Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.453exploits catalogados
37.908CVEs com exploração pública
24.695testados em laboratório
81.453 exploits
GitHub PoC
ChoDeokCheol/CVE-2023-39361
CVE-2023-39361CRITICAL26 abr 2025
Unauthenticated SQL Injection in graph_view.php in Cacti
85RISCO
abrir ↗
GitHub PoC★ 10
CraftCMS RCE Checker (CVE-2025-32432)
CVE-2025-32432CRITICALsob ataque26 abr 2025
Craft CMS Allows Remote Code Execution
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-2294CRITICAL26 abr 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-32432CRITICALsob ataque26 abr 2025
Craft CMS Allows Remote Code Execution
100RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2021-41773HIGHsob ataqueransomware26 abr 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗
GitHub PoC★ 1
chhhd/CVE-2025-1974
CVE-2025-1974CRITICAL26 abr 2025
ingress-nginx admission controller RCE escalation
85RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2023-39361CRITICAL26 abr 2025
Unauthenticated SQL Injection in graph_view.php in Cacti
85RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-1389HIGHsob ataque26 abr 2025
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability i
100RISCO
abrir ↗
GitHub PoC
romanedutov/CVE-2025-2294
CVE-2025-2294CRITICAL26 abr 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISCO
abrir ↗
GitHub PoC★ 2
CVE-2021-42287/CVE-2021-42278/OTHER Scanner & Exploiter.
CVE-2021-42287HIGHsob ataqueransomware26 abr 2025
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISCO
abrir ↗
GitHub PoC
A PoC of CVE-2016-10033 I made for PentesterLab
CVE-2016-10033CRITICALsob ataque25 abr 2025
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir ↗
GitHub PoC
K4Der11000/k4_cve-2023-41064
CVE-2023-41064HIGHsob ataque25 abr 2025
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1
83RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-32433CRITICALsob ataque25 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir ↗
GitHub PoC
Python Proof of Concept for CVE-2023-1545 (SQL Injection for Teampass versions prior to 3.0.0.23).
CVE-2023-1545HIGH25 abr 2025
SQL Injection in nilsteampassnet/teampass
41RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-3102HIGH25 abr 2025
SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
78RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-29306CRITICAL25 abr 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISCO
abrir ↗
GitHub PoC
WonderCMS v3.4.2 NSE Discovery Script
CVE-2023-41425MEDIUM25 abr 2025
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISCO
abrir ↗
GitHub PoC★ 1
Erlang OTP SSH NSE Discovery Script
CVE-2025-32433CRITICALsob ataque25 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir ↗
GitHub PoC★ 2
Next.js middleware bypass exploit
CVE-2025-29927CRITICAL25 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗
GitHub PoC
A PoC of CVE-2016-2098 I made for PentesterLab
CVE-2016-2098—25 abr 2025
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RISCO
abrir ↗
GitHub PoC★ 3
CVE-2025-32433 Erlang/OTP SSH RCE Exploit SSH远程代码执行漏洞EXP
CVE-2025-32433CRITICALsob ataque25 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir ↗
GitHub PoC★ 4
Proof-of-Concept (PoC) for CVE-2025-29306, a Remote Code Execution vulnerability in FoxCMS. This Python script scans single or multiple targets, executes commands, and reports vulnerable hosts.
CVE-2025-29306CRITICAL25 abr 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2016-10033CRITICALsob ataque25 abr 2025
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-24919HIGHsob ataqueransomware25 abr 2025
Information disclosure
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL25 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗
GitHub PoC
A PoC of CVE-2018-0114 I made for PentesterLab
CVE-2018-0114—25 abr 2025
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISCO
abrir ↗
GitHub PoC
A PoC of CVE-2019-5420 I made for PentesterLab
CVE-2019-5420—25 abr 2025
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISCO
abrir ↗
GitHub PoC
CyprianAtsyor/CVE-2024-24919-Incident-Report.md
CVE-2024-24919HIGHsob ataqueransomware25 abr 2025
Information disclosure
100RISCO
abrir ↗
GitHub PoC★ 4
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
CVE-2025-31324CRITICALsob ataqueransomware25 abr 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-30406CRITICALsob ataque24 abr 2025
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
100RISCO
abrir ↗
← anteriorpágina 343 / 2.716próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.