Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.524exploits catalogados
37.962CVEs com exploração pública
24.695testados em laboratório
81.524 exploits
GitHub PoC★ 1
PHP CGI CVE-2024-4577 PoC
CVE-2024-4577CRITICALsob ataqueransomware12 abr 2025
Argument Injection in PHP-CGI
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2014-0160HIGHsob ataque12 abr 2025
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir ↗
GitHub PoC★ 35
mistymntncop/CVE-2024-7971
CVE-2024-7971HIGHsob ataque12 abr 2025
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a
76RISCO
abrir ↗
GitHub PoC
nicoleman0/CVE-2016-6210-OpenSSHd-7.2p2
CVE-2016-6210MEDIUM12 abr 2025
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-28121—12 abr 2025
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to s
60RISCO
abrir ↗
GitHub PoC★ 3
A Python proof-of-concept exploit for CVE-2025-24813 - Unauthenticated RCE in Apache Tomcat (v9.0.0-9.0.98/10.1.0-10.1.34/11.0.0-11.0.2) via malicious Java object deserialization. Includes safe detection mode and custom payload support.
CVE-2025-24813CRITICALsob ataque12 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗
GitHub PoC
vsFTPd 2.3.4 CVE-2011-2523 PoC
CVE-2011-2523—12 abr 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-36991HIGH12 abr 2025
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
61RISCO
abrir ↗
Exploit-DB
WebFileSys 2.31.0 - Directory Path Traversal
CVE-2024-53586MEDIUMwebappsmultiple11 abr 2025
An issue in the relPath parameter of WebFileSys version 2.31.0 allows attackers to perform directory traversal via a cra
33RISCO
abrir ↗
Exploit-DB
Roundcube Webmail 1.6.6 - Stored Cross Site Scripting (XSS)
CVE-2024-37383MEDIUMsob ataquewebappsphp11 abr 2025
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
85RISCO
abrir ↗
Exploit-DB
MagnusSolution magnusbilling 7.3.0 - Command Injection
CVE-2023-30258CRITICALwebappsmultiple11 abr 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISCO
abrir ↗
Exploit-DB
ABB Cylon FLXeon 9.3.4 - WebSocket Command Spawning
CVE-2024-48849HIGHhardwaremultiple11 abr 2025
Authentication and Authorization Issues
41RISCO
abrir ↗
Exploit-DB
NEWS-BUZZ News Management System 1.0 - SQL Injection
CVE-2024-10758MEDIUMwebappsphp11 abr 2025
code-projects/anirbandutta9 Content Management System/News-Buzz index.php sql injection
33RISCO
abrir ↗
Exploit-DB
RosarioSIS 7.6 - SQL Injection
CVE-2021-44567—webappsphp11 abr 2025
An unauthenticated SQL Injection vulnerability exists in RosarioSIS before 7.6.1 via the votes parameter in ProgramFunct
28RISCO
abrir ↗
Exploit-DB
CyberPanel 2.3.6 - Remote Code Execution (RCE)
CVE-2024-51378CRITICALsob ataqueransomwarewebappsmultiple11 abr 2025
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
100RISCO
abrir ↗
Exploit-DB
phpIPAM 1.6 - Reflected Cross Site Scripting (XSS)
CVE-2023-24657MEDIUMwebappsphp11 abr 2025
phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter
48RISCO
abrir ↗
GitHub PoC★ 3
Exploit PoC for CVE-2023-20198
CVE-2023-20198CRITICALsob ataque11 abr 2025
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISCO
abrir ↗
Exploit-DB
ABB Cylon FLXeon 9.3.4 - Remote Code Execution (Authenticated)
CVE-2024-48841CRITICALhardwaremultiple11 abr 2025
Remote Code Execution (RCE) Vulnerabilities
48RISCO
abrir ↗
Exploit-DB
ABB Cylon FLXeon 9.3.4 - System Logs Information Disclosure
CVE-2024-48852MEDIUMhardwaremultiple11 abr 2025
Information disclosures
33RISCO
abrir ↗
Exploit-DB
ABB Cylon FLXeon 9.3.4 - Remote Code Execution (RCE)
CVE-2024-48841CRITICALhardwaremultiple11 abr 2025
Remote Code Execution (RCE) Vulnerabilities
48RISCO
abrir ↗
Exploit-DB
GeoVision GV-ASManager 6.1.0.0 - Broken Access Control
CVE-2024-56898HIGHwebappsmultiple11 abr 2025
Broken access control vulnerability in Geovision GV-ASWeb with version v6.1.0.0 or less. This vulnerability allows low p
41RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALsob ataqueransomware11 abr 2025
Argument Injection in PHP-CGI
100RISCO
abrir ↗
Exploit-DB
GetSimpleCMS 3.3.16 - Remote Code Execution (RCE)
CVE-2021-28976—webappsphp11 abr 2025
Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess.
23RISCO
abrir ↗
GitHub PoC
ngyinkit/cve-2019-18634
CVE-2019-18634—11 abr 2025
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-2825—11 abr 2025
35RISCO
abrir ↗
GitHub PoC★ 1
A Python proof-of-concept exploit for CVE-2019-15107 - an unauthenticated remote code execution vulnerability in Webmin versions 1.890 through 1.920.
CVE-2019-15107CRITICALsob ataqueransomware11 abr 2025
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir ↗
Exploit-DB
MiniCMS 1.1 - Cross Site Scripting (XSS)
CVE-2018-1000638—webappsphp11 abr 2025
MiniCMS version 1.1 contains a Cross Site Scripting (XSS) vulnerability in http://example.org/mc-admin/page.php?date={pa
23RISCO
abrir ↗
Exploit-DB
qBittorrent 5.0.1 - MITM RCE
CVE-2024-51774HIGHlocalmultiple11 abr 2025
qBittorrent before 5.0.1 proceeds with use of https URLs even after certificate validation errors.
41RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALsob ataqueransomware11 abr 2025
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir ↗
GitHub PoC★ 43
CVE-2024-36401 图形化利用工具,支持各个JDK版本利用以及回显、内存马实现
CVE-2024-36401CRITICALsob ataque11 abr 2025
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir ↗
← anteriorpágina 353 / 2.718próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.