Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.589exploits catalogados
34.508CVEs com exploração pública
24.695testados em laboratório
75.589 exploits
VulnCheck XDB
initial-access
CVE-2025-34299CRITICAL10 nov 2025
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RISCO
abrir
GitHub PoC1
check if vulnerable python-django version to CVE-2025-64459 bug
CVE-2025-64459CRITICAL10 nov 2025
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-11953CRITICALsob ataque10 nov 2025
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
90RISCO
abrir
GitHub PoC
Exploit and test stand for CVE-2025-2945
CVE-2025-2945CRITICAL10 nov 2025
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
75RISCO
abrir
GitHub PoC1
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
CVE-2025-6440CRITICAL10 nov 2025
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISCO
abrir
GitHub PoC
Ghstxz/CVE-2025-32463
CVE-2025-32463CRITICALsob ataque10 nov 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC
n0m-d/CVE-2021-40438-POC
CVE-2021-40438CRITICALsob ataqueransomware09 nov 2025
mod_proxy SSRF
100RISCO
abrir
GitHub PoC12
CVE-2025-6554
CVE-2025-6554HIGHsob ataque09 nov 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RISCO
abrir
GitHub PoC
A proof of concept for CVE-2025-24054/CVE-2025-24071
CVE-2025-24054MEDIUMsob ataque09 nov 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-40438CRITICALsob ataqueransomware09 nov 2025
mod_proxy SSRF
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-11749CRITICAL08 nov 2025
AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation
85RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-21042HIGHsob ataque08 nov 2025
Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitra
83RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALsob ataque08 nov 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
GitHub PoC
letsr00t/-CVE-2019-18634-sudo-pwfeedback
CVE-2019-1863408 nov 2025
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISCO
abrir
GitHub PoC
l1nuxkid/CVE-2025-32433-exploit
CVE-2025-32433CRITICALsob ataque08 nov 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
GitHub PoC9
AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation
CVE-2025-11749CRITICAL08 nov 2025
AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation
85RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-48384HIGHsob ataque08 nov 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
Metasploit600
FreePBX filestore authenticated command injection
CVE-2025-64328HIGHsob ataque08 nov 2025
FreePBX Administration GUI is Vulnerable to Authenticated Command Injection
100RISCO
abrir
Metasploit600
Monsta FTP downloadFile Remote Code Execution
CVE-2025-34299CRITICAL07 nov 2025
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-9491MEDIUM07 nov 2025
Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability
45RISCO
abrir
GitHub PoC10
Firefox/Tor Browser 0day exploit analysis (CVE-2024-9680) A UAF in animation timelines leading to RCE. Patched.
CVE-2024-9680CRITICALsob ataqueransomware07 nov 2025
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timeli
83RISCO
abrir
GitHub PoC1
Emergency Chrome update information and tools for CVE-2023-7024 and other critical vulnerabilities
CVE-2023-7024HIGHsob ataque07 nov 2025
Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit
71RISCO
abrir
GitHub PoC1
Emergency Chrome update information and tools for CVE-2023-7024 and other critical vulnerabilities
CVE-2023-7024HIGHsob ataque07 nov 2025
Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit
71RISCO
abrir
GitHub PoC
Tomcat - PUT Method
CVE-2017-12615HIGHsob ataqueransomware07 nov 2025
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-5902CRITICALsob ataqueransomware07 nov 2025
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2024-21413CRITICALsob ataque06 nov 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
local
CVE-2019-2215HIGHsob ataque06 nov 2025
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISCO
abrir
GitHub PoC2
This repository contains research notes and a high-level proof-of-concept (PoC) for CVE-2024-21413, a vulnerability observed in certain mail clients when handling SMB/moniker-style links embedded in messages. The PoC and experiments documented here were performed in a controlled lab environment on systems.
CVE-2024-21413CRITICALsob ataque06 nov 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC5
demo CVE-2019-2215 (Bad Binder) for Android Q
CVE-2019-2215HIGHsob ataque06 nov 2025
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISCO
abrir
GitHub PoC
rockmelodies/django_sqli_target_CVE-2025-64459
CVE-2025-64459CRITICAL06 nov 2025
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RISCO
abrir
anteriorpágina 188 / 2.520próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.