Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.313exploits catalogados
34.834CVEs com exploração pública
24.695testados em laboratório
76.008 exploits
Metasploit600
Pandora FMS authenticated command injection leading to RCE via chromium_path or phantomjs_bin
CVE-2024-12971HIGH17 mar 2025
QuickShell Authenticated Command Injection
48RISCO
abrir
GitHub PoC3
Nuclei Template CVE-2025–24813
CVE-2025-24813CRITICALsob ataque17 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-4587817 mar 2025
GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not
50RISCO
abrir
GitHub PoC
KillReal01/CVE-2023-4911
CVE-2023-4911HIGHsob ataque17 mar 2025
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISCO
abrir
GitHub PoC
regantemudo/CVE-2024-25641-Exploit-for-Cacti-1.2.26
CVE-2024-25641CRITICAL17 mar 2025
Cacti RCE vulnerability when importing packages
85RISCO
abrir
GitHub PoC1
orilevy8/cve-2023-0386
CVE-2023-0386HIGHsob ataque17 mar 2025
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISCO
abrir
GitHub PoC405
CVE-2025-24071: NTLM Hash Leak via RAR/ZIP Extraction and .library-ms File
CVE-2025-24071MEDIUM16 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
GitHub PoC
DavidBr27/CVE-2013-3900-Remediation-Script
CVE-2013-3900MEDIUMsob ataque16 mar 2025
WinVerifyTrust Signature Validation Vulnerability
75RISCO
abrir
GitHub PoC
CVE-2024-9047, wfu_file_downloader.php
CVE-2024-9047CRITICAL16 mar 2025
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
85RISCO
abrir
GitHub PoC
RCE, Citirx ADC and Gateway Directory Traversal
CVE-2019-19781CRITICALsob ataqueransomware16 mar 2025
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
GitHub PoC2
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.
CVE-2023-30258CRITICAL16 mar 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-30258CRITICAL16 mar 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISCO
abrir
VulnCheck XDB
client-side
CVE-2024-7014HIGH16 mar 2025
Improper multimedia file attachment validation in Telegram for Android app
41RISCO
abrir
GitHub PoC16
CVE-2025-24813利用工具
CVE-2025-24813CRITICALsob ataque16 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2019-19781CRITICALsob ataqueransomware16 mar 2025
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-24071MEDIUM16 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALsob ataque16 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC47
一個測試CVE-2024-4577和CVE-2024-8926的安全滲透工具
CVE-2024-4577CRITICALsob ataqueransomware15 mar 2025
Argument Injection in PHP-CGI
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALsob ataqueransomware15 mar 2025
Argument Injection in PHP-CGI
100RISCO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHsob ataque15 mar 2025
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC2
One-Click-Root program based on CVE-2016-5195, that works on the old 'PlayStation Certified' android devices
CVE-2016-5195HIGHsob ataque15 mar 2025
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC
ishwardeepp/CVE-2025-22604-Cacti-RCE
CVE-2025-22604CRITICAL15 mar 2025
Cacti has Authenticated RCE via multi-line SNMP responses
48RISCO
abrir
GitHub PoC2
PoC - OpenSSL NPN Buffer Overread
CVE-2024-5535CRITICAL15 mar 2025
SSL_select_next_proto buffer overread
48RISCO
abrir
GitHub PoC2
CVE-2024-51788 - WordPress The Novel Design Store Directory plugin <= 4.3.0 - Unauthenticated Arbitrary File Upload Vulnerability
CVE-2024-51788CRITICAL15 mar 2025
WordPress The Novel Design Store Directory plugin <= 4.3.0 - Arbitrary File Upload vulnerability
48RISCO
abrir
GitHub PoC
Pei4AN/CVE-2025-28915
CVE-2025-28915CRITICAL14 mar 2025
WordPress ThemeEgg ToolKit plugin <= 1.2.9 - Arbitrary File Upload vulnerability
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALsob ataque14 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC11
cve-2025-24813验证脚本
CVE-2025-24813CRITICALsob ataque14 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC196
his repository contains an automated Proof of Concept (PoC) script for exploiting **CVE-2025-24813**, a Remote Code Execution (RCE) vulnerability in Apache Tomcat. The vulnerability allows an attacker to upload a malicious serialized payload to the server, leading to arbitrary code execution via deserialization when specific conditions are met.
CVE-2025-24813CRITICALsob ataque14 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC3
CVE-2025-24813_POC
CVE-2025-24813CRITICALsob ataque14 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC1
Security Researcher
CVE-2025-24813CRITICALsob ataque14 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
anteriorpágina 295 / 2.534próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.