Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.584exploits catalogados
34.508CVEs com exploração pública
24.695testados em laboratório
75.526 exploits
VulnCheck XDB
initial-access
CVE-2025-64446CRITICALsob ataque17 nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-21587CRITICALsob ataqueransomware17 nov 2025
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).
100RISCO
abrir
GitHub PoC
This exploit demonstrates a **path traversal vulnerability** in Xibo CMS (CVE-2023-33177) that allows remote code execution through malicious layout imports.
CVE-2023-33177HIGH17 nov 2025
Xibo CMS vulnerable to Remote Code Execution through Zip Slip
41RISCO
abrir
GitHub PoC
FortiWeb Unauthenticated RCE via Path Traversal & CGI Auth Bypass
CVE-2025-64446CRITICALsob ataque17 nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISCO
abrir
GitHub PoC
Vulnerability Found on Squid Proxy.
CVE-2025-54574CRITICAL17 nov 2025
Squid's URN Handling can lead to Buffer Overflow
53RISCO
abrir
GitHub PoC
This lab simulates CVE-2019-9193 - PostgreSQL COPY FROM PROGRAM RCE
CVE-2019-919317 nov 2025
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISCO
abrir
GitHub PoC
developerfred/CVE-2022-31199
CVE-2022-31199CRITICALsob ataqueransomware17 nov 2025
Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting bot
90RISCO
abrir
GitHub PoC
letsr00t/CVE-2019-13272
CVE-2019-13272HIGHsob ataque17 nov 2025
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir
GitHub PoC31
A scanner for the FortiNet vulnerability CVE-2025-64446
CVE-2025-64446CRITICALsob ataque17 nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISCO
abrir
VulnCheck XDB
local
CVE-2019-13272HIGHsob ataque17 nov 2025
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir
GitHub PoC
CVE-2025-33073
CVE-2025-33073HIGHsob ataque17 nov 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RISCO
abrir
GitHub PoC3
CVE-2025-64446 - A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
CVE-2025-64446CRITICALsob ataque17 nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISCO
abrir
GitHub PoC
Hands-on exploitation lab for Roundcube Webmail CVE-2025-49113 (authenticated PHP object deserialization → RCE) to read /secret.txt.
CVE-2025-49113CRITICALsob ataque17 nov 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
GitHub PoC
CVE-2015-3306 - ProFTPD - RCE Home Lab setup (Docker) easy to use for Red Teaming or Penetration Testing
CVE-2015-330617 nov 2025
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISCO
abrir
GitHub PoC
CVE-2017-12615 Tomcat: Remote Code Execution via JSP Upload Home Lab for Red Teaming, Penetration Testing
CVE-2017-12615HIGHsob ataqueransomware17 nov 2025
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISCO
abrir
Metasploit300
N-able N-Central Authentication Bypass and XXE Scanner
CVE-2025-11700HIGH17 nov 2025
N-central Multiple XXE Injection Vulnerabilities
68RISCO
abrir
Metasploit300
N-able N-Central Authentication Bypass and XXE Scanner
CVE-2025-9316MEDIUM17 nov 2025
N-central unauthenticated sessionID generation
60RISCO
abrir
GitHub PoC
kautilyagupt/CVE-2024-26169-Detail-1
CVE-2024-26169HIGHsob ataqueransomware17 nov 2025
Windows Error Reporting Service Elevation of Privilege Vulnerability
71RISCO
abrir
GitHub PoC2
This Python PoC script detects the Heartbleed vulnerability (CVE-2014-0160) by performing a TLS handshake with heartbeat extension and sending a crafted heartbeat request. It parses responses to identify leaked memory, helping assess server susceptibility to this critical OpenSSL flaw.
CVE-2014-0160HIGHsob ataque17 nov 2025
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC
D-link AX1500 Vulnerability
CVE-2025-60854CRITICAL16 nov 2025
A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during
48RISCO
abrir
VulnCheck XDB
local
CVE-2025-21479HIGHsob ataque16 nov 2025
Incorrect Authorization in Graphics
71RISCO
abrir
GitHub PoC
Practical security research project exploiting CVE-2025-32463 to gain root access on a vulnerable sudo version. Includes write-up, PoC, and mitigation steps.
CVE-2025-32463CRITICALsob ataque16 nov 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALsob ataque16 nov 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC
This repository contains my work for a cybersecurity assignment where I exploited the real-world Log4Shell (CVE-2021-44228) vulnerability inside a safe, controlled virtual machine. The project followed a Capture-the-Flag format with multiple exploitation tasks to retrieve hidden flags.
CVE-2021-44228CRITICALsob ataqueransomware16 nov 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
placeholder for CitrixBleed 2.0 CVE-2025-5777
CVE-2025-5777CRITICALsob ataqueransomware16 nov 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
GitHub PoC1
CMS Made Simple < 2.2.10 - SQL Injection . Actual working version
CVE-2019-905316 nov 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
GitHub PoC13
Unauthenticated RCE PoC in Microsoft Windows Server Update Service (WSUS) - CVE-2025-59287 & CVE-2023-35317
CVE-2025-59287CRITICALsob ataque16 nov 2025
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
honeyvig/CVE-2022-0847-DirtyPipe-Exploit
CVE-2022-0847HIGHsob ataque16 nov 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC13
soltanali0/CVE-2025-64446-Exploit
CVE-2025-64446CRITICALsob ataque15 nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISCO
abrir
GitHub PoC1
Twodimensionalitylevelcrossing817/CVE-2025-59287
CVE-2025-59287CRITICALsob ataque15 nov 2025
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISCO
abrir
anteriorpágina 184 / 2.518próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.