Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
13.282 exploits
GitHub PoC
foregenix/CVE-2023-39143
CVE-2023-39143CRITICAL09 out 2025
PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete
85RISCO
abrir
GitHub PoC1
Reproduction and fix of the CVE-2025-29927 vulnerability.
CVE-2025-29927CRITICAL08 out 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
lastvocher/Hikvision-CVE-2017-7921-decryptor
CVE-2017-7921CRITICALsob ataque08 out 2025
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISCO
abrir
GitHub PoC1
Advanced PostgreSQL database enumeration tool exploiting CVE-2024-39309 in Parse Server - Comprehensive SQL injection exploitation for security research
CVE-2024-39309CRITICAL07 out 2025
ZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability
53RISCO
abrir
GitHub PoC
Authenticated API Key Exposure in Nagios Log Server 2024R1.3.1
CVE-2025-44823CRITICAL07 out 2025
Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagi
53RISCO
abrir
GitHub PoC
Remote Code Execution PoC for Apache 2.4.49
CVE-2021-41773HIGHsob ataqueransomware07 out 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC1
compiled poc binary
CVE-2024-30088HIGHsob ataqueransomware06 out 2025
Windows Kernel Elevation of Privilege Vulnerability
83RISCO
abrir
GitHub PoC
hybinn/CVE-2024-23897
CVE-2024-23897CRITICALsob ataqueransomware06 out 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
GitHub PoC
exploit for CVE-2018-16763
CVE-2018-1676305 out 2025
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir
GitHub PoC
WP-CVE-2025-6934 | Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation
CVE-2025-6934CRITICAL05 out 2025
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RISCO
abrir
GitHub PoC
shoucheng3/apache__struts_CVE-2020-17530_2-5-25
CVE-2020-17530CRITICALsob ataque05 out 2025
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISCO
abrir
GitHub PoC
Explicação e demonstração da vulnerabilidade ZeroLogon (CVE-2020-1472)
CVE-2020-1472MEDIUMsob ataqueransomware04 out 2025
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC2
An Python Exp For "GeoServer"
CVE-2024-36401CRITICALsob ataque04 out 2025
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir
GitHub PoC12
Arbitrary Function Call Exploit using the ThrottleStop driver
CVE-2025-7771HIGH03 out 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RISCO
abrir
GitHub PoC13
watchtowrlabs/watchTowr-vs-WatchGuard-CVE-2025-9242
CVE-2025-9242CRITICALsob ataque01 out 2025
WatchGuard Firebox iked Out of Bounds Write Vulnerability
100RISCO
abrir
GitHub PoC
CS50 Cybersecurity final project — Palo Alto OAuth token breach (CVE-2024-3400)
CVE-2024-3400CRITICALsob ataqueransomware01 out 2025
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISCO
abrir
GitHub PoC
tno01/cve-2019-3396
CVE-2019-3396CRITICALsob ataqueransomware30 set 2025
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISCO
abrir
GitHub PoC1
A Rust implementation of the POC for CVE-2017-7269, targeting the WebDAV service in Microsoft Internet Information Services (IIS) 6.0.
CVE-2017-7269CRITICALsob ataque30 set 2025
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISCO
abrir
GitHub PoC1
Detection for CVE-2025-41244
CVE-2025-41244HIGHsob ataque30 set 2025
VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)
71RISCO
abrir
GitHub PoC
Tnot123/cve-2017-9822
CVE-2017-9822HIGHsob ataqueransomware30 set 2025
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code e
100RISCO
abrir
GitHub PoC3
ticofookfook/CVE-2025-43300
CVE-2025-43300CRITICALsob ataque30 set 2025
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1
83RISCO
abrir
GitHub PoC1
This is POC for IOS 0click CVE-2025-43300
CVE-2025-43300CRITICALsob ataque30 set 2025
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1
83RISCO
abrir
GitHub PoC
A Python exploit for CVE-2025-32463, a critical local privilege escalation vulnerability in the Sudo binary on Linux systems. This flaw allows local users to obtain root access by exploiting the --chroot option, which incorrectly uses /etc/nsswitch.conf from a user-controlled directory.
CVE-2025-32463CRITICALsob ataque30 set 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC
CVE-2024-47051
CVE-2024-47051CRITICAL29 set 2025
Remote Code Execution & File Deletion in Asset Uploads
48RISCO
abrir
GitHub PoC
victormbogu1/LetsDefend-SOC342-CVE-2025-53770-SharePoint-ToolShell-Auth-Bypass-andRCE-EventID-320
CVE-2025-53770CRITICALsob ataqueransomware29 set 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
Log4Shell (CVE-2021-44228) PoC
CVE-2021-44228CRITICALsob ataqueransomware29 set 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
kuyrathdaro/cve-2025-29927
CVE-2025-29927CRITICAL28 set 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
ethan-repo-lab4b6/CVE-2022-36537
CVE-2022-36537HIGHsob ataqueransomware28 set 2025
ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafte
100RISCO
abrir
GitHub PoC
0xDTC/CrushFTP-auth-bypass-CVE-2025-31161
CVE-2025-31161CRITICALsob ataqueransomware27 set 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISCO
abrir
GitHub PoC
CVE-2025-10035_GoAnywhere Get RCE
CVE-2025-10035CRITICALsob ataqueransomware27 set 2025
Deserialization Vulnerability in GoAnywhere MFT's License Servlet
100RISCO
abrir
anteriorpágina 114 / 443próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.