Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.313exploits catalogados
34.834CVEs com exploração pública
24.695testados em laboratório
76.066 exploits
VulnCheck XDB
initial-access
CVE-2024-2961HIGH02 fev 2025
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RISCO
abrir
GitHub PoC
rehan6658/CVE-2023-40028
CVE-2023-40028MEDIUM02 fev 2025
Arbitrary file read via symlinks in Ghost
45RISCO
abrir
GitHub PoC1
hashdr1ft/SOC274-Palo-Alto-Networks-PAN-OS-Command-Injection-Vulnerability-Exploitation-CVE-2024-3400
CVE-2024-3400CRITICALsob ataqueransomware02 fev 2025
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHsob ataqueransomware02 fev 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL02 fev 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware02 fev 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-3400CRITICALsob ataqueransomware02 fev 2025
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISCO
abrir
GitHub PoC2
CVE-2024-56898 - Broken access control vulnerability in GeoVision GV-ASManager web application with version v6.1.0.0 or less. This vulnerability allows low privilege users perform actions that they aren't authorized to, which can be leveraged to escalate privileges, create, modify or delete accounts.
CVE-2024-56898HIGH02 fev 2025
Broken access control vulnerability in Geovision GV-ASWeb with version v6.1.0.0 or less. This vulnerability allows low p
41RISCO
abrir
GitHub PoC3
CVE-2024-56902 - Information disclosure vulnerability in GeoVision GV-ASManager web application with the version v6.1.0.0 or less, which discloses account information, including cleartext password.
CVE-2024-56902HIGH02 fev 2025
Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which
46RISCO
abrir
GitHub PoC
CVE-2017-8869 - MediaCoder 0.8.48.5888 - Local Buffer Overflow (SEH)
CVE-2017-886902 fev 2025
Buffer overflow in MediaCoder 0.8.48.5888 allows remote attackers to execute arbitrary code via a crafted .m3u file.
43RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-26319CRITICAL02 fev 2025
FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.
75RISCO
abrir
GitHub PoC
User Profile Builder <= 3.11.7 - Unauthenticated Media Upload
CVE-2024-6366CRITICAL02 fev 2025
User Profile Builder < 3.11.8 - Unauthenticated Media Upload
68RISCO
abrir
GitHub PoC2
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
CVE-2024-10924CRITICAL02 fev 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir
GitHub PoC
dorattias/CVE-2025-26319
CVE-2025-26319CRITICAL02 fev 2025
FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.
75RISCO
abrir
GitHub PoC2
CVE-2024-56901 - A Cross-Site Request Forgery (CSRF) vulnerability in Geovision GV-ASManager web application with the version 6.1.1.0 or less that allows attackers to arbitrarily create Admin accounts via a crafted POST request.
CVE-2024-56901HIGH02 fev 2025
A Cross-Site Request Forgery (CSRF) vulnerability in Geovision GV-ASWeb application with the version 6.1.1.0 or less tha
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2014-370402 fev 2025
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISCO
abrir
GitHub PoC
This code is taken from "Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Add Admin User)" and was converted to Python 3 to suit the exercise in Academy for Module "Attacking Commoon Applications" and section "Attacking Drupal".
CVE-2014-370402 fev 2025
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISCO
abrir
GitHub PoC
This repository contains a Proof-of-Concept for the CVE-2021-41773. This CVE contains a LFI and RCE vulnerablity.
CVE-2021-41773HIGHsob ataqueransomware02 fev 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-023231 jan 2025
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISCO
abrir
GitHub PoC
asepsaepdin/CVE-2022-36804
CVE-2022-36804HIGHsob ataque30 jan 2025
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALsob ataqueransomware30 jan 2025
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-32315HIGHsob ataque30 jan 2025
Openfire administration console authentication bypass
100RISCO
abrir
GitHub PoC6
Proof of Concept for CVE-2022-45460
CVE-2022-45460CRITICAL30 jan 2025
Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C74311
48RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2022-36804HIGHsob ataque30 jan 2025
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALsob ataqueransomware30 jan 2025
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-33891HIGHsob ataque30 jan 2025
Apache Spark shell command injection vulnerability via Spark UI
100RISCO
abrir
Metasploit300
NetAlertX File Read Vulnerability
CVE-2024-48766HIGH30 jan 2025
NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and
48RISCO
abrir
GitHub PoC15
CVE-2024-8381: A SpiderMonkey Interpreter Type Confusion Bug.
CVE-2024-8381CRITICAL30 jan 2025
A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as t
48RISCO
abrir
Metasploit600
Unauthenticated RCE in NetAlertX
CVE-2024-46506CRITICAL30 jan 2025
NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because fun
75RISCO
abrir
GitHub PoC
asepsaepdin/CVE-2023-32315
CVE-2023-32315HIGHsob ataque30 jan 2025
Openfire administration console authentication bypass
100RISCO
abrir
anteriorpágina 306 / 2.536próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.