Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.107exploits catalogados
34.679CVEs com exploração pública
24.695testados em laboratório
75.902 exploits
Exploit-DB
OpenPanel 0.3.4 - OS Command Injection
CVE-2024-53584CRITICALwebappsmultiple14 abr 2025
OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter.
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALsob ataqueransomware14 abr 2025
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir
GitHub PoC
jakehomb/cve-2023-42793
CVE-2023-42793CRITICALsob ataqueransomware14 abr 2025
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir
GitHub PoC
The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes it possible for attackers with contributor level access and above to upload malicious files that can be used to obtain remote code execution,
CVE-2021-42362HIGH14 abr 2025
WordPress Popular Posts <= 5.3.2 Authenticated Arbitrary File Upload
78RISCO
abrir
GitHub PoC
Kiểm thử xâm nhập
CVE-2021-44228CRITICALsob ataqueransomware14 abr 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
pulentoski/Explotacion-CVE-2023-32315-Openfire
CVE-2023-32315HIGHsob ataque14 abr 2025
Openfire administration console authentication bypass
100RISCO
abrir
Exploit-DB
GestioIP 3.5.7 - Remote Command Execution (RCE)
CVE-2024-48760CRITICALremotemultiple14 abr 2025
An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacke
75RISCO
abrir
GitHub PoC
AsierEgana/cve-2021-4034
CVE-2021-4034HIGHsob ataque14 abr 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
Kiểm thử xâm nhập
CVE-2021-41773HIGHsob ataqueransomware14 abr 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
PoC for CVE-2023-27350
CVE-2023-27350CRITICALsob ataqueransomware14 abr 2025
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir
Metasploit600
Craft CMS Image Transform Preauth RCE (CVE-2025-32432)
CVE-2025-32432CRITICALsob ataque14 abr 2025
Craft CMS Allows Remote Code Execution
100RISCO
abrir
GitHub PoC12
Exploit for CVE-2025-29927 (Next.js) - Authorization Bypass
CVE-2025-29927CRITICAL14 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
Exploit-DB
OpenPanel 0.3.4 - Directory Traversal
CVE-2024-53537CRITICALwebappsmultiple14 abr 2025
An issue in OpenPanel v0.3.4 to v0.2.1 allows attackers to execute a directory traversal in File Actions of File Manager
48RISCO
abrir
Exploit-DB
OpenPanel Copy and View functions in the File Manager 0.3.4 - Directory Traversal
CVE-2024-53582HIGHwebappsmultiple14 abr 2025
An issue found in the Copy and View functions in the File Manager component of OpenPanel v0.3.4 allows attackers to exec
41RISCO
abrir
Exploit-DB
SilverStripe 5.3.8 - Stored Cross Site Scripting (XSS) (Authenticated)
CVE-2024-47605MEDIUMwebappsmultiple14 abr 2025
Cross-site Scripting via insert media remote file oembed in silverstripe-asset-admin
33RISCO
abrir
GitHub PoC
CVE-2024-4367
CVE-2024-4367MEDIUM14 abr 2025
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir
Exploit-DB
GestioIP 3.5.7 - Cross-Site Request Forgery (CSRF)
CVE-2024-50858HIGHremotemultiple14 abr 2025
Multiple endpoints in GestioIP v3.5.7 are vulnerable to Cross-Site Request Forgery (CSRF). An attacker can execute actio
41RISCO
abrir
Exploit-DB
GestioIP 3.5.7 - Reflected Cross-Site Scripting (Reflected XSS)
CVE-2024-50859MEDIUMremotemultiple14 abr 2025
The ip_import_acl_csv request in GestioIP v3.5.7 is vulnerable to Reflected XSS. When a user uploads an improperly forma
33RISCO
abrir
Exploit-DB
GestioIP 3.5.7 - Stored Cross-Site Scripting (Stored XSS)
CVE-2024-50861MEDIUMremotemultiple14 abr 2025
The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious cod
33RISCO
abrir
Exploit-DB
Pimcore 11.4.2 - Stored cross site scripting
CVE-2024-11954MEDIUMwebappsmultiple14 abr 2025
Pimcore Search Document cross site scripting
33RISCO
abrir
Exploit-DB
Pimcore customer-data-framework 4.2.0 - SQL injection
CVE-2024-11956MEDIUMwebappsmultiple14 abr 2025
Pimcore customer-data-framework list sql injection
33RISCO
abrir
GitHub PoC
The goal of this project was to conduct a security audit of a blog recently launched by Ackme Support Incorporated, identifying any critical vulnerabilities before the site goes public. The task involved finding a way to remotely execute code and gain access to the target system.
CVE-2018-1676313 abr 2025
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir
GitHub PoC
Este repositorio muestra cómo explotar la vulnerabilidad CVE-2021-4034.
CVE-2021-4034HIGHsob ataque13 abr 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
spyata123/CVE-2023-3128
CVE-2023-3128CRITICAL13 abr 2025
Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique a
48RISCO
abrir
GitHub PoC
ikerSandoval003/CVE-2021-4034
CVE-2021-4034HIGHsob ataque13 abr 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
Exploit de la vulneravilidad CVE-2021-4034
CVE-2021-4034HIGHsob ataque13 abr 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
nagorealbisu/CVE-2021-4034
CVE-2021-4034HIGHsob ataque13 abr 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataque13 abr 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL13 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataque13 abr 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
anteriorpágina 275 / 2.531próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.