Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.008exploits catalogados
34.638CVEs com exploração pública
24.695testados em laboratório
76.008 exploits
GitHub PoC1
Repositorio de investigación de seguridad que contiene una Prueba de Concepto (PoC) para la vulnerabilidad CVE-2021-4034 (PwnKit) y utilidades de scripting para la demostración de escalada de privilegios y ejecución remota en entornos Linux.
CVE-2021-4034HIGHsob ataque05 jun 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC198
Proof of Concept for CVE-2025-32756 - A critical stack-based buffer overflow vulnerability affecting multiple Fortinet products.
CVE-2025-32756CRITICALsob ataque05 jun 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2025-32756CRITICALsob ataque05 jun 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RISCO
abrir
GitHub PoC
PoC for CVE-2024-42049
CVE-2024-42049CRITICAL05 jun 2025
TightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pipe via a network connection.
48RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALsob ataque05 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
GitHub PoC1
CyberQuestor-infosec/CVE-2022-46604-Responsive-File-Manager
CVE-2022-46604HIGH05 jun 2025
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanis
41RISCO
abrir
Exploit-DB
macOS LaunchDaemon iOS 17.2 - Privilege Escalation
CVE-2025-24085CRITICALsob ataquelocalmacos05 jun 2025
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, i
83RISCO
abrir
GitHub PoC
An exploit automation script that builds upon the work of Voidzone security.
CVE-2022-44268MEDIUM04 jun 2025
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISCO
abrir
GitHub PoC
MantisToboggan-git/CVE-2025-4632-POC
CVE-2025-4632CRITICALsob ataque04 jun 2025
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 2
98RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-4123HIGH04 jun 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISCO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHsob ataque04 jun 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-2539HIGH04 jun 2025
File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Read
56RISCO
abrir
VulnCheck XDB
infoleak
CVE-2019-20085HIGHsob ataque04 jun 2025
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RISCO
abrir
GitHub PoC
Superliverbun/cve-2021-3156-
CVE-2021-3156HIGHsob ataque04 jun 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC
A repository used for Hackthebox ServMon Machine
CVE-2019-20085HIGHsob ataque04 jun 2025
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RISCO
abrir
GitHub PoC
Authenticated Remote Command Execution - Webmin <= 1.910
CVE-2019-1284004 jun 2025
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RISCO
abrir
GitHub PoC32
CVE-2025-4123 - Grafana Tool
CVE-2025-4123HIGH04 jun 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISCO
abrir
GitHub PoC3
CVE-2025-49113 - Roundcube <= 1.6.10 Post-Auth RCE via PHP Object Deserialization
CVE-2025-49113CRITICALsob ataque04 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
GitHub PoC108
fearsoff-org/CVE-2025-49113
CVE-2025-49113CRITICALsob ataque04 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
GitHub PoC2
r007sec/CVE-2024-53677
CVE-2024-53677CRITICAL03 jun 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir
GitHub PoC1
A XZ backdoor vulnerability explained in details
CVE-2024-3094CRITICAL03 jun 2025
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC5
Detection for CVE-2025-49113
CVE-2025-49113CRITICALsob ataque03 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
GitHub PoC
Authenticated Remote Command Execution – pfSense <= 2.1.3
CVE-2014-468803 jun 2025
pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_
23RISCO
abrir
GitHub PoC
imbas007/CVE-2025-4123-template
CVE-2025-4123HIGH03 jun 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISCO
abrir
GitHub PoC
For CTF use only (the CVE-2019-7214 also resolves the host from /etc/hosts)
CVE-2019-721403 jun 2025
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker co
60RISCO
abrir
GitHub PoC3
pgAdmin Proof of Concept
CVE-2025-2945CRITICAL03 jun 2025
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-3102HIGH03 jun 2025
SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
78RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL03 jun 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-4123HIGH03 jun 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-27163MEDIUM03 jun 2025
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISCO
abrir
anteriorpágina 255 / 2.534próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.