Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.524exploits catalogados
37.962CVEs com exploração pública
24.695testados em laboratório
81.524 exploits
GitHub PoC
Sp4ceDogy/NPE-CS-V-CVE-2021-1675
CVE-2021-1675HIGHsob ataqueransomware10 mar 2025
Windows Print Spooler Remote Code Execution Vulnerability
100RISCO
abrir ↗
GitHub PoC★ 3
Ivanti Remote code execution
CVE-2025-0282CRITICALsob ataqueransomware10 mar 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RISCO
abrir ↗
GitHub PoC
Sornphut/CVE-2021-3156-Heap-Based-Buffer-Overflow-in-Sudo-Baron-Samedit-
CVE-2021-3156HIGHsob ataque10 mar 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir ↗
Metasploit600
Tomcat Partial PUT Java Deserialization
CVE-2025-24813CRITICALsob ataque10 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2025-21333HIGHsob ataque10 mar 2025
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RISCO
abrir ↗
GitHub PoC
sk00l/CVE-2023-30258
CVE-2023-30258CRITICAL09 mar 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-27350CRITICALsob ataqueransomware09 mar 2025
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir ↗
GitHub PoC★ 4
Unauthenticated remote command execution in Papercut service allows an attacker to execute commands due to improper access controls in the SetupCompleted Java class.
CVE-2023-27350CRITICALsob ataqueransomware09 mar 2025
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-27636MEDIUM09 mar 2025
Apache Camel: Camel Message Header Injection via Improper Filtering
55RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-30258CRITICAL09 mar 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISCO
abrir ↗
GitHub PoC
cve-2017-5487 wp rest api 취약점
CVE-2017-5487—08 mar 2025
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RISCO
abrir ↗
GitHub PoC
progress moveit cve-2024-5806
CVE-2024-5806CRITICAL08 mar 2025
MOVEit Transfer Authentication Bypass Vulnerability
85RISCO
abrir ↗
GitHub PoC
Zimbra CVE-2024-45519
CVE-2024-45519CRITICALsob ataque08 mar 2025
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-45519CRITICALsob ataque08 mar 2025
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RISCO
abrir ↗
GitHub PoC
elphon/CVE-2007-2447-Exploit
CVE-2007-2447—08 mar 2025
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-5806CRITICAL08 mar 2025
MOVEit Transfer Authentication Bypass Vulnerability
85RISCO
abrir ↗
GitHub PoC
CVE-2023-40028 is a security vulnerability affecting Ghost CMS versions prior to 5.59.1.
CVE-2023-40028MEDIUM07 mar 2025
Arbitrary file read via symlinks in Ghost
45RISCO
abrir ↗
GitHub PoC★ 1
A Critical Windows OLE Zero-Click Vulnerability. This is a proof-of-concept for CVE-2025-21298 - Windows OLE Remote Code Execution Vulnerability (CVSS 9.8). This is a memory corruption PoC
CVE-2025-21298CRITICAL07 mar 2025
Windows OLE Remote Code Execution Vulnerability
70RISCO
abrir ↗
GitHub PoC★ 4
Python3 Rewrite of SmarterMail < Build 6985 Remote Code Execution found by 1F98D (CVE-2019-7214) POC
CVE-2019-7214—07 mar 2025
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker co
60RISCO
abrir ↗
GitHub PoC
Simulation of the Zerologon (CVE-2020-1472) vulnerability attack in Active Directory on Windows Server 2016 and the use of the Trend Micro Deep Security solution to prevent such attacks.
CVE-2020-1472MEDIUMsob ataqueransomware07 mar 2025
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-23692CRITICALsob ataqueransomware06 mar 2025
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISCO
abrir ↗
GitHub PoC
HFS 2.3m SERVER RCE Vulnerability exploit
CVE-2024-23692CRITICALsob ataqueransomware06 mar 2025
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2023-4911HIGHsob ataque06 mar 2025
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISCO
abrir ↗
GitHub PoC★ 2
Arbitrary file read in Grafana allows an attacker to read server files by abusing a path traversal.
CVE-2021-43798HIGHsob ataque06 mar 2025
Grafana path traversal
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2021-43798HIGHsob ataque06 mar 2025
Grafana path traversal
100RISCO
abrir ↗
GitHub PoC
This repository contains a PoC for exploiting CVE-2024-32002, a vulnerability in Git that allows RCE during a git clone operation. By crafting repositories with submodules in a specific way, an attacker can exploit symlink handling on case-insensitive filesystems to write files into the .git/ directory, leading to the execution of malicious hooks.
CVE-2024-32002CRITICAL06 mar 2025
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir ↗
GitHub PoC
This repository contains a PoC for exploiting CVE-2024-32002, a vulnerability in Git that allows RCE during a git clone operation. By crafting repositories with submodules in a specific way, an attacker can exploit symlink handling on case-insensitive filesystems to write files into the .git/ directory, leading to the execution of malicious hooks.
CVE-2024-32002CRITICAL06 mar 2025
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir ↗
GitHub PoC★ 2
Newscrunch <= 1.8.4 - Authenticated (Subscriber+) Arbitrary File Upload
CVE-2025-1307CRITICAL05 mar 2025
Newscrunch <= 1.8.4 - Authenticated (Subscriber+) Arbitrary File Upload
48RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2019-0232—05 mar 2025
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-50164—05 mar 2025
Apache Struts: File upload component had a directory traversal vulnerability
45RISCO
abrir ↗
← anteriorpágina 373 / 2.718próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.