Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.524exploits catalogados
37.962CVEs com exploração pública
24.695testados em laboratório
81.524 exploits
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALsob ataque05 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALsob ataque05 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM05 abr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗
GitHub PoC
CVE-2025-30065 PoC
CVE-2025-30065CRITICAL05 abr 2025
Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
60RISCO
abrir ↗
Exploit-DB
Royal Elementor Addons and Templates 1.3.78 - Unauthenticated Arbitrary File Upload
CVE-2023-5360—webappsmultiple05 abr 2025
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RISCO
abrir ↗
Exploit-DB
IBM Security Verify Access 10.0.0 - Open Redirect during OAuth Flow
CVE-2024-35133MEDIUMwebappsmultiple05 abr 2025
IBM Security Verify Access HTTP open redirect
33RISCO
abrir ↗
Exploit-DB
Kubio AI Page Builder 2.5.1 - Local File Inclusion (LFI)
CVE-2025-2294CRITICALwebappsmultiple05 abr 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISCO
abrir ↗
GitHub PoC★ 2
Vulnerability assessment and exploitation of vsftpd 2.3.4 (CVE-2011-2523) using Metasploit. Full report and proof of root access included.
CVE-2011-2523—05 abr 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir ↗
GitHub PoC
CVE-2025-29927 is a critical vulnerability in Next.js, a popular React-based web framework. The flaw exists in how the middleware feature handles certain internal headers — specifically, the x-middleware-subrequest header
CVE-2025-29927CRITICAL05 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗
GitHub PoC
sn1p3rt3s7/NextJS_CVE-2025-29927
CVE-2025-29927CRITICAL04 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗
Exploit-DB
Angular-Base64-Upload Library 0.1.20 - Remote Code Execution (RCE)
CVE-2024-42640CRITICALremotemultiple04 abr 2025
angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Explo
75RISCO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2021-38163CRITICALsob ataque04 abr 2025
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated
90RISCO
abrir ↗
GitHub PoC
WordPress RomethemeKit For Elementor Plugin <= 1.5.4 is vulnerable to Remote Code Execution (RCE)
CVE-2025-30911CRITICAL04 abr 2025
WordPress RomethemeKit For Elementor plugin <= 1.5.4 - Arbitrary Plugin Installation/Activation to RCE vulnerability
48RISCO
abrir ↗
GitHub PoC★ 7
This PoC targets CVE-2025-30065, an RCE vulnerability in Apache Parquet via Avro schema deserialization. It abuses the getDefaultValue() mechanism to instantiate arbitrary record types during parsing, enabling code execution when untrusted data is processed without proper controls.
CVE-2025-30065CRITICAL04 abr 2025
Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
60RISCO
abrir ↗
GitHub PoC
all3njk/NextJS_CVE-2025-29927
CVE-2025-29927CRITICAL04 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗
GitHub PoC
Jenkins CLI arbitrary read (CVE-2024-23897 applies to versions below 2.442 and LTS 2.426.3)
CVE-2024-23897CRITICALsob ataqueransomware04 abr 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-23897CRITICALsob ataqueransomware04 abr 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗
GitHub PoC
Subrion File Upload Bypass to RCE and Custom File Upload (Authenticated) POC
CVE-2018-19422—04 abr 2025
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, beca
50RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL04 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗
GitHub PoC★ 2
YesWiki is a wiki system written in PHP. The squelette parameter is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server.
CVE-2025-31131HIGH04 abr 2025
Path Traversal allowing arbitrary read of files in Yeswiki
56RISCO
abrir ↗
GitHub PoC
CVE-2021-38163 - SAP NetWeaver AS Java Desynchronization Vulnerability
CVE-2021-38163CRITICALsob ataque04 abr 2025
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated
90RISCO
abrir ↗
Metasploit600
BentoML RCE
CVE-2025-27520CRITICAL04 abr 2025
BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
75RISCO
abrir ↗
Exploit-DB
Microchip TimeProvider 4100 Grandmaster (Banner Config Modules) 2.4.6 - Stored Cross-Site Scripting (XSS)
CVE-2024-43687HIGHremotehardware04 abr 2025
XSS vulnerability in bannerconfig endpoint in TimeProvider 4100
41RISCO
abrir ↗
GitHub PoC
PoC for CVE-2024-25600
CVE-2024-25600CRITICAL04 abr 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL04 abr 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir ↗
Exploit-DB
Microchip TimeProvider 4100 (Configuration modules) 2.4.6 - OS Command Injection
CVE-2024-9054HIGHremotehardware04 abr 2025
Remote code Execution inTimeProvider® 4100
46RISCO
abrir ↗
GitHub PoC★ 12
PoC
CVE-2025-30065CRITICAL04 abr 2025
Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
60RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-2825—04 abr 2025
35RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL03 abr 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM03 abr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗
← anteriorpágina 358 / 2.718próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.