Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.689exploits catalogados
38.075CVEs com exploração pública
24.695testados em laboratório
81.689 exploits
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL14 fev 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir ↗
GitHub PoC
php-cgi-cve-2024-4577
CVE-2024-4577CRITICALsob ataqueransomware14 fev 2025
Argument Injection in PHP-CGI
100RISCO
abrir ↗
GitHub PoC★ 2
A Proof-of-Concept (PoC) exploit for CVE-2024-10924, a vulnerability in the Really Simple SSL WordPress plugin that allows bypassing two-factor authentication (2FA). Includes mitigation techniques to secure affected WordPress sites.
CVE-2024-10924CRITICAL14 fev 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALsob ataqueransomware14 fev 2025
Argument Injection in PHP-CGI
100RISCO
abrir ↗
GitHub PoC
Didarul342/CVE-2024-4577
CVE-2024-4577CRITICALsob ataqueransomware14 fev 2025
Argument Injection in PHP-CGI
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-10914CRITICAL14 fev 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALsob ataqueransomware14 fev 2025
Argument Injection in PHP-CGI
100RISCO
abrir ↗
GitHub PoC★ 8
PoC exploit for CVE-2025-0108 - PAN-OS Authentication Bypass
CVE-2025-0108HIGHsob ataque14 fev 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-0108HIGHsob ataque14 fev 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2024-42009CRITICALsob ataque13 fev 2025
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-0108HIGHsob ataque13 fev 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-47575CRITICALsob ataque13 fev 2025
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2
100RISCO
abrir ↗
GitHub PoC★ 32
Palo Alto Networks PAN-OS 身份验证绕过漏洞批量检测脚本(CVE-2025-0108)
CVE-2025-0108HIGHsob ataque13 fev 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2021-21551HIGHsob ataque13 fev 2025
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RISCO
abrir ↗
GitHub PoC
CMS Made Simple < 2.2.10 - SQL Injection python3
CVE-2019-9053—13 fev 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir ↗
GitHub PoC
CVE-2016-6914-UniFiVideo-LPE
CVE-2016-6914—13 fev 2025
Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local u
23RISCO
abrir ↗
GitHub PoC
luke0x90/CVE-2021-21551
CVE-2021-21551HIGHsob ataque13 fev 2025
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RISCO
abrir ↗
GitHub PoC★ 2
POC for Roundcube vulnerabilities CVE-2024-42008 and CVE-2024-42010
CVE-2024-42008CRITICAL13 fev 2025
A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7
60RISCO
abrir ↗
Metasploit300
mySCADA myPRO Manager Credential Harvester (CVE-2025-24865 and CVE-2025-22896)
CVE-2025-22896CRITICAL13 fev 2025
mySCADA myPRO Manager Cleartext Storage of Sensitive Information
43RISCO
abrir ↗
Metasploit300
mySCADA myPRO Manager Credential Harvester (CVE-2025-24865 and CVE-2025-22896)
CVE-2025-24865CRITICAL13 fev 2025
mySCADA myPRO Manager Missing Authentication for Critical Function
43RISCO
abrir ↗
GitHub PoC
Apache Struts CVE-2024-53677 Exploitation
CVE-2024-53677CRITICAL13 fev 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir ↗
GitHub PoC★ 1
This Proof of Concept (PoC) demonstrates an exploit for CVE-2024-42009, leveraging a cross-site scripting (XSS) vulnerability to extract emails from a target webmail application. The attack injects a malicious payload that exfiltrates email content to an attacker-controlled listener.
CVE-2024-42009CRITICALsob ataque13 fev 2025
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-24016CRITICALsob ataque13 fev 2025
Remote code execution in Wazuh server
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL13 fev 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir ↗
GitHub PoC★ 4
huseyinstif/CVE-2025-24016-Nuclei-Template
CVE-2025-24016CRITICALsob ataque13 fev 2025
Remote code execution in Wazuh server
100RISCO
abrir ↗
GitHub PoC
qnole000/CVE-2024-51378
CVE-2024-51378CRITICALsob ataqueransomware12 fev 2025
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-2961HIGH12 fev 2025
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RISCO
abrir ↗
GitHub PoC
Active Exploitation of Atlassian’s Questions for Confluence App CVE-2022-26134
CVE-2022-26134CRITICALsob ataqueransomware12 fev 2025
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir ↗
GitHub PoC
Modified exploit for CVE-2021-43798 compatible with both Windows and Linux hosts.
CVE-2021-43798HIGHsob ataque12 fev 2025
Grafana path traversal
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2021-43798HIGHsob ataque12 fev 2025
Grafana path traversal
100RISCO
abrir ↗
← anteriorpágina 380 / 2.723próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.