Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.020exploits catalogados
35.276CVEs com exploração pública
24.695testados em laboratório
77.020 exploits
GitHub PoC1
Hoanle396/CVE-2021-44228-demo
CVE-2021-44228CRITICALsob ataqueransomware28 mai 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC3
CVE-2024-4956 : Nexus Repository Manager 3 poc exploit
CVE-2024-4956HIGH28 mai 2024
Nexus Repository 3 - Path Traversal
61RISCO
abrir
VulnCheck XDB
local
CVE-2024-0582HIGH28 mai 2024
Kernel: io_uring: page use-after-free vulnerability via buffer ring mmap
46RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-23108CRITICAL28 mai 2024
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware28 mai 2024
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC1
Microsoft Windows 'HTTP.sys' - Remote Code Execution
CVE-2015-1635CRITICALsob ataque28 mai 2024
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISCO
abrir
GitHub PoC5
POC iteration for CVE-2024-23108 which can use -l for list input
CVE-2024-23108CRITICAL28 mai 2024
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
85RISCO
abrir
GitHub PoC1
Goplush/CVE-2024-32002-git-rce
CVE-2024-32002CRITICAL28 mai 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
GitHub PoC1
The Country State City Dropdown CF7 WordPress plugin (versions up to 2.7.2) is vulnerable to SQL Injection via 'cnt' and 'sid' parameters. Insufficient escaping and lack of preparation in the SQL query allow unauthenticated attackers to append queries, potentially extracting sensitive database information.
CVE-2024-3495CRITICAL28 mai 2024
Country State City Dropdown CF7 <= 2.7.2 - Unauthenticated SQL Injection
68RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALsob ataqueransomware28 mai 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC2
Demo for CVE-2023-43654 - Remote Code Execution in PyTorch TorchServe
CVE-2023-43654CRITICAL28 mai 2024
TorchServe Server-Side Request Forgery
75RISCO
abrir
GitHub PoC8
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
CVE-2024-5084CRITICAL27 mai 2024
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
75RISCO
abrir
GitHub PoC1
TeamCity CVE-2023-42793 exploit written in Rust
CVE-2023-42793CRITICALsob ataqueransomware27 mai 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir
GitHub PoC
CVE-2019-10092: Limited Cross-Site Scripting via "Proxy Error" Page in Apache HTTP Server
CVE-2019-1009227 mai 2024
In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page
60RISCO
abrir
GitHub PoC
PoC CVE-2011-2523
CVE-2011-252327 mai 2024
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-2961HIGH27 mai 2024
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALsob ataqueransomware27 mai 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2024-21683HIGH27 mai 2024
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and
78RISCO
abrir
GitHub PoC
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.
CVE-2017-548727 mai 2024
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALsob ataque27 mai 2024
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC1
thinhap/CVE-2024-4956-PoC
CVE-2024-4956HIGH27 mai 2024
Nexus Repository 3 - Path Traversal
61RISCO
abrir
GitHub PoC
Apache Tomcat - Open Redirect
CVE-2018-1178427 mai 2024
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a r
60RISCO
abrir
GitHub PoC17
[CVE-2024-4956] Nexus Repository Manager 3 Unauthenticated Path Traversal Bulk Scanner
CVE-2024-4956HIGH26 mai 2024
Nexus Repository 3 - Path Traversal
61RISCO
abrir
GitHub PoC
sn130hk/CVE-2023-44487
CVE-2023-44487HIGHsob ataque26 mai 2024
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISCO
abrir
GitHub PoC
Un exploit con el que puedes aprovecharte de la vulnerabilidad (CVE-2024-23897)
CVE-2024-23897CRITICALsob ataqueransomware26 mai 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALsob ataqueransomware26 mai 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-4443CRITICAL26 mai 2024
Business Directory Plugin – Easy Listing Directories for WordPress <= 6.4.2 - Unauthenticated SQL Injection via listingfields Parameter
68RISCO
abrir
GitHub PoC1
Joomla! Core SQL Injection
CVE-2015-729726 mai 2024
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RISCO
abrir
GitHub PoC28
CVE-2025-8088-BUILDER
CVE-2025-8088HIGHsob ataqueransomware26 mai 2024
Path traversal vulnerability in WinRAR
93RISCO
abrir
GitHub PoC1
changedetection rce though ssti
CVE-2024-32651CRITICAL26 mai 2024
Server Side Template Injection in Jinja2 allows Remote Command Execution
85RISCO
abrir
anteriorpágina 394 / 2.568próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.