Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.689exploits catalogados
38.075CVEs com exploração pública
24.695testados em laboratório
81.689 exploits
GitHub PoC
Zita Site Builder <= 1.0.2 - Missing Authorization to Arbitrary Plugin Installation
CVE-2024-54369CRITICAL19 dez 2024
WordPress Zita Site Builder plugin <= 1.0.2 - Arbitrary Plugin Installation and Activation vulnerability
48RISCO
abrir ↗
GitHub PoC★ 1
yiliufeng168/CVE-2024-50379-POC
CVE-2024-50379CRITICAL19 dez 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RISCO
abrir ↗
Metasploit600
Craft CMS Twig Template Injection RCE via FTP Templates Path
CVE-2024-56145CRITICALsob ataque19 dez 2024
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALsob ataqueransomware19 dez 2024
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2009-2265—18 dez 2024
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL18 dez 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir ↗
GitHub PoC★ 4
v3153/CVE-2024-50379-POC
CVE-2024-50379CRITICAL18 dez 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL18 dez 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir ↗
GitHub PoC
CVE-2023-4966-exploit
CVE-2023-4966CRITICALsob ataqueransomware18 dez 2024
Unauthenticated sensitive information disclosure
100RISCO
abrir ↗
GitHub PoC★ 1
Adobe ColdFusion 8 - Remote Command Execution (RCE)
CVE-2009-2265—18 dez 2024
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RISCO
abrir ↗
GitHub PoC★ 2
dustblessnotdust/CVE-2024-53677-S2-067-thread
CVE-2024-53677CRITICAL18 dez 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir ↗
GitHub PoC★ 3
yangyanglo/CVE-2024-53677
CVE-2024-53677CRITICAL17 dez 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir ↗
GitHub PoC★ 3
A Docker-based environment to reproduce the CVE-2024-53677 vulnerability in Apache Struts 2.
CVE-2024-53677CRITICAL17 dez 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir ↗
GitHub PoC★ 6
Proof of concept (POC) for CVE-2024-45337
CVE-2024-45337CRITICAL17 dez 2024
Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
48RISCO
abrir ↗
GitHub PoC★ 1
An example project that showcases golang code vulnerable to CVE-2024-45337
CVE-2024-45337CRITICAL17 dez 2024
Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
48RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL17 dez 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2019-12725—16 dez 2024
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISCO
abrir ↗
GitHub PoC
DS.DownloadList <= 1.3 - Unauthenticated PHP Object Injection
CVE-2024-50507CRITICAL16 dez 2024
WordPress DS.DownloadList plugin <= 1.3 - PHP Object Injection vulnerability
48RISCO
abrir ↗
VulnCheck XDB
local
CVE-2024-49039HIGHsob ataqueransomware16 dez 2024
Windows Task Scheduler Elevation of Privilege Vulnerability
76RISCO
abrir ↗
VulnCheck XDB
local
CVE-2024-1086HIGHsob ataqueransomware16 dez 2024
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISCO
abrir ↗
GitHub PoC★ 21
LLfam/CVE-2024-1086
CVE-2024-1086HIGHsob ataqueransomware16 dez 2024
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISCO
abrir ↗
GitHub PoC★ 14
A short scraper looking for a POC of CVE-2024-49112
CVE-2024-49112CRITICAL16 dez 2024
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
70RISCO
abrir ↗
GitHub PoC
t0mmy4/CVE-2019-12725-modified-exp
CVE-2019-12725—16 dez 2024
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISCO
abrir ↗
GitHub PoC
Rahul-Thakur7/CVE-2023-21554
CVE-2023-21554CRITICAL16 dez 2024
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
85RISCO
abrir ↗
GitHub PoC★ 1
The EXP/POC of CVE-2019-12725
CVE-2019-12725—16 dez 2024
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISCO
abrir ↗
Metasploit600
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) unauthenticated Remote Code Execution
CVE-2024-12356CRITICALsob ataque16 dez 2024
Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA)
100RISCO
abrir ↗
Metasploit600
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) unauthenticated Remote Code Execution
CVE-2025-1094HIGH16 dez 2024
PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation
78RISCO
abrir ↗
GitHub PoC
redspy-sec/CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware16 dez 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-41773HIGHsob ataqueransomware16 dez 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2019-12725—16 dez 2024
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISCO
abrir ↗
← anteriorpágina 394 / 2.723próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.