Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.836exploits catalogados
32.133CVEs com exploração pública
1.932testados em laboratório
8.156 exploits
VulnCheck XDB
initial-access
CVE-2024-10914CRITICAL11 fev 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir
VulnCheck XDB
client-side
CVE-2024-42009CRITICALsob ataque11 fev 2025
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-53704HIGHsob ataqueransomware11 fev 2025
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-38856HIGHsob ataque11 fev 2025
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-27348CRITICALsob ataque10 fev 2025
Apache HugeGraph-Server: Command execution in gremlin
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2023-3864610 fev 2025
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-0847HIGHsob ataque09 fev 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHsob ataque08 fev 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-39713HIGH07 fev 2025
A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.
56RISCO
abrir
VulnCheck XDB
client-side
CVE-2022-30190HIGHsob ataqueransomware07 fev 2025
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-9474MEDIUMsob ataqueransomware06 fev 2025
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALsob ataqueransomware06 fev 2025
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2019-20085HIGHsob ataque06 fev 2025
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-24919HIGHsob ataqueransomware05 fev 2025
Information disclosure
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-7954CRITICAL05 fev 2025
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL05 fev 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-2961HIGH04 fev 2025
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-3400CRITICALsob ataqueransomware02 fev 2025
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-26319CRITICAL02 fev 2025
FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-2961HIGH02 fev 2025
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHsob ataqueransomware02 fev 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2014-370402 fev 2025
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware02 fev 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL02 fev 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-023231 jan 2025
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-33891HIGHsob ataque30 jan 2025
Apache Spark shell command injection vulnerability via Spark UI
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2022-36804HIGHsob ataque30 jan 2025
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-0235MEDIUM30 jan 2025
EventON (Free < 2.2.8, Premium < 4.5.5) - Unauthenticated Email Address Disclosure
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALsob ataqueransomware30 jan 2025
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALsob ataqueransomware30 jan 2025
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
anteriorpágina 98 / 272próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.