Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
81.524exploits catalogados
37.962CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.482Referência 24.284GitHub PoC 15.675VulnCheck XDB 9.136Nuclei 4.441Metasploit 3.506✓ só verificadosrecentespopularesrisco
81.524 exploits
VulnCheck XDB
infoleak
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir ↗GitHub PoC★ 35
mistymntncop/CVE-2024-7971
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a
76RISCO
abrir ↗GitHub PoC
nicoleman0/CVE-2016-6210-OpenSSHd-7.2p2
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RISCO
abrir ↗VulnCheck XDB
initial-access
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to s
60RISCO
abrir ↗GitHub PoC★ 3
A Python proof-of-concept exploit for CVE-2025-24813 - Unauthenticated RCE in Apache Tomcat (v9.0.0-9.0.98/10.1.0-10.1.34/11.0.0-11.0.2) via malicious Java object deserialization. Includes safe detection mode and custom payload support.
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗GitHub PoC
vsFTPd 2.3.4 CVE-2011-2523 PoC
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir ↗VulnCheck XDB
infoleak
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
61RISCO
abrir ↗Exploit-DB
WebFileSys 2.31.0 - Directory Path Traversal
An issue in the relPath parameter of WebFileSys version 2.31.0 allows attackers to perform directory traversal via a cra
33RISCO
abrir ↗Exploit-DB
Roundcube Webmail 1.6.6 - Stored Cross Site Scripting (XSS)
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
85RISCO
abrir ↗Exploit-DB
MagnusSolution magnusbilling 7.3.0 - Command Injection
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISCO
abrir ↗Exploit-DB
ABB Cylon FLXeon 9.3.4 - WebSocket Command Spawning
Authentication and Authorization Issues
41RISCO
abrir ↗Exploit-DB
NEWS-BUZZ News Management System 1.0 - SQL Injection
code-projects/anirbandutta9 Content Management System/News-Buzz index.php sql injection
33RISCO
abrir ↗Exploit-DB
RosarioSIS 7.6 - SQL Injection
An unauthenticated SQL Injection vulnerability exists in RosarioSIS before 7.6.1 via the votes parameter in ProgramFunct
28RISCO
abrir ↗Exploit-DB
CyberPanel 2.3.6 - Remote Code Execution (RCE)
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
100RISCO
abrir ↗Exploit-DB
phpIPAM 1.6 - Reflected Cross Site Scripting (XSS)
phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter
48RISCO
abrir ↗GitHub PoC★ 3
Exploit PoC for CVE-2023-20198
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISCO
abrir ↗Exploit-DB
ABB Cylon FLXeon 9.3.4 - Remote Code Execution (Authenticated)
Remote Code Execution (RCE) Vulnerabilities
48RISCO
abrir ↗Exploit-DB
ABB Cylon FLXeon 9.3.4 - System Logs Information Disclosure
Information disclosures
33RISCO
abrir ↗Exploit-DB
ABB Cylon FLXeon 9.3.4 - Remote Code Execution (RCE)
Remote Code Execution (RCE) Vulnerabilities
48RISCO
abrir ↗Exploit-DB
GeoVision GV-ASManager 6.1.0.0 - Broken Access Control
Broken access control vulnerability in Geovision GV-ASWeb with version v6.1.0.0 or less. This vulnerability allows low p
41RISCO
abrir ↗Exploit-DB
GetSimpleCMS 3.3.16 - Remote Code Execution (RCE)
Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess.
23RISCO
abrir ↗GitHub PoC
ngyinkit/cve-2019-18634
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISCO
abrir ↗GitHub PoC★ 1
A Python proof-of-concept exploit for CVE-2019-15107 - an unauthenticated remote code execution vulnerability in Webmin versions 1.890 through 1.920.
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir ↗Exploit-DB
MiniCMS 1.1 - Cross Site Scripting (XSS)
MiniCMS version 1.1 contains a Cross Site Scripting (XSS) vulnerability in http://example.org/mc-admin/page.php?date={pa
23RISCO
abrir ↗Exploit-DB
qBittorrent 5.0.1 - MITM RCE
qBittorrent before 5.0.1 proceeds with use of https URLs even after certificate validation errors.
41RISCO
abrir ↗VulnCheck XDB
initial-access
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir ↗GitHub PoC★ 43
CVE-2024-36401 图形化利用工具,支持各个JDK版本利用以及回显、内存马实现
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.