Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.496exploits catalogados
34.964CVEs com exploração pública
24.695testados em laboratório
76.107 exploits
GitHub PoC
redspy-sec/CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware16 dez 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-1272516 dez 2024
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISCO
abrir
GitHub PoC
DS.DownloadList <= 1.3 - Unauthenticated PHP Object Injection
CVE-2024-50507CRITICAL16 dez 2024
WordPress DS.DownloadList plugin <= 1.3 - PHP Object Injection vulnerability
48RISCO
abrir
GitHub PoC21
LLfam/CVE-2024-1086
CVE-2024-1086HIGHsob ataqueransomware16 dez 2024
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISCO
abrir
GitHub PoC14
A short scraper looking for a POC of CVE-2024-49112
CVE-2024-49112CRITICAL16 dez 2024
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
70RISCO
abrir
Metasploit600
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) unauthenticated Remote Code Execution
CVE-2025-1094HIGH16 dez 2024
PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation
78RISCO
abrir
Metasploit600
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) unauthenticated Remote Code Execution
CVE-2024-12356CRITICALsob ataque16 dez 2024
Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA)
95RISCO
abrir
VulnCheck XDB
local
CVE-2024-0582HIGH15 dez 2024
Kernel: io_uring: page use-after-free vulnerability via buffer ring mmap
46RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-11972CRITICAL15 dez 2024
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
75RISCO
abrir
VulnCheck XDB
client-side
CVE-2024-46982HIGH14 dez 2024
Cache Poisoning in next.js
53RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-43798HIGHsob ataque14 dez 2024
Grafana path traversal
100RISCO
abrir
GitHub PoC4
Automated Exploit Tool for Grafana CVE-2021-43798: Scanning common files that contain juicy informations and extracting SSH keys from compromised users.
CVE-2021-43798HIGHsob ataque14 dez 2024
Grafana path traversal
100RISCO
abrir
GitHub PoC
sudlit/CVE-2023-40028
CVE-2023-40028MEDIUM13 dez 2024
Arbitrary file read via symlinks in Ghost
45RISCO
abrir
GitHub PoC
tlavi00/CVE-2018-7750
CVE-2018-775013 dez 2024
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x
28RISCO
abrir
GitHub PoC
CVE to CTF FP
CVE-2022-22963CRITICALsob ataque13 dez 2024
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir
GitHub PoC8
CVE-2024-55875 | GHSA-7mj5-hjjj-8rgw | http4k first CVE
CVE-2024-55875CRITICAL13 dez 2024
http4k has a potential XXE (XML External Entity Injection) vulnerability
48RISCO
abrir
GitHub PoC
Super Backup & Clone - Migrate for WordPress <= 2.3.3 - Unauthenticated Arbitrary File Upload
CVE-2024-9290CRITICAL13 dez 2024
Super Backup & Clone - Migrate for WordPress <= 2.3.3 - Unauthenticated Arbitrary File Upload
48RISCO
abrir
GitHub PoC
Improved version of PikaChu CVE
CVE-2017-12617HIGHsob ataque13 dez 2024
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-12617HIGHsob ataque13 dez 2024
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISCO
abrir
Metasploit600
InvoiceShelf unauthenticated PHP Deserialization Vulnerability
CVE-2024-55556CRITICAL13 dez 2024
A vulnerability in Crater Invoice allows an unauthenticated attacker with knowledge of the APP_KEY to achieve remote com
55RISCO
abrir
Metasploit600
Invoice Ninja unauthenticated PHP Deserialization Vulnerability
CVE-2024-55555HIGH13 dez 2024
Invoice Ninja before 5.10.43 allows remote code execution from a pre-authenticated route when an attacker knows the APP_
36RISCO
abrir
GitHub PoC4
666asd/CVE-2024-23653
CVE-2024-23653CRITICAL13 dez 2024
BuildKit interactive containers API does not validate entitlements check
48RISCO
abrir
GitHub PoC96
A critical vulnerability, CVE-2024-53677, has been identified in the popular Apache Struts framework, potentially allowing attackers to execute arbitrary code remotely. This vulnerability arises from flaws in the file upload logic, which can be exploited to perform path traversal and malicious file uploads.
CVE-2024-53677CRITICAL13 dez 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir
GitHub PoC9
s2-067(CVE-2024-53677)
CVE-2024-53677CRITICAL12 dez 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir
GitHub PoC4
exploit CVE-2024-38475(mod_rewrite weakness with filesystem path matching)
CVE-2024-38475CRITICALsob ataque12 dez 2024
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
100RISCO
abrir
GitHub PoC13
CVE-2023-40028 affects Ghost, an open source content management system, where versions prior to 5.59.1 allow authenticated users to upload files that are symlinks. This can be exploited to perform an arbitrary file read of any file on the host operating system.
CVE-2023-40028MEDIUM12 dez 2024
Arbitrary file read via symlinks in Ghost
45RISCO
abrir
GitHub PoC
Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
CVE-2024-10124CRITICAL12 dez 2024
Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
60RISCO
abrir
GitHub PoC
writeup cve-2024-42327
CVE-2024-42327CRITICAL12 dez 2024
SQL injection in user.get API
70RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-38475CRITICALsob ataque12 dez 2024
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-50623CRITICALsob ataqueransomware11 dez 2024
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file up
100RISCO
abrir
anteriorpágina 319 / 2.537próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.