Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.313exploits catalogados
34.834CVEs com exploração pública
24.695testados em laboratório
76.107 exploits
Metasploit600
Cacti Graph Template authenticated RCE versions prior to 1.2.29
CVE-2025-24367HIGH27 jan 2025
Cacti allows Arbitrary File Creation leading to RCE
48RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-2961HIGH27 jan 2025
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RISCO
abrir
GitHub PoC290
针对JWT渗透开发的漏洞验证/密钥爆破工具,针对CVE-2015-9235/空白密钥/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ,也可使用字典/字符枚举(包括JJWT)的方式进行爆破(JWT Crack)
CVE-2018-011427 jan 2025
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISCO
abrir
GitHub PoC1
7-Zip Mark-of-the-Web绕过漏洞PoC(CVE-2025-0411)
CVE-2025-0411HIGHsob ataque27 jan 2025
7-Zip Mark-of-the-Web Bypass Vulnerability
83RISCO
abrir
GitHub PoC77
watchtowrlabs/fortios-auth-bypass-poc-CVE-2024-55591
CVE-2024-55591CRITICALsob ataqueransomware27 jan 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISCO
abrir
GitHub PoC
CVE-2021-43798 working exploit
CVE-2021-43798HIGHsob ataque26 jan 2025
Grafana path traversal
100RISCO
abrir
GitHub PoC1
CVE-2016-2555 Exploit
CVE-2016-255526 jan 2025
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbi
60RISCO
abrir
GitHub PoC
Repository for internship test task.
CVE-2024-25600CRITICAL26 jan 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-43798HIGHsob ataque26 jan 2025
Grafana path traversal
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-55591CRITICALsob ataqueransomware26 jan 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL26 jan 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir
GitHub PoC4
Exploit for WordPress File Upload Plugin - All versions up to 4.24.11 are vulnerable.
CVE-2024-9047CRITICAL25 jan 2025
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-9047CRITICAL25 jan 2025
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-55591CRITICALsob ataqueransomware24 jan 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISCO
abrir
GitHub PoC
CVE-2017-7921 exploit. Allows admin password retrieval and automatic snapshot download.
CVE-2017-7921CRITICALsob ataque24 jan 2025
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISCO
abrir
GitHub PoC
This repository contains informaion about the Fortigate firewall vulnerability (CVE-2022-40684) and affected data that were publicly disclosed by the Belsen Group. This information is being shared for security research and defensive purposes to help organizations identify if they were impacted.
CVE-2022-40684CRITICALsob ataqueransomware24 jan 2025
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-4220HIGH24 jan 2025
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir
VulnCheck XDB
infoleak
CVE-2017-7921CRITICALsob ataque24 jan 2025
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISCO
abrir
GitHub PoC1
Exploit for CVE-2023-4220
CVE-2023-4220HIGH24 jan 2025
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir
GitHub PoC1
Proof of Concept for CVE-2024-45337 against Gitea and Forgejo
CVE-2024-45337CRITICAL24 jan 2025
Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
48RISCO
abrir
GitHub PoC8
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS and FortiProxy may allow a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
CVE-2024-55591CRITICALsob ataqueransomware24 jan 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISCO
abrir
GitHub PoC1
CVE-2024-3673 Exploit: Local File Inclusion in Web Directory Free WordPress Plugin ( before 1.7.3 )
CVE-2024-3673CRITICAL24 jan 2025
Web Directory Free < 1.7.3 - Unauthenticated LFI
63RISCO
abrir
GitHub PoC
CVE-2024-38077-POC
CVE-2024-38077CRITICAL23 jan 2025
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC1
Course Booking System <= 6.0.5 - Unauthenticated SQL Injection
CVE-2025-22785CRITICAL23 jan 2025
WordPress Course Booking System plugin <= 6.0.6 - SQL Injection vulnerability
63RISCO
abrir
GitHub PoC2
ExploitDB CVE-2024-50379 a vulnerability that enables attackers to upload a JSP shell to a vulnerable server and execute commands remotely. The exploit is especially effective when the /uploads directory is either unprotected or missing on the target server.
CVE-2024-50379CRITICAL23 jan 2025
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RISCO
abrir
GitHub PoC1
XalfiE/Fortigate-Belsen-Leak-Dump-CVE-2022-40684-
CVE-2022-40684CRITICALsob ataqueransomware23 jan 2025
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2024-46982HIGH23 jan 2025
Cache Poisoning in next.js
53RISCO
abrir
GitHub PoC
备份的CVE
CVE-2024-6460CRITICAL22 jan 2025
Grow by Tradedoubler <= 2.0.21 - Unauthenticated LFI
63RISCO
abrir
GitHub PoC155
This repository contains POC scenarios as part of CVE-2025-0411 MotW bypass.
CVE-2025-0411HIGHsob ataque22 jan 2025
7-Zip Mark-of-the-Web Bypass Vulnerability
83RISCO
abrir
GitHub PoC
In this project, I exploited the CVE-2024-27198-RCE vulnerability to perform a remote code execution (RCE) attack on a vulnerable TeamCity server.
CVE-2024-27198CRITICALsob ataqueransomware22 jan 2025
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir
anteriorpágina 309 / 2.537próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.