Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.529exploits catalogados
37.964CVEs com exploração pública
24.695testados em laboratório
81.643 exploits
VulnCheck XDB
initial-access
CVE-2018-13382CRITICALsob ataqueransomware26 fev 2025
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti
100RISCO
abrir ↗
GitHub PoC
cojoben/CVE-2018-13382
CVE-2018-13382CRITICALsob ataqueransomware26 fev 2025
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti
100RISCO
abrir ↗
GitHub PoC★ 6
CVE-2025-26263 - GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less, is vulnerable to credentials disclosure due to improper memory handling in the ASManagerService.exe process.
CVE-2025-26263MEDIUM26 fev 2025
GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to cred
33RISCO
abrir ↗
GitHub PoC
A Rust exploit for CVE-2024-23346 that functions as a "terminal" (tested on chemistry.htb)
CVE-2024-23346CRITICAL25 fev 2025
pymatgen arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
48RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-1302CRITICAL25 fev 2025
Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input
68RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-0282CRITICALsob ataqueransomware25 fev 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RISCO
abrir ↗
GitHub PoC★ 10
XWiki SolrSearchMacros 远程代码执行漏洞PoC(CVE-2025-24893)
CVE-2025-24893CRITICALsob ataque25 fev 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir ↗
GitHub PoC★ 21
JSONPath-plus Remote Code Execution
CVE-2025-1302CRITICAL25 fev 2025
Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input
68RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2021-22204MEDIUMsob ataque25 fev 2025
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALsob ataque25 fev 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALsob ataque25 fev 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir ↗
GitHub PoC★ 3
WP Load Gallery <= 2.1.6 - Authenticated (Author+) Arbitrary File Upload
CVE-2025-23942CRITICAL25 fev 2025
WordPress WP Load Gallery Plugin <= 2.1.6 - Arbitrary File Upload vulnerability
48RISCO
abrir ↗
GitHub PoC
vivigotnotime/CVE-2023-22515-Exploit-Script
CVE-2023-22515CRITICALsob ataqueransomware24 fev 2025
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISCO
abrir ↗
GitHub PoC
Code to exploit CVE-2021-4034
CVE-2021-4034HIGHsob ataqueransomware24 fev 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir ↗
GitHub PoC★ 3
shishirghimir/CVE-2024-53677-Exploit
CVE-2024-53677CRITICAL24 fev 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-21839HIGHsob ataque24 fev 2025
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISCO
abrir ↗
GitHub PoC★ 4
numanturle/CVE-2025-25279
CVE-2025-25279CRITICAL24 fev 2025
Arbitrary file read in Mattermost Boards via import & export board archive
53RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-22515CRITICALsob ataqueransomware24 fev 2025
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISCO
abrir ↗
GitHub PoC★ 1
Copy of the POC for CVE-2023-1545
CVE-2023-1545HIGH24 fev 2025
SQL Injection in nilsteampassnet/teampass
41RISCO
abrir ↗
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataqueransomware24 fev 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2025-0411HIGHsob ataque23 fev 2025
7-Zip Mark-of-the-Web Bypass Vulnerability
83RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL23 fev 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir ↗
GitHub PoC
WinVerifyTrust Signature Validation CVE-2013-3900 Mitigation (EnableCertPaddingCheck)
CVE-2013-3900MEDIUMsob ataque23 fev 2025
WinVerifyTrust Signature Validation Vulnerability
75RISCO
abrir ↗
GitHub PoC★ 2
cesarbtakeda/7-Zip-CVE-2025-0411-POC
CVE-2025-0411HIGHsob ataque23 fev 2025
7-Zip Mark-of-the-Web Bypass Vulnerability
83RISCO
abrir ↗
GitHub PoC★ 1
WordPress CVE-2024-10924 Exploit for Really Simple Security plugin
CVE-2024-10924CRITICAL23 fev 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir ↗
GitHub PoC
Example usage: exploit.sh http://site.com
CVE-2023-1545HIGH22 fev 2025
SQL Injection in nilsteampassnet/teampass
41RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-1698CRITICAL21 fev 2025
WAGO: WBM Command Injection in multiple products
85RISCO
abrir ↗
GitHub PoC★ 4
CVE-2023-1698 Proof of Concept (PoC)
CVE-2023-1698CRITICAL21 fev 2025
WAGO: WBM Command Injection in multiple products
85RISCO
abrir ↗
GitHub PoC★ 1
CVE-2025-24016: RCE in Wazuh server! Remote Code Execution
CVE-2025-24016CRITICALsob ataque21 fev 2025
Remote code execution in Wazuh server
100RISCO
abrir ↗
GitHub PoC★ 1
funixone/CVE-2024-24919---Exploit-Script
CVE-2024-24919HIGHsob ataqueransomware21 fev 2025
Information disclosure
100RISCO
abrir ↗
← anteriorpágina 376 / 2.722próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.