Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.008exploits catalogados
34.638CVEs com exploração pública
24.695testados em laboratório
75.902 exploits
GitHub PoC
Updated exploit script for the CVE-2021-43798
CVE-2021-43798HIGHsob ataque27 abr 2025
Grafana path traversal
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-4288927 abr 2025
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-8291HIGHsob ataque27 abr 2025
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion
100RISCO
abrir
GitHub PoC
shun1403/PIL-CVE-2017-8291-study
CVE-2017-8291HIGHsob ataque27 abr 2025
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion
100RISCO
abrir
GitHub PoC
shun1403/CVE-2017-8291
CVE-2017-8291HIGHsob ataque27 abr 2025
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion
100RISCO
abrir
GitHub PoC
WHS3기 가상화 취약한(CVE) Docker 환경 구성 과제
CVE-2025-1974CRITICAL27 abr 2025
ingress-nginx admission controller RCE escalation
85RISCO
abrir
GitHub PoC
CVE-2025-32433 Summary and Attack Overview
CVE-2025-32433CRITICALsob ataque27 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
GitHub PoC
Attacks a vulnerable WordPress site with the wp-automatic plugin. Inserts a new user called eviladmin directly into the database (INSERT INTO wp_users). Searches for the ID of the newly created user (cyclic SELECT). Promotes eviladmin to Administrator (INSERT INTO wp_usermeta).
CVE-2024-27956CRITICAL27 abr 2025
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISCO
abrir
GitHub PoC2
CVE-2022-3552 RCE with detailed exploitation steps
CVE-2022-3552HIGH27 abr 2025
Unrestricted Upload of File with Dangerous Type in boxbilling/boxbilling
53RISCO
abrir
GitHub PoC1
chhhd/CVE-2025-1974
CVE-2025-1974CRITICAL26 abr 2025
ingress-nginx admission controller RCE escalation
85RISCO
abrir
GitHub PoC2
CVE-2021-42287/CVE-2021-42278/OTHER Scanner & Exploiter.
CVE-2021-42287HIGHsob ataqueransomware26 abr 2025
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-2294CRITICAL26 abr 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISCO
abrir
GitHub PoC
ChoDeokCheol/CVE-2023-39361
CVE-2023-39361CRITICAL26 abr 2025
Unauthenticated SQL Injection in graph_view.php in Cacti
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-1389HIGHsob ataque26 abr 2025
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability i
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-32432CRITICALsob ataque26 abr 2025
Craft CMS Allows Remote Code Execution
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-39361CRITICAL26 abr 2025
Unauthenticated SQL Injection in graph_view.php in Cacti
85RISCO
abrir
GitHub PoC10
CraftCMS RCE Checker (CVE-2025-32432)
CVE-2025-32432CRITICALsob ataque26 abr 2025
Craft CMS Allows Remote Code Execution
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2021-41773HIGHsob ataqueransomware26 abr 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
romanedutov/CVE-2025-2294
CVE-2025-2294CRITICAL26 abr 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISCO
abrir
GitHub PoC
A PoC of CVE-2016-2098 I made for PentesterLab
CVE-2016-209825 abr 2025
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RISCO
abrir
GitHub PoC5
Proof-of-Concept (PoC) for CVE-2025-29306, a Remote Code Execution vulnerability in FoxCMS. This Python script scans single or multiple targets, executes commands, and reports vulnerable hosts.
CVE-2025-29306CRITICAL25 abr 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISCO
abrir
GitHub PoC2
Next.js middleware bypass exploit
CVE-2025-29927CRITICAL25 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
A PoC of CVE-2016-10033 I made for PentesterLab
CVE-2016-10033CRITICALsob ataque25 abr 2025
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-3102HIGH25 abr 2025
SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
78RISCO
abrir
GitHub PoC
WonderCMS v3.4.2 NSE Discovery Script
CVE-2023-41425MEDIUM25 abr 2025
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-24919HIGHsob ataqueransomware25 abr 2025
Information disclosure
100RISCO
abrir
GitHub PoC
CyprianAtsyor/CVE-2024-24919-Incident-Report.md
CVE-2024-24919HIGHsob ataqueransomware25 abr 2025
Information disclosure
100RISCO
abrir
GitHub PoC
K4Der11000/k4_cve-2023-41064
CVE-2023-41064HIGHsob ataque25 abr 2025
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1
76RISCO
abrir
GitHub PoC
A PoC of CVE-2018-0114 I made for PentesterLab
CVE-2018-011425 abr 2025
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-32433CRITICALsob ataque25 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
anteriorpágina 267 / 2.531próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.