Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.652exploits catalogados
34.545CVEs com exploração pública
24.695testados em laboratório
75.652 exploits
GitHub PoC1
CVE-2025-23266 – Fully Weaponized NVIDIA Container Toolkit Exploit
CVE-2025-23266CRITICAL02 set 2025
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, wher
48RISCO
abrir
GitHub PoC2
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation
CVE-2025-6934CRITICAL02 set 2025
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-34300CRITICAL01 set 2025
Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-18935CRITICALsob ataqueransomware01 set 2025
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-3515HIGH01 set 2025
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.9 - Unauthenticated Arbitrary File Upload via Insufficient Blacklist Checks
56RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-57819CRITICALsob ataque01 set 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL01 set 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir
GitHub PoC1
HTML cache poisoning through unsafe reflections
CVE-2025-53693CRITICAL01 set 2025
HTML Cache Poisoning through Unsafe Reflections
53RISCO
abrir
GitHub PoC1
Sawtooth Lighthouse Studio存在模板注入漏洞CVE-2025-34300
CVE-2025-34300CRITICAL01 set 2025
Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE
75RISCO
abrir
GitHub PoC6
FreePBX SQL Injection Exploit
CVE-2025-57819CRITICALsob ataque01 set 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir
GitHub PoC1
a proof of concept of CVE-2024-53677
CVE-2024-53677CRITICAL01 set 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-9841CRITICALsob ataque01 set 2025
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-11317CRITICALsob ataque01 set 2025
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-1920701 set 2025
The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to exe
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-11357CRITICALsob ataqueransomware01 set 2025
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which a
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHsob ataqueransomware31 ago 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-48307CRITICAL31 ago 2025
JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalD
75RISCO
abrir
GitHub PoC
Detection for CVE-2025-4427 and CVE-2025-4428
CVE-2025-4427MEDIUMsob ataque31 ago 2025
Authentication Bypass
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALsob ataque31 ago 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
VulnCheck XDB
local
CVE-2025-7771HIGH31 ago 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RISCO
abrir
VulnCheck XDB
client-side
CVE-2015-925131 ago 2025
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed wi
28RISCO
abrir
GitHub PoC2
Detection for CVE-2025-7775
CVE-2025-7775CRITICALsob ataque31 ago 2025
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service
83RISCO
abrir
GitHub PoC20
Apache (CVE-2025-24813) GOExploiter Checker & Exploiter very Fast
CVE-2025-24813CRITICALsob ataque31 ago 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC
It shook the world in 2017 and has evolved into today’s CVE‑2025‑2776. Microsoft still relies on SMBv1, this article will explain how attackers have tweaked the chain from a simple DLL to a full reverse‑shell stack, and what that means for the defenders.
CVE-2025-2776CRITICALsob ataque31 ago 2025
SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection
100RISCO
abrir
GitHub PoC18
CVE-2025-7771: Arbitrary physical memory and I/O port read/write via ThrottleStop driver
CVE-2025-7771HIGH31 ago 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RISCO
abrir
GitHub PoC
CTF_WRITEUPS/TryHackMe /CVE-2021-41773/
CVE-2021-41773HIGHsob ataqueransomware31 ago 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC1
jeecg-boot getDictItemsByTable接口存在SQL注入漏洞
CVE-2024-48307CRITICAL31 ago 2025
JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalD
75RISCO
abrir
GitHub PoC
tranphuc2005/CVE-2019-3396
CVE-2019-3396CRITICALsob ataqueransomware30 ago 2025
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISCO
abrir
GitHub PoC6
Detects vulnerable FreePBX versions affected by CVE-2025-57819.
CVE-2025-57819CRITICALsob ataque30 ago 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-9841CRITICALsob ataque30 ago 2025
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISCO
abrir
anteriorpágina 208 / 2.522próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.