Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.496exploits catalogados
34.964CVEs com exploração pública
24.695testados em laboratório
76.107 exploits
VulnCheck XDB
initial-access
CVE-2024-56145CRITICALsob ataque20 dez 2024
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-27956CRITICAL20 dez 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISCO
abrir
GitHub PoC
Import Export For WooCommerce <= 1.5 - Authenticated (Subscriber+) Arbitrary File Upload
CVE-2024-54262CRITICAL19 dez 2024
WordPress Import Export For WooCommerce plugin <= 1.6.2 - Arbitrary File Upload vulnerability
48RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-12025HIGH19 dez 2024
Collapsing Categories <= 3.0.8 - Unauthenticated SQL Injection
56RISCO
abrir
Metasploit600
Craft CMS Twig Template Injection RCE via FTP Templates Path
CVE-2024-56145CRITICALsob ataque19 dez 2024
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALsob ataqueransomware19 dez 2024
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
GitHub PoC
Zita Site Builder <= 1.0.2 - Missing Authorization to Arbitrary Plugin Installation
CVE-2024-54369CRITICAL19 dez 2024
WordPress Zita Site Builder plugin <= 1.0.2 - Arbitrary Plugin Installation and Activation vulnerability
48RISCO
abrir
GitHub PoC3
test code for cve-2024-6387
CVE-2024-6387HIGH19 dez 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir
GitHub PoC1
yiliufeng168/CVE-2024-50379-POC
CVE-2024-50379CRITICAL19 dez 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RISCO
abrir
GitHub PoC1
webmin or minisever RCE
CVE-2019-15107CRITICALsob ataqueransomware19 dez 2024
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
Metasploit600
Windows Cloud File Mini Filer Driver Heap Overflow
CVE-2024-30085HIGH19 dez 2024
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC
CVE-2023-4966-exploit
CVE-2023-4966CRITICALsob ataqueransomware18 dez 2024
Unauthenticated sensitive information disclosure
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL18 dez 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir
VulnCheck XDB
initial-access
CVE-2009-226518 dez 2024
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL18 dez 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir
GitHub PoC1
Adobe ColdFusion 8 - Remote Command Execution (RCE)
CVE-2009-226518 dez 2024
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RISCO
abrir
GitHub PoC2
dustblessnotdust/CVE-2024-53677-S2-067-thread
CVE-2024-53677CRITICAL18 dez 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir
GitHub PoC4
v3153/CVE-2024-50379-POC
CVE-2024-50379CRITICAL18 dez 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RISCO
abrir
GitHub PoC3
A Docker-based environment to reproduce the CVE-2024-53677 vulnerability in Apache Struts 2.
CVE-2024-53677CRITICAL17 dez 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir
GitHub PoC3
yangyanglo/CVE-2024-53677
CVE-2024-53677CRITICAL17 dez 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir
GitHub PoC6
Proof of concept (POC) for CVE-2024-45337
CVE-2024-45337CRITICAL17 dez 2024
Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
48RISCO
abrir
GitHub PoC1
An example project that showcases golang code vulnerable to CVE-2024-45337
CVE-2024-45337CRITICAL17 dez 2024
Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL17 dez 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir
Metasploit600
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) unauthenticated Remote Code Execution
CVE-2024-12356CRITICALsob ataque16 dez 2024
Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA)
95RISCO
abrir
VulnCheck XDB
local
CVE-2024-49039HIGHsob ataqueransomware16 dez 2024
Windows Task Scheduler Elevation of Privilege Vulnerability
76RISCO
abrir
Metasploit600
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) unauthenticated Remote Code Execution
CVE-2025-1094HIGH16 dez 2024
PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation
78RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHsob ataqueransomware16 dez 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC1
The EXP/POC of CVE-2019-12725
CVE-2019-1272516 dez 2024
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISCO
abrir
GitHub PoC
redspy-sec/CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware16 dez 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-1272516 dez 2024
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISCO
abrir
anteriorpágina 318 / 2.537próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.