Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
13.264 exploits
GitHub PoC4
Secure expression evaluator - Drop-in replacement for expr-eval without CVE-2025-12735 vulnerability
CVE-2025-12735CRITICAL27 nov 2025
CVE-2025-12735
48RISCO
abrir
GitHub PoC3
PoC RCE exploit for Nostromo nhttpd ≤ 1.9.6
CVE-2019-16278CRITICALsob ataque26 nov 2025
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISCO
abrir
GitHub PoC2
ExtremeUday/CVE-2025-2945-pgAdmin4-Authenticated-RCE-PoC-
CVE-2025-2945CRITICAL26 nov 2025
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
75RISCO
abrir
GitHub PoC
OS command injection vulnerability in Samba that received the maximum possible CVSS v3.1 score of 10.0
CVE-2025-10230CRITICAL26 nov 2025
Samba: command injection in wins server hook script
60RISCO
abrir
GitHub PoC
Path Traversal Apache HTTP Server 2.4.49/2.4.50
CVE-2021-41773HIGHsob ataqueransomware26 nov 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
yunus-a1i/veeam-cve-2023-27532-mock
CVE-2023-27532HIGHsob ataqueransomware26 nov 2025
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database
93RISCO
abrir
GitHub PoC
CVE-2025-6389
CVE-2025-6389CRITICAL26 nov 2025
Sneeit Framework <= 8.3 - Unauthenticated Remote Code Execution in sneeit_articles_pagination_callback
60RISCO
abrir
GitHub PoC2
Reproducing CVE-2024-29943 for Windows, based on https://github.com/bjrjk/CVE-2024-29943
CVE-2024-29943CRITICAL25 nov 2025
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds chec
53RISCO
abrir
GitHub PoC2
Tutorial of CVE-2022-37969 with focus on the methodology of Kernel exploitation, not CVE's internal causes
CVE-2022-37969HIGHsob ataque25 nov 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC31
aklnjakln/CVE-2025-6554
CVE-2025-6554HIGHsob ataque25 nov 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RISCO
abrir
GitHub PoC
Proof-of-Concept (PoC) for CVE-2025-62168 👾
CVE-2025-62168CRITICAL25 nov 2025
Squid vulnerable to information disclosure via authentication credential leakage in error handling
75RISCO
abrir
GitHub PoC
CVE-2025-61757
CVE-2025-61757CRITICALsob ataque25 nov 2025
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported vers
100RISCO
abrir
GitHub PoC
CVE-2025-41115
CVE-2025-41115CRITICAL24 nov 2025
Incorrect privilege assignment
53RISCO
abrir
GitHub PoC
Juniper JunOS J-Web PHP external variable modification (CVE-2023-36845) exploit.
CVE-2023-36845CRITICALsob ataque24 nov 2025
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISCO
abrir
GitHub PoC
CVE-2025-12762
CVE-2025-12762CRITICAL24 nov 2025
Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)
53RISCO
abrir
GitHub PoC1
A easy poc for CVE-2024-12084.
CVE-2024-12084CRITICAL24 nov 2025
Rsync: heap buffer overflow in rsync due to improper checksum length handling
70RISCO
abrir
GitHub PoC
IS8123/CVE-2025-54381
CVE-2025-54381CRITICAL24 nov 2025
BentoML is Vulnerable to an SSRF Attack Through File Upload Processing
53RISCO
abrir
GitHub PoC
CVE-2012-2122 MySQL Authentication Bypass Home Lab
CVE-2012-212224 nov 2025
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x befor
60RISCO
abrir
GitHub PoC2
Windows File Explorer Zero Click NTLMv2-SSP Hash Disclosure
CVE-2025-24054MEDIUMsob ataque23 nov 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RISCO
abrir
GitHub PoC
rashedhasan090/CVE-2025-5777
CVE-2025-5777CRITICALsob ataqueransomware23 nov 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
GitHub PoC
CVE-2025-11833 Checker
CVE-2025-11833CRITICAL23 nov 2025
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Log Disclosure
75RISCO
abrir
GitHub PoC1
This repository contains a full blue-team malware analysis of a real malicious DOCX exploiting CVE-2017-0199. The lab includes sandbox execution, network forensics, IOC extraction, MITRE ATT&CK mapping, dropped files review, and detection rules. Evidence screenshots are included inside the evidence folder for professional documentation.
CVE-2017-0199HIGHsob ataqueransomware23 nov 2025
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir
GitHub PoC1
CVE-2025-10230 PoC - Samba WINS Hook Command Injection
CVE-2025-10230CRITICAL23 nov 2025
Samba: command injection in wins server hook script
60RISCO
abrir
GitHub PoC
ranasen-rat/CVE-2025-11001
CVE-2025-11001HIGH22 nov 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RISCO
abrir
GitHub PoC
Custom Docker Image
CVE-2017-7494CRITICALsob ataqueransomware22 nov 2025
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISCO
abrir
GitHub PoC4
CVE-2025-26633 (CVSS 7.8) – Zero-day MMC .msc EvilTwin LPE actively exploited by Water Gamayun APT. PoC creates local admin via malicious MSC file on unpatched Windows 10/11/Server. Patched March 2025. Authorized testing only.
CVE-2025-26633HIGHsob ataqueransomware22 nov 2025
Microsoft Management Console Security Feature Bypass Vulnerability
83RISCO
abrir
GitHub PoC
POC
CVE-2025-5777CRITICALsob ataqueransomware22 nov 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
GitHub PoC7
CVE-2025-11001 (CVSS 7.0) – 7-Zip < 25.00 Directory Traversal → RCE via crafted ZIP with symlink. Allows arbitrary file write when extracted as Administrator. Fixed in 7-Zip 25.00 (July 2025).
CVE-2025-11001HIGH22 nov 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RISCO
abrir
GitHub PoC1
Proof‑of‑concept for CVE‑2024‑58258, a SugarCRM (<13.0.4 / <14.0.1) flaw where user input is parsed as LESS in /css/preview, allowing unauthenticated SSRF or local file access.
CVE-2024-58258HIGH21 nov 2025
SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can
46RISCO
abrir
GitHub PoC4
Oracle Identity Manager 远程代码执行漏洞CVE-2025-61757
CVE-2025-61757CRITICALsob ataque21 nov 2025
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported vers
100RISCO
abrir
anteriorpágina 106 / 443próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.