Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
13.307 exploits
GitHub PoC1
Joelp03/CVE-2025-49113
CVE-2025-49113CRITICALsob ataque18 jul 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
GitHub PoC32
POC of CVE-2025-7783
CVE-2025-7783CRITICAL18 jul 2025
Usage of unsafe random function in form-data for choosing boundary
48RISCO
abrir
GitHub PoC1
Zenar CMS 9.3 suffers from an ​​unrestricted file upload vulnerability​​ in its file management module, allowing authenticated attackers (with minimal privileges) to upload arbitrary files, including malicious PHP scripts, to the web server.
CVE-2022-44136CRITICAL18 jul 2025
Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).
48RISCO
abrir
GitHub PoC8
Exploit para explotar la vulnerabilidad CVE-2025-32463
CVE-2021-3156HIGHsob ataque18 jul 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC8
Exploit para explotar la vulnerabilidad CVE-2025-32463
CVE-2025-32463CRITICALsob ataque18 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC
Local Privilege Escalation to Root via Sudo chroot in Linux
CVE-2025-32463CRITICALsob ataque18 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC
admin-ping/CVE-2025-48384-RCE
CVE-2025-48384HIGHsob ataque17 jul 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC
This is the exploit for the CVE-2025-32463
CVE-2025-32463CRITICALsob ataque17 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC
PoC of cve-2016-6210
CVE-2016-6210MEDIUM17 jul 2025
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RISCO
abrir
GitHub PoC1
blindma1den/CVE-2025-47812
CVE-2025-47812CRITICALsob ataque17 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir
GitHub PoC
simplyfurious/CVE-2025-48384-submodule_test
CVE-2025-48384HIGHsob ataque17 jul 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC
nguyentranbaotran/cve-2025-48384-poc
CVE-2025-48384HIGHsob ataque16 jul 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC2
joelczk/CVE-2025-52688
CVE-2025-52688CRITICAL16 jul 2025
Command Injection Vulnerability in the OmniAccess Stellar Web Management Interface
53RISCO
abrir
GitHub PoC
rpc.py 0.6.0 - Remote Code Execution (RCE)
CVE-2022-3541116 jul 2025
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header i
35RISCO
abrir
GitHub PoC2
(PoC) CVE-2025-27210, a precise Path Traversal vulnerability affecting Node.js applications running on Microsoft Windows. This vulnerability leverages the specific way Windows handles reserved device file names
CVE-2025-27210HIGH16 jul 2025
An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CO
41RISCO
abrir
GitHub PoC1
krypton-0x00/CVE-2025-32463-Chwoot-POC
CVE-2025-32463CRITICALsob ataque16 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC
Floodnut/CVE-2025-32463
CVE-2025-32463CRITICALsob ataque16 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC
Kalidas-7/CVE-2019-9053
CVE-2019-905316 jul 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
GitHub PoC5
An in-depth analysis of CVE 2023 38408, a critical OpenSSH vulnerability, including technical background, exploitation in controlled environments, and mitigation strategies.
CVE-2023-38408CRITICAL16 jul 2025
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISCO
abrir
GitHub PoC
CVE-2025-53833
CVE-2025-53833CRITICAL16 jul 2025
LaRecipe is vulnerable to Server-Side Template Injection attacks
63RISCO
abrir
GitHub PoC
malaya-m/cve-2013-3900-remediation-report
CVE-2013-3900MEDIUMsob ataque16 jul 2025
WinVerifyTrust Signature Validation Vulnerability
75RISCO
abrir
GitHub PoC
Detection for CVE-2025-47812
CVE-2025-47812CRITICALsob ataque16 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir
GitHub PoC
Exploit for php-cgi
CVE-2024-4577CRITICALsob ataqueransomware16 jul 2025
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
CVE-2025-5777 (CitrixBleed 2) - [Citrix NetScaler ADC] [Citrix Gateway]
CVE-2025-5777CRITICALsob ataqueransomware15 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
GitHub PoC
ECHO6789/CVE-2025-48384-submodule
CVE-2025-48384HIGHsob ataque15 jul 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC2
An advanced, powerful, and easy-to-use tool designed to detect and exploit CVE-2025-5777 (CitrixBleed 2). This script not only identifies the vulnerability but also helps in demonstrating its impact by parsing human-readable information from the memory leak.
CVE-2025-5777CRITICALsob ataqueransomware15 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
GitHub PoC1
PoC for CVE-2025-25257, a critical unauthenticated SQL injection in FortiWeb. Exploits SQLi via the Authorization header to write a webshell and gain RCE. No login required. Fully automated.
CVE-2025-25257CRITICALsob ataque15 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISCO
abrir
GitHub PoC48
Privilege escalation to root using sudo chroot, NO NEED for gcc installed.
CVE-2025-32463CRITICALsob ataque14 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC1
This repository contains a proof-of-concept exploit for CVE-2025-48827, a critical authentication bypass vulnerability affecting vBulletin 5.0.0–5.7.5 and 6.0.0–6.0.3 when running on PHP 8.1 or later. The vulnerability allows unauthenticated attackers to invoke protected API methods remotely.
CVE-2025-48827CRITICAL14 jul 2025
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
85RISCO
abrir
GitHub PoC2
Royal Elementor Addons - Unauthenticated Remote Code Execution
CVE-2023-536014 jul 2025
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RISCO
abrir
anteriorpágina 134 / 444próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.