Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.524exploits catalogados
37.962CVEs com exploração pública
24.695testados em laboratório
81.524 exploits
GitHub PoC★ 2
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.
CVE-2023-30258CRITICAL16 mar 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2025-24071MEDIUM16 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir ↗
GitHub PoC★ 407
CVE-2025-24071: NTLM Hash Leak via RAR/ZIP Extraction and .library-ms File
CVE-2025-24071MEDIUM16 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir ↗
GitHub PoC
CVE-2024-9047, wfu_file_downloader.php
CVE-2024-9047CRITICAL16 mar 2025
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
85RISCO
abrir ↗
GitHub PoC
DavidBr27/CVE-2013-3900-Remediation-Script
CVE-2013-3900MEDIUMsob ataque16 mar 2025
WinVerifyTrust Signature Validation Vulnerability
75RISCO
abrir ↗
GitHub PoC
RCE, Citirx ADC and Gateway Directory Traversal
CVE-2019-19781CRITICALsob ataqueransomware16 mar 2025
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2024-7014HIGH16 mar 2025
Improper multimedia file attachment validation in Telegram for Android app
41RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2019-19781CRITICALsob ataqueransomware16 mar 2025
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-30258CRITICAL16 mar 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALsob ataqueransomware15 mar 2025
Argument Injection in PHP-CGI
100RISCO
abrir ↗
GitHub PoC★ 52
一個測試CVE-2024-4577和CVE-2024-8926的安全滲透工具
CVE-2024-4577CRITICALsob ataqueransomware15 mar 2025
Argument Injection in PHP-CGI
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2016-5195HIGHsob ataque15 mar 2025
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir ↗
GitHub PoC
ishwardeepp/CVE-2025-22604-Cacti-RCE
CVE-2025-22604CRITICAL15 mar 2025
Cacti has Authenticated RCE via multi-line SNMP responses
48RISCO
abrir ↗
GitHub PoC★ 2
PoC - OpenSSL NPN Buffer Overread
CVE-2024-5535CRITICAL15 mar 2025
SSL_select_next_proto buffer overread
48RISCO
abrir ↗
GitHub PoC★ 2
CVE-2024-51788 - WordPress The Novel Design Store Directory plugin <= 4.3.0 - Unauthenticated Arbitrary File Upload Vulnerability
CVE-2024-51788CRITICAL15 mar 2025
WordPress The Novel Design Store Directory plugin <= 4.3.0 - Arbitrary File Upload vulnerability
48RISCO
abrir ↗
GitHub PoC★ 2
One-Click-Root program based on CVE-2016-5195, that works on the old 'PlayStation Certified' android devices
CVE-2016-5195HIGHsob ataque15 mar 2025
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir ↗
GitHub PoC
Webmin 1.580 /file/show.cgi Remote Code Execution
CVE-2012-2982—14 mar 2025
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISCO
abrir ↗
GitHub PoC
DeividasTerechovas/SOC335-CVE-2024-49138-Exploitation-Detected
CVE-2024-49138HIGHsob ataque14 mar 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir ↗
GitHub PoC
redpack-kr/CVE-2025-26319
CVE-2025-26319CRITICAL14 mar 2025
FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.
75RISCO
abrir ↗
GitHub PoC★ 197
his repository contains an automated Proof of Concept (PoC) script for exploiting **CVE-2025-24813**, a Remote Code Execution (RCE) vulnerability in Apache Tomcat. The vulnerability allows an attacker to upload a malicious serialized payload to the server, leading to arbitrary code execution via deserialization when specific conditions are met.
CVE-2025-24813CRITICALsob ataque14 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗
GitHub PoC★ 11
cve-2025-24813验证脚本
CVE-2025-24813CRITICALsob ataque14 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗
GitHub PoC
Pei4AN/CVE-2025-28915
CVE-2025-28915CRITICAL14 mar 2025
WordPress ThemeEgg ToolKit plugin <= 1.2.9 - Arbitrary File Upload vulnerability
48RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALsob ataque14 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗
GitHub PoC★ 1
User name enumeration against SSH daemons affected by CVE-2016-6210.
CVE-2016-6210MEDIUM14 mar 2025
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RISCO
abrir ↗
GitHub PoC★ 3
CVE-2025-24813_POC
CVE-2025-24813CRITICALsob ataque14 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗
GitHub PoC★ 1
Security Researcher
CVE-2025-24813CRITICALsob ataque14 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALsob ataque14 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALsob ataque14 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALsob ataque14 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALsob ataque13 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗
← anteriorpágina 371 / 2.718próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.