Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.689exploits catalogados
38.075CVEs com exploração pública
24.695testados em laboratório
81.689 exploits
VulnCheck XDB
infoleak
CVE-2024-39713HIGH07 fev 2025
A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.
56RISCO
abrir ↗
GitHub PoC★ 4
Cityworks deserialization of untrusted data vulnerability Detection
CVE-2025-0994HIGHsob ataque07 fev 2025
Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to
83RISCO
abrir ↗
GitHub PoC
PoC of CVE-2022-30190
CVE-2022-30190HIGHsob ataqueransomware07 fev 2025
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir ↗
GitHub PoC★ 4
Snizi/Moodle-CVE-2024-43425-Exploit
CVE-2024-43425HIGH07 fev 2025
Moodle: remote code execution via calculated question types
78RISCO
abrir ↗
GitHub PoC
Directory Traversal Exploit written in Bash for NVMS-1000 (CVE-2019-20085).
CVE-2019-20085HIGHsob ataque06 fev 2025
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-9474MEDIUMsob ataqueransomware06 fev 2025
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RISCO
abrir ↗
GitHub PoC★ 1
This is a Python script that exploits the CVE-2024-6624 vulnerability in the JSON API User <= 3.9.3 plugin for WordPress.
CVE-2024-6624CRITICAL06 fev 2025
JSON API User <= 3.9.3 - Unauthenticated Privilege Escalation
48RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2019-20085HIGHsob ataque06 fev 2025
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RISCO
abrir ↗
GitHub PoC★ 4
Python script for CVE-2024-0012 / CVE-2024-9474 exploit
CVE-2024-0012CRITICALsob ataqueransomware06 fev 2025
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALsob ataqueransomware06 fev 2025
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISCO
abrir ↗
GitHub PoC
cy3erdr4g0n/CVE-2024-10924
CVE-2024-10924CRITICAL05 fev 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir ↗
GitHub PoC★ 1
SOC287 - Arbitrary File Read on Checkpoint Security Gateway [CVE-2024-24919]
CVE-2024-24919HIGHsob ataqueransomware05 fev 2025
Information disclosure
100RISCO
abrir ↗
GitHub PoC
Arthikw3b/RCE-CVE-2024-7954
CVE-2024-7954CRITICAL05 fev 2025
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISCO
abrir ↗
GitHub PoC
daikinitanda/-CVE-2024-47875-
CVE-2024-47875CRITICAL05 fev 2025
DOMPurify nesting-based mXSS
48RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL05 fev 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir ↗
Metasploit600
D-Tale RCE
CVE-2025-0655—05 fev 2025
15RISCO
abrir ↗
GitHub PoC
KGorbakon/CVE-2023-41425
CVE-2023-41425MEDIUM05 fev 2025
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-7954CRITICAL05 fev 2025
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISCO
abrir ↗
Metasploit600
D-Tale RCE
CVE-2024-3408CRITICAL05 fev 2025
Authentication Bypass and RCE in man-group/dtale
85RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-24919HIGHsob ataqueransomware05 fev 2025
Information disclosure
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-2961HIGH04 fev 2025
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RISCO
abrir ↗
GitHub PoC★ 6
CVE-2019-2215 poc for Huawei hardened kernel
CVE-2019-2215HIGHsob ataque04 fev 2025
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir ↗
GitHub PoC★ 1
qw3rtyou/CVE-2021-44228_dockernize
CVE-2021-44228CRITICALsob ataqueransomware04 fev 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗
GitHub PoC★ 1
This script checks for devices vulnerable to the EternalBlue exploit (CVE-2017-0144) in a network using SMB.
CVE-2017-0144HIGHsob ataqueransomware03 fev 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir ↗
GitHub PoC
Code to decrypt Huawei passwords CVE-2012-4960
CVE-2012-4960—03 fev 2025
The Huawei NE5000E, MA5200G, NE40E, NE80E, ATN, NE40, NE80, NE20E-X6, NE20, ME60, CX600, CX200, CX300, ACU, WLAN AC 6605
23RISCO
abrir ↗
GitHub PoC
In this challenge, I analyzed the Spring4Shell (CVE-2022-22965) vulnerability, investigated security bypasses, and wrote an Incident Postmortem Report detailing the detection, impact, and resolution of the attack. I also implemented a firewall rule in Python to block malicious requests and prevent future exploitation.
CVE-2022-22965CRITICALsob ataque03 fev 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir ↗
GitHub PoC
dorattias/CVE-2025-26319
CVE-2025-26319CRITICAL02 fev 2025
FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.
75RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL02 fev 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir ↗
GitHub PoC★ 2
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
CVE-2024-10924CRITICAL02 fev 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir ↗
GitHub PoC★ 1
hashdr1ft/SOC274-Palo-Alto-Networks-PAN-OS-Command-Injection-Vulnerability-Exploitation-CVE-2024-3400
CVE-2024-3400CRITICALsob ataqueransomware02 fev 2025
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISCO
abrir ↗
← anteriorpágina 382 / 2.723próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.