Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.689exploits catalogados
38.075CVEs com exploração pública
24.695testados em laboratório
81.689 exploits
GitHub PoC★ 4
numanturle/CVE-2025-25279
CVE-2025-25279CRITICAL24 fev 2025
Arbitrary file read in Mattermost Boards via import & export board archive
53RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-22515CRITICALsob ataqueransomware24 fev 2025
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataqueransomware24 fev 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2025-0411HIGHsob ataque23 fev 2025
7-Zip Mark-of-the-Web Bypass Vulnerability
83RISCO
abrir ↗
GitHub PoC
WinVerifyTrust Signature Validation CVE-2013-3900 Mitigation (EnableCertPaddingCheck)
CVE-2013-3900MEDIUMsob ataque23 fev 2025
WinVerifyTrust Signature Validation Vulnerability
75RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL23 fev 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir ↗
GitHub PoC★ 2
cesarbtakeda/7-Zip-CVE-2025-0411-POC
CVE-2025-0411HIGHsob ataque23 fev 2025
7-Zip Mark-of-the-Web Bypass Vulnerability
83RISCO
abrir ↗
GitHub PoC★ 1
WordPress CVE-2024-10924 Exploit for Really Simple Security plugin
CVE-2024-10924CRITICAL23 fev 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir ↗
GitHub PoC
Example usage: exploit.sh http://site.com
CVE-2023-1545HIGH22 fev 2025
SQL Injection in nilsteampassnet/teampass
41RISCO
abrir ↗
GitHub PoC★ 1
funixone/CVE-2024-24919---Exploit-Script
CVE-2024-24919HIGHsob ataqueransomware21 fev 2025
Information disclosure
100RISCO
abrir ↗
GitHub PoC★ 1
CVE-2025-24016: RCE in Wazuh server! Remote Code Execution
CVE-2025-24016CRITICALsob ataque21 fev 2025
Remote code execution in Wazuh server
100RISCO
abrir ↗
GitHub PoC★ 4
CVE-2023-1698 Proof of Concept (PoC)
CVE-2023-1698CRITICAL21 fev 2025
WAGO: WBM Command Injection in multiple products
85RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-24919HIGHsob ataqueransomware21 fev 2025
Information disclosure
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-1698CRITICAL21 fev 2025
WAGO: WBM Command Injection in multiple products
85RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-2961HIGH20 fev 2025
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RISCO
abrir ↗
Metasploit600
Remote Code Execution Vulnerability in XWiki Platform (CVE-2025-24893)
CVE-2025-24893CRITICALsob ataque20 fev 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir ↗
GitHub PoC★ 2
PoC of the vulnerability CVE-2024-23346
CVE-2024-23346CRITICAL20 fev 2025
pymatgen arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
48RISCO
abrir ↗
GitHub PoC
anu
CVE-2024-1651CRITICAL20 fev 2025
Torrentpier 2.4.1 - RCE
60RISCO
abrir ↗
GitHub PoC
CVE-2025-24971 exploit
CVE-2025-24971CRITICAL20 fev 2025
OS Command Injection endpoint '/upload/init' parameter 'filename' (RCE) in DumpDrop
48RISCO
abrir ↗
GitHub PoC★ 5
CVE-2025-24016: RCE in Wazuh server! Remote Code Execution
CVE-2025-24016CRITICALsob ataque20 fev 2025
Remote code execution in Wazuh server
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-24016CRITICALsob ataque20 fev 2025
Remote code execution in Wazuh server
100RISCO
abrir ↗
VulnCheck XDB
denial-of-service
CVE-2023-44487HIGHsob ataque19 fev 2025
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISCO
abrir ↗
GitHub PoC
barcrange/CVE-2025-0108-Authentication-Bypass-checker
CVE-2025-0108HIGHsob ataque19 fev 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RISCO
abrir ↗
GitHub PoC★ 1
ishwardeepp/CVE-2025-0411-MoTW-PoC
CVE-2025-0411HIGHsob ataque19 fev 2025
7-Zip Mark-of-the-Web Bypass Vulnerability
83RISCO
abrir ↗
GitHub PoC★ 2
NSE script that checks for CVE-2025-0108 vulnerability in Palo Alto Networks PAN-OS
CVE-2025-0108HIGHsob ataque19 fev 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RISCO
abrir ↗
GitHub PoC★ 1
PAN-OS CVE POC SCRIPT
CVE-2025-0108HIGHsob ataque19 fev 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RISCO
abrir ↗
GitHub PoC
This report details exploiting Trickster via an XSS in PrestaShop (CVE-2024-34716) to gain www-data access, extracting database credentials for SSH as james. A root shell in Docker is obtained via ChangeDetection.io (CVE-2024-32651), revealing adam’s credentials, followed by root escalation with CVE-2023-47268 in PrusaSlicer.
CVE-2024-34716CRITICAL19 fev 2025
PrestaShop vulnerable to XSS via customer contact form in FO, through file upload
60RISCO
abrir ↗
GitHub PoC
POC for CVE-2023-44487
CVE-2023-44487HIGHsob ataque19 fev 2025
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISCO
abrir ↗
Metasploit600
SPIP Saisies Plugin Unauthenticated RCE
CVE-2025-71243CRITICAL19 fev 2025
SPIP Saisies Plugin < 5.11.1 Remote Code Execution
63RISCO
abrir ↗
GitHub PoC
A fully functional exploit for a stack-based buffer overflow vulnerability in VideoLan’s VLC Media Player 0.9.4 when processing TiVo files.
CVE-2008-4654—19 fev 2025
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RISCO
abrir ↗
← anteriorpágina 378 / 2.723próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.