Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.445exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
13.627 exploits
GitHub PoC
dorattias/CVE-2025-26319
CVE-2025-26319CRITICAL02 fev 2025
FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.
75RISCO
abrir
GitHub PoC3
CVE-2024-56902 - Information disclosure vulnerability in GeoVision GV-ASManager web application with the version v6.1.0.0 or less, which discloses account information, including cleartext password.
CVE-2024-56902HIGH02 fev 2025
Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which
46RISCO
abrir
GitHub PoC2
CVE-2024-56898 - Broken access control vulnerability in GeoVision GV-ASManager web application with version v6.1.0.0 or less. This vulnerability allows low privilege users perform actions that they aren't authorized to, which can be leveraged to escalate privileges, create, modify or delete accounts.
CVE-2024-56898HIGH02 fev 2025
Broken access control vulnerability in Geovision GV-ASWeb with version v6.1.0.0 or less. This vulnerability allows low p
41RISCO
abrir
GitHub PoC
CVE-2017-8869 - MediaCoder 0.8.48.5888 - Local Buffer Overflow (SEH)
CVE-2017-886902 fev 2025
Buffer overflow in MediaCoder 0.8.48.5888 allows remote attackers to execute arbitrary code via a crafted .m3u file.
43RISCO
abrir
GitHub PoC
This code is taken from "Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Add Admin User)" and was converted to Python 3 to suit the exercise in Academy for Module "Attacking Commoon Applications" and section "Attacking Drupal".
CVE-2014-370402 fev 2025
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISCO
abrir
GitHub PoC
lukwagoasuman/-home-lukewago-Downloads-CVE-2021-23017-Nginx-1.14
CVE-2021-2301730 jan 2025
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t
35RISCO
abrir
GitHub PoC15
CVE-2024-8381: A SpiderMonkey Interpreter Type Confusion Bug.
CVE-2024-8381CRITICAL30 jan 2025
A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as t
48RISCO
abrir
GitHub PoC
asepsaepdin/CVE-2023-32315
CVE-2023-32315HIGHsob ataque30 jan 2025
Openfire administration console authentication bypass
100RISCO
abrir
GitHub PoC4
honeyb33z/cve-2020-11023-scanner
CVE-2020-11023MEDIUMsob ataque30 jan 2025
Potential XSS vulnerability in jQuery
85RISCO
abrir
GitHub PoC50
An XNU kernel race condition bug
CVE-2025-24118CRITICAL30 jan 2025
The issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.4, macOS Sequoia 15.3, macOS S
48RISCO
abrir
GitHub PoC1
## About The script has been made for exploiting the Laravel RCE (CVE-2021-3129) vulnerability.<br> This script allows you to write/execute commands on a website running <b>Laravel <= v8.4.2</b>, that has "APP_DEBUG" set to "true" in its ".env" file.
CVE-2021-3129CRITICALsob ataqueransomware30 jan 2025
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
GitHub PoC6
Proof of Concept for CVE-2022-45460
CVE-2022-45460CRITICAL30 jan 2025
Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C74311
48RISCO
abrir
GitHub PoC
asepsaepdin/CVE-2021-42013
CVE-2021-42013CRITICALsob ataqueransomware30 jan 2025
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC
asepsaepdin/CVE-2022-33891
CVE-2022-33891HIGHsob ataque30 jan 2025
Apache Spark shell command injection vulnerability via Spark UI
100RISCO
abrir
GitHub PoC
asepsaepdin/CVE-2022-36804
CVE-2022-36804HIGHsob ataque30 jan 2025
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
GitHub PoC11
A comprehensive all-in-one Python-based Proof of Concept script to discover and exploit a critical authentication bypass vulnerability (CVE-2024-55591) in certain Fortinet devices.
CVE-2024-55591CRITICALsob ataqueransomware29 jan 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISCO
abrir
GitHub PoC1
bsec404/CVE-2020-0796
CVE-2020-0796CRITICALsob ataqueransomware29 jan 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC1
A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.
CVE-2024-12084CRITICAL29 jan 2025
Rsync: heap buffer overflow in rsync due to improper checksum length handling
70RISCO
abrir
GitHub PoC
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
CVE-2024-11972CRITICAL29 jan 2025
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
75RISCO
abrir
GitHub PoC3
watchtowrlabs/nakivo-arbitrary-file-read-poc-CVE-2024-48248
CVE-2024-48248HIGHsob ataque28 jan 2025
NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /
100RISCO
abrir
GitHub PoC2
Ivanti Connect Secure, Policy Secure & ZTA Gateways - CVE-2025-0282
CVE-2025-0282CRITICALsob ataqueransomware28 jan 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RISCO
abrir
GitHub PoC1
7-Zip Mark-of-the-Web绕过漏洞PoC(CVE-2025-0411)
CVE-2025-0411HIGHsob ataque27 jan 2025
7-Zip Mark-of-the-Web Bypass Vulnerability
83RISCO
abrir
GitHub PoC77
watchtowrlabs/fortios-auth-bypass-poc-CVE-2024-55591
CVE-2024-55591CRITICALsob ataqueransomware27 jan 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISCO
abrir
GitHub PoC289
针对JWT渗透开发的漏洞验证/密钥爆破工具,针对CVE-2015-9235/空白密钥/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ,也可使用字典/字符枚举(包括JJWT)的方式进行爆破(JWT Crack)
CVE-2018-011427 jan 2025
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISCO
abrir
GitHub PoC
A rewrite of the Polkit vulnerability.
CVE-2021-4034HIGHsob ataque27 jan 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
CVE-2021-43798 working exploit
CVE-2021-43798HIGHsob ataque26 jan 2025
Grafana path traversal
100RISCO
abrir
GitHub PoC
Repository for internship test task.
CVE-2024-25600CRITICAL26 jan 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir
GitHub PoC1
CVE-2016-2555 Exploit
CVE-2016-255526 jan 2025
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbi
60RISCO
abrir
GitHub PoC4
Exploit for WordPress File Upload Plugin - All versions up to 4.24.11 are vulnerable.
CVE-2024-9047CRITICAL25 jan 2025
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
85RISCO
abrir
GitHub PoC1
CVE-2024-3673 Exploit: Local File Inclusion in Web Directory Free WordPress Plugin ( before 1.7.3 )
CVE-2024-3673CRITICAL24 jan 2025
Web Directory Free < 1.7.3 - Unauthenticated LFI
63RISCO
abrir
anteriorpágina 180 / 455próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.