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISCO
abrir ↗
GitHub PoC★ 1
Python exploit for vsftpd 2.3.4 - Backdoor Command Execution
CVE-2011-2523—12 jul 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-24919HIGHsob ataqueransomware12 jul 2025
Information disclosure
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-1212CRITICALsob ataque12 jul 2025
LoadMaster Pre-Authenticated OS Command Injection
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALsob ataque12 jul 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗
GitHub PoC
MacUchegit/Detecting-and-Analyzing-CVE-2024-24919-Exploitation
CVE-2024-24919HIGHsob ataqueransomware12 jul 2025
Information disclosure
100RISCO
abrir ↗
GitHub PoC
This repository contains Detailed explanation and working poc for Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution.
CVE-2014-6287CRITICALsob ataque11 jul 2025
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2024-4577CRITICALsob ataqueransomware11 jul 2025
Argument Injection in PHP-CGI
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2014-6287CRITICALsob ataque11 jul 2025
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2025-32463CRITICALsob ataque11 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-10915CRITICAL11 jul 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2024-4577CRITICALsob ataqueransomware11 jul 2025
Argument Injection in PHP-CGI
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-32113CRITICALsob ataque11 jul 2025
Apache OFBiz: Path traversal leading to RCE
100RISCO
abrir ↗
GitHub PoC
Delivering PHP RCE (CVE-2024-4577) to the Local Network Servers
CVE-2024-4577CRITICALsob ataqueransomware11 jul 2025
Argument Injection in PHP-CGI
100RISCO
abrir ↗
GitHub PoC
r0otk3r/CVE-2024-10915
CVE-2024-10915CRITICAL11 jul 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir ↗
GitHub PoC
Metasploit module for MailEnable CVE-2022-36934 authentication bypass RCE
CVE-2022-36934CRITICAL11 jul 2025
An integer overflow in WhatsApp could result in remote code execution in an established video call.
48RISCO
abrir ↗
GitHub PoC
just remeber how small mistake in santisize username could give yoy root access to the full machine
CVE-2007-2447—11 jul 2025
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir ↗
← anteriorpágina 303 / 2.701próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.