Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.008exploits catalogados
34.638CVEs com exploração pública
24.695testados em laboratório
76.008 exploits
GitHub PoC1
eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Upload via set_image Task
CVE-2025-5058CRITICAL21 mai 2025
eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Upload via set_image()
48RISCO
abrir
GitHub PoC
RdBBB3/SHELL-POC-CVE-2022-46169
CVE-2022-46169CRITICALsob ataque21 mai 2025
Unauthenticated Command Injection
100RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2019-0708CRITICALsob ataqueransomware21 mai 2025
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC1
IndominusRexes/CVE-2025-4322-Exploit
CVE-2025-4322CRITICAL20 mai 2025
Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover
68RISCO
abrir
GitHub PoC
PoC for CVE-2025-47646 - WordPress PSW Front-end Login Registration Plugin ≤ 1.12 Unauthenticated Privilege Escalation
CVE-2025-47646CRITICAL20 mai 2025
WordPress PSW Front-end Login & Registration plugin <= 1.13 - Broken Authentication Vulnerability
68RISCO
abrir
GitHub PoC2
PoC and vulnerability report for CVE-2025-47827.
CVE-2025-47827MEDIUMsob ataque20 mai 2025
In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptograph
63RISCO
abrir
GitHub PoC
It was determined that malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. # It was determined that only certain operating systems and operating system versions were affected by this vulnerability.
CVE-2024-3094CRITICAL20 mai 2025
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC
CVE-2024-53677
CVE-2024-53677CRITICAL20 mai 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL20 mai 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir
GitHub PoC
HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion (LFI)
CVE-2025-1661CRITICAL20 mai 2025
HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion
75RISCO
abrir
GitHub PoC
The `swp_debug` parameter in `admin-post.php` allows remote attackers to include external files containing malicious PHP code, which are evaluated on the server. By supplying a crafted URL that hosts a reverse shell payload, an attacker can gain command execution.
CVE-2019-9978MEDIUMsob ataque19 mai 2025
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2021-38003HIGHsob ataque19 mai 2025
Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially explo
83RISCO
abrir
GitHub PoC1
Vulnerabilidad NTLM (CVE-2025-24054) explotada para robo de hashes
CVE-2025-24054MEDIUMsob ataque19 mai 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-24054MEDIUMsob ataque19 mai 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RISCO
abrir
GitHub PoC
Um script automatizado melhorando o exploit do cve-2011-0762 postado no exploit-db
CVE-2011-076219 mai 2025
The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a deni
60RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-43798HIGHsob ataque19 mai 2025
Grafana path traversal
100RISCO
abrir
GitHub PoC
Automated path traversal testing tool for Grafana plugin endpoints using curl and Bash.
CVE-2021-43798HIGHsob ataque19 mai 2025
Grafana path traversal
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-41713CRITICALsob ataqueransomware18 mai 2025
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could
100RISCO
abrir
GitHub PoC
Mitel MiCollab Authentication Bypass to Arbitrary File Read
CVE-2024-41713CRITICALsob ataqueransomware18 mai 2025
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could
100RISCO
abrir
Exploit-DB
Invision Community 5.0.6 - Remote Code Execution (RCE)
CVE-2025-47916CRITICALremotemultiple18 mai 2025
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The
85RISCO
abrir
Exploit-DB
CrushFTP 11.3.1 - Authentication Bypass
CVE-2025-31161CRITICALsob ataqueransomwareremotemultiple18 mai 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISCO
abrir
GitHub PoC4
Designed for Demonstration of Deep Exploitation.
CVE-2025-32756CRITICALsob ataque18 mai 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-32756CRITICALsob ataque18 mai 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RISCO
abrir
VulnCheck XDB
local
CVE-2024-44258HIGH18 mai 2025
This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18
41RISCO
abrir
Exploit-DB
Zyxel USG FLEX H series uOS 1.31 - Privilege Escalation
CVE-2025-1731HIGHlocalmultiple18 mai 2025
An incorrect permission assignment vulnerability in the PostgreSQL commands of the Zyxel USG FLEX H series uOS firmware
41RISCO
abrir
GitHub PoC
tdevworks/CVE-2020-0796-SMBGhost-Exploit-Demo
CVE-2020-0796CRITICALsob ataqueransomware17 mai 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC4
Eventin <= 4.0.26 - Missing Authorization to Unauthenticated Privilege Escalation
CVE-2025-47539CRITICAL17 mai 2025
WordPress Eventin plugin <= 4.0.26 - Privilege Escalation Vulnerability
75RISCO
abrir
GitHub PoC
Automation Exploit
CVE-2021-4034HIGHsob ataque17 mai 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC200
CVE-2025-31200 is a zero-day, zero-click RCE in iOS CoreAudio’s AudioConverterService, triggered by a malicious audio file via iMessage/SMS. Exploitation bypassed Blastdoor, enabled kernel escalation (CVE-2025-31201), and allowed token theft until patched in iOS 18.4.1 (Apr 16, 2025).
CVE-2025-31200CRITICALsob ataque17 mai 2025
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4
83RISCO
abrir
GitHub PoC
tdevworks/CVE-2020-1472-ZeroLogon-Demo-Detection-Mitigation
CVE-2020-1472MEDIUMsob ataqueransomware17 mai 2025
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
anteriorpágina 260 / 2.534próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.