Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.453exploits catalogados
37.908CVEs com exploração pública
24.695testados em laboratório
81.453 exploits
GitHub PoC
This contains single-file exploit for cve-2021-4034 which is a Polkit Local Privilege Escalation. Use it wisely!
CVE-2021-4034HIGHsob ataqueransomware14 mai 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataqueransomware14 mai 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir ↗
GitHub PoC
fatkz/CVE-2020-17530
CVE-2020-17530CRITICALsob ataque14 mai 2025
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISCO
abrir ↗
GitHub PoC
This contains single-file exploit for ProFTPd 1.3.5 mod_copy (CVE-2015-3306) vulnerability, especially for TryHackMe Kenobi Lab.
CVE-2015-3306—14 mai 2025
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISCO
abrir ↗
VulnCheck XDB
local
CVE-2025-29824HIGHsob ataqueransomware14 mai 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2020-17530CRITICALsob ataque14 mai 2025
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISCO
abrir ↗
GitHub PoC★ 29
encrypter15/CVE-2025-29824
CVE-2025-29824HIGHsob ataqueransomware14 mai 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-27636MEDIUM14 mai 2025
Apache Camel: Camel Message Header Injection via Improper Filtering
55RISCO
abrir ↗
Metasploit600
Ivanti EPMM Authentication Bypass for Expression Language Remote Code Execution
CVE-2025-4427MEDIUMsob ataque13 mai 2025
Authentication Bypass
100RISCO
abrir ↗
GitHub PoC★ 2
CVE-2025-3248: A critical flaw has been discovered in Langflow that allows malicious actors to execute arbitrary Python code on the target system. This can lead to full remote code execution without authentication, potentially giving attackers control over the server.
CVE-2025-3248CRITICALsob ataqueransomware13 mai 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir ↗
Metasploit600
Ivanti EPMM Authentication Bypass for Expression Language Remote Code Execution
CVE-2025-4428HIGHsob ataque13 mai 2025
Remote Code Execution
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-2294CRITICAL13 mai 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISCO
abrir ↗
GitHub PoC★ 1
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
CVE-2025-2294CRITICAL13 mai 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISCO
abrir ↗
Exploit-DB
Kentico Xperience 13.0.178 - Cross Site Scripting (XSS)
CVE-2025-32370HIGHwebappsmultiple13 mai 2025
Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uplo
41RISCO
abrir ↗
GitHub PoC
MandipJoshi/CVE-2021-3560
CVE-2021-3560HIGHsob ataque13 mai 2025
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISCO
abrir ↗
GitHub PoC
A Python PoC for CVE-2022-21661, adapted from z92g's Go PoC, designed to demonstrate the vulnerability in a more accessible scripting environment.
CVE-2022-21661HIGH13 mai 2025
SQL injection in WordPress
78RISCO
abrir ↗
VulnCheck XDB
local
CVE-2021-3560HIGHsob ataque13 mai 2025
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2022-21661HIGH13 mai 2025
SQL injection in WordPress
78RISCO
abrir ↗
Exploit-DB
TP-Link VN020 F3v(T) TT_V6.2.1021) - DHCP Stack Buffer Overflow
CVE-2024-11237HIGHlocalmultiple13 mai 2025
TP-Link VN020 F3v(T) DHCP DISCOVER Packet Parser TP-Thumper stack-based overflow
41RISCO
abrir ↗
Exploit-DB
WordPress Frontend Login and Registration Blocks Plugin 1.0.7 - Privilege Escalation
CVE-2025-3605CRITICALwebappsmultiple13 mai 2025
Frontend Login and Registration Blocks <= 1.1.1 - Unauthenticated Privilege Escalation via Account Takeover
63RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALsob ataqueransomware13 mai 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2025-24085CRITICALsob ataque13 mai 2025
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, i
83RISCO
abrir ↗
GitHub PoC★ 1
eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Deletion
CVE-2025-4603CRITICAL12 mai 2025
eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Deletion
48RISCO
abrir ↗
GitHub PoC★ 3
rebelle3/cve-2017-7117
CVE-2017-7117—12 mai 2025
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud befor
28RISCO
abrir ↗
GitHub PoC★ 55
WHW0x455/CVE-2023-41992
CVE-2023-41992HIGHsob ataque12 mai 2025
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macO
71RISCO
abrir ↗
GitHub PoC
laishouchao/Apache-RocketMQ-RCE-CVE-2023-37582-poc
CVE-2023-37582CRITICAL12 mai 2025
Apache RocketMQ: Possible remote code execution when using the update configuration function
85RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2017-8917—12 mai 2025
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISCO
abrir ↗
GitHub PoC
shishirpandey18/CVE-2021-3156
CVE-2021-3156HIGHsob ataque12 mai 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2021-3156HIGHsob ataque12 mai 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALsob ataqueransomware12 mai 2025
Argument Injection in PHP-CGI
100RISCO
abrir ↗
← anteriorpágina 336 / 2.716próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.