Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.689exploits catalogados
38.075CVEs com exploração pública
24.695testados em laboratório
81.689 exploits
Metasploit300
NetAlertX File Read Vulnerability
CVE-2024-48766HIGH30 jan 2025
NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and
48RISCO
abrir ↗
Metasploit600
Unauthenticated RCE in NetAlertX
CVE-2024-46506CRITICAL30 jan 2025
NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because fun
75RISCO
abrir ↗
GitHub PoC★ 1
## About The script has been made for exploiting the Laravel RCE (CVE-2021-3129) vulnerability.<br> This script allows you to write/execute commands on a website running <b>Laravel <= v8.4.2</b>, that has "APP_DEBUG" set to "true" in its ".env" file.
CVE-2021-3129CRITICALsob ataqueransomware30 jan 2025
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir ↗
GitHub PoC
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
CVE-2024-11972CRITICAL29 jan 2025
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
75RISCO
abrir ↗
GitHub PoC★ 1
A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.
CVE-2024-12084CRITICAL29 jan 2025
Rsync: heap buffer overflow in rsync due to improper checksum length handling
70RISCO
abrir ↗
GitHub PoC★ 11
A comprehensive all-in-one Python-based Proof of Concept script to discover and exploit a critical authentication bypass vulnerability (CVE-2024-55591) in certain Fortinet devices.
CVE-2024-55591CRITICALsob ataqueransomware29 jan 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2020-0796CRITICALsob ataqueransomware29 jan 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-55591CRITICALsob ataqueransomware29 jan 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-55591CRITICALsob ataqueransomware29 jan 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2020-0796CRITICALsob ataqueransomware29 jan 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir ↗
GitHub PoC★ 1
bsec404/CVE-2020-0796
CVE-2020-0796CRITICALsob ataqueransomware29 jan 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-11972CRITICAL29 jan 2025
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
75RISCO
abrir ↗
GitHub PoC★ 2
Ivanti Connect Secure, Policy Secure & ZTA Gateways - CVE-2025-0282
CVE-2025-0282CRITICALsob ataqueransomware28 jan 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-48248HIGHsob ataque28 jan 2025
NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /
100RISCO
abrir ↗
GitHub PoC★ 3
watchtowrlabs/nakivo-arbitrary-file-read-poc-CVE-2024-48248
CVE-2024-48248HIGHsob ataque28 jan 2025
NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /
100RISCO
abrir ↗
Metasploit600
Cacti Graph Template authenticated RCE versions prior to 1.2.29
CVE-2025-24367HIGH27 jan 2025
Cacti allows Arbitrary File Creation leading to RCE
48RISCO
abrir ↗
GitHub PoC★ 1
7-Zip Mark-of-the-Web绕过漏洞PoC(CVE-2025-0411)
CVE-2025-0411HIGHsob ataque27 jan 2025
7-Zip Mark-of-the-Web Bypass Vulnerability
83RISCO
abrir ↗
GitHub PoC★ 77
watchtowrlabs/fortios-auth-bypass-poc-CVE-2024-55591
CVE-2024-55591CRITICALsob ataqueransomware27 jan 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-55591CRITICALsob ataqueransomware27 jan 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-2961HIGH27 jan 2025
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RISCO
abrir ↗
GitHub PoC★ 287
针对JWT渗透开发的漏洞验证/密钥爆破工具,针对CVE-2015-9235/空白密钥/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ,也可使用字典/字符枚举(包括JJWT)的方式进行爆破(JWT Crack)
CVE-2018-0114—27 jan 2025
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISCO
abrir ↗
GitHub PoC
A rewrite of the Polkit vulnerability.
CVE-2021-4034HIGHsob ataqueransomware27 jan 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-55591CRITICALsob ataqueransomware26 jan 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL26 jan 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2021-43798HIGHsob ataque26 jan 2025
Grafana path traversal
100RISCO
abrir ↗
GitHub PoC★ 1
CVE-2016-2555 Exploit
CVE-2016-2555—26 jan 2025
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbi
60RISCO
abrir ↗
GitHub PoC
CVE-2021-43798 working exploit
CVE-2021-43798HIGHsob ataque26 jan 2025
Grafana path traversal
100RISCO
abrir ↗
GitHub PoC
Repository for internship test task.
CVE-2024-25600CRITICAL26 jan 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-9047CRITICAL25 jan 2025
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
85RISCO
abrir ↗
GitHub PoC★ 4
Exploit for WordPress File Upload Plugin - All versions up to 4.24.11 are vulnerable.
CVE-2024-9047CRITICAL25 jan 2025
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
85RISCO
abrir ↗
← anteriorpágina 384 / 2.723próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.