Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.524exploits catalogados
37.962CVEs com exploração pública
24.695testados em laboratório
81.524 exploits
GitHub PoC
vances25/CVE-2024-44871
CVE-2024-44871HIGH07 abr 2025
An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute a
46RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2019-5418HIGHsob ataque07 abr 2025
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2024-44308HIGHsob ataque07 abr 2025
The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18
76RISCO
abrir ↗
GitHub PoC
WHS 3기 장대혁 취약한(CVE) Docker 환경 구성 과제입니다.
CVE-2019-5418HIGHsob ataque07 abr 2025
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir ↗
GitHub PoC
d0x-awrqxavc/-CVE-2024-10924
CVE-2024-10924CRITICAL06 abr 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir ↗
GitHub PoC★ 8
Next.js Middleware Bypass Scanne
CVE-2025-29927CRITICAL06 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗
GitHub PoC
VVeakee/CVE-2024-4367
CVE-2024-4367MEDIUM06 abr 2025
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir ↗
Exploit-DB
Watcharr 1.43.0 - Remote Code Execution (RCE)
CVE-2024-48827HIGHwebappsmultiple06 abr 2025
An issue in sbondCo Watcharr v.1.43.0 allows a remote attacker to execute arbitrary code and escalate privileges via the
41RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL06 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗
GitHub PoC★ 33
Simulated PoC for CVE-2025-2783 — a sandbox escape vulnerability in Chrome's Mojo IPC. Includes phishing delivery, memory fuzzing, IPC simulation, and logging. Safe for red team demos, detection engineering, and educational use.
CVE-2025-2783HIGHsob ataque06 abr 2025
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
71RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL06 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL06 abr 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir ↗
GitHub PoC
A POC lab environment for CVE-2024-56145 CraftCMS RCE.
CVE-2024-56145CRITICALsob ataque06 abr 2025
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
100RISCO
abrir ↗
GitHub PoC★ 1
cybermads/CVE-2011-2523
CVE-2011-2523—06 abr 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir ↗
Exploit-DB
Reservit Hotel 2.1 - Stored Cross-Site Scripting (XSS)
CVE-2024-9458MEDIUMwebappsphp06 abr 2025
Reservit Hotel < 3.0 - Admin+ Stored XSS
33RISCO
abrir ↗
GitHub PoC★ 2
CVE-2025-24813-POC JSP Web Shell Uploader
CVE-2025-24813CRITICALsob ataque06 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗
GitHub PoC★ 3
WordPress FEUP Arbitrary File Upload Exploit (CVE-2025-2005)
CVE-2025-2005CRITICAL06 abr 2025
Front-End-Only-Users <= 3.2.32 - Unauthenticated Arbitrary File Upload
53RISCO
abrir ↗
GitHub PoC
Koray123-debug/CVE-2024-34102
CVE-2024-34102CRITICALsob ataque06 abr 2025
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir ↗
GitHub PoC
vulnerable-nextjs-14-CVE-2025-29927
CVE-2025-29927CRITICAL06 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗
Exploit-DB
Backup and Staging by WP Time Capsule 1.22.21 - Unauthenticated Arbitrary File Upload
CVE-2024-8856CRITICALwebappsphp06 abr 2025
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RISCO
abrir ↗
Exploit-DB
DataEase 2.4.0 - Database Configuration Information Exposure
CVE-2024-30269MEDIUMwebappsjava06 abr 2025
DataEase has database configuration information exposure vulnerability
53RISCO
abrir ↗
Exploit-DB
Palo Alto Networks Expedition 1.2.90.1 - Admin Account Takeover
CVE-2024-5910CRITICALsob ataquewebappsmultiple06 abr 2025
Expedition: Missing Authentication Leads to Admin Account Takeover
100RISCO
abrir ↗
GitHub PoC★ 1
Vite-CVE-2025-30208-EXP单目标检测,支持自定义读取路径,深度检索
CVE-2025-30208MEDIUM05 abr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗
GitHub PoC
CVE-2025-30065 PoC
CVE-2025-30065CRITICAL05 abr 2025
Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
60RISCO
abrir ↗
GitHub PoC★ 2
Vulnerability assessment and exploitation of vsftpd 2.3.4 (CVE-2011-2523) using Metasploit. Full report and proof of root access included.
CVE-2011-2523—05 abr 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir ↗
Exploit-DB
Exclusive Addons for Elementor 2.6.9 - Stored Cross-Site Scripting (XSS)
CVE-2024-1234MEDIUMwebappsmultiple05 abr 2025
Exclusive Addons for Elementor <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
33RISCO
abrir ↗
Exploit-DB
Microchip TimeProvider 4100 Grandmaster (Data plot modules) 2.4.6 - SQL Injection
CVE-2024-7801MEDIUMremotehardware05 abr 2025
SQL injection in get_chart_data in TimeProvider 4100
33RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM05 abr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗
Exploit-DB
Royal Elementor Addons and Templates 1.3.78 - Unauthenticated Arbitrary File Upload
CVE-2023-5360—webappsmultiple05 abr 2025
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALsob ataque05 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗
← anteriorpágina 357 / 2.718próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.