Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.597exploits catalogados
34.511CVEs com exploração pública
24.695testados em laboratório
75.589 exploits
GitHub PoC
Log4Shell CVE-2021-44228 PoC
CVE-2021-44228CRITICALsob ataqueransomware09 set 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
This repository contains the corrected code for CVE: 2019-9053
CVE-2019-905309 set 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
GitHub PoC6
CVE-2025-43300: iOS/macOS DNG Image Processing Memory Corruption
CVE-2025-43300CRITICALsob ataque09 set 2025
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1
83RISCO
abrir
GitHub PoC12
This repository contains a python exploit code for CVE-2024-28397 intended for use on the "CodePartTwo" machine on Hack The Box (HTB).
CVE-2024-28397MEDIUM09 set 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISCO
abrir
GitHub PoC
PoC Script for the CVE-2018-11776 vuln
CVE-2018-11776HIGHsob ataque09 set 2025
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
Metasploit600
Remote Code Execution Vulnerability in MotionEye Frontend (CVE-2025-60787)
CVE-2025-60787HIGH09 set 2025
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name
61RISCO
abrir
GitHub PoC
FuelCMS 1.4.1 Command Injection/Remote Code Execution.
CVE-2018-1676309 set 2025
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir
GitHub PoC
In OctoPrint version <=1.11.2, an attacker with file upload access (e.g., valid API key or session) can craft a malicious filename that bypasses sanitization and is later executed by OctoPrint’s event system, leading to remote code execution (RCE) on the host
CVE-2025-58180HIGH09 set 2025
OctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File Upload
46RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-11776HIGHsob ataque09 set 2025
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-57819CRITICALsob ataque08 set 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir
GitHub PoC
CVE-2024-6387
CVE-2024-6387HIGH08 set 2025
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-57819CRITICALsob ataque08 set 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir
GitHub PoC1
CVE-2025-54914 exposes a critical flaw in Azure Networking that allows attackers to escalate privileges and control routing across subnets. The article explains how a missing privilege check in the “GetRouteTable” API enables lateral movement and remote exploitation, urging immediate patching and monitoring
CVE-2025-54914CRITICAL08 set 2025
Azure Networking Elevation of Privilege Vulnerability
48RISCO
abrir
VulnCheck XDB
local
CVE-2025-21333HIGHsob ataque08 set 2025
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RISCO
abrir
GitHub PoC1
Vulnerability Detection and Mitigation Apache ActiveMQ | Security Architectures and Systems Administration - on - Apache ActiveMQ Deserialization Remote Code Execution (RCE) – CVE-2023-46604
CVE-2023-46604CRITICALsob ataqueransomware08 set 2025
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM08 set 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir
GitHub PoC
Este repositorio contiene un exploit automatizado desarrollado con fines educativos y de investigación en ciberseguridad, dirigido a demostrar una potencial vulnerabilidad de ejecución remota de código (RCE) en Apache Tomcat (CVE-2025-24813).
CVE-2025-24813CRITICALsob ataque08 set 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC
boriitoo/CVE-2012-2982
CVE-2012-298208 set 2025
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISCO
abrir
GitHub PoC
CVE-2025-47812
CVE-2025-47812CRITICALsob ataque08 set 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir
GitHub PoC
CTY-Research-1/CVE-2025-47812_Lab_environment
CVE-2025-47812CRITICALsob ataque07 set 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALsob ataque07 set 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
GitHub PoC2
CVE-2025-23266 targets FastAPI’s parse_request() function, where oversized HTTP headers cause a buffer overflow and remote code execution. The article explains how attackers can escape container boundaries, compromise AI workloads, and how tools like Sentinel can detect and mitigate the threat
CVE-2025-23266CRITICAL07 set 2025
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, wher
48RISCO
abrir
GitHub PoC10
CVE-2025-7771 ThrottleStop.sys privilege escalation exploit - unrestricted IOCTL access to physical memory via MmMapIoSpace
CVE-2025-7771HIGH07 set 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RISCO
abrir
GitHub PoC3
PoC showing unauthenticated remote code execution in Erlang/OTP SSH server. By exploiting a flaw in SSH protocol message handling, an attacker can execute arbitrary commands on the target without valid credentials.
CVE-2025-32433CRITICALsob ataque07 set 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
GitHub PoC
Boon-Rekcah/CMS-Made-Simple-2.2.9-CVE-2019-9053
CVE-2019-905307 set 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
VulnCheck XDB
local
CVE-2025-7771HIGH07 set 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-52970HIGH07 set 2025
A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.
56RISCO
abrir
GitHub PoC3
This is CVE-2025-53690 Analysis Documents.
CVE-2025-53690CRITICALsob ataque07 set 2025
Sitecore Products ViewState Deserialization Vulnerability
90RISCO
abrir
GitHub PoC
PoC exploit for CVE-2024-28397 – Remote Code Execution in pyload-ng via js2py sandbox escape
CVE-2024-28397MEDIUM06 set 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-54309CRITICALsob ataque06 set 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RISCO
abrir
anteriorpágina 204 / 2.520próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.