Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.589exploits catalogados
34.508CVEs com exploração pública
24.695testados em laboratório
75.589 exploits
VulnCheck XDB
client-side
CVE-2025-64095CRITICAL06 nov 2025
DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite
75RISCO
abrir
GitHub PoC5
demo CVE-2019-2215 (Bad Binder) for Android Q
CVE-2019-2215HIGHsob ataque06 nov 2025
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISCO
abrir
GitHub PoC
rockmelodies/django_sqli_target_CVE-2025-64459
CVE-2025-64459CRITICAL06 nov 2025
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RISCO
abrir
GitHub PoC2
This repository contains research notes and a high-level proof-of-concept (PoC) for CVE-2024-21413, a vulnerability observed in certain mail clients when handling SMB/moniker-style links embedded in messages. The PoC and experiments documented here were performed in a controlled lab environment on systems.
CVE-2024-21413CRITICALsob ataque06 nov 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
CVE-2025-54782
CVE-2025-54782CRITICAL06 nov 2025
@nestjs/devtools-integration's CSRF to Sandbox Escape Allows for RCE against JS Developers
75RISCO
abrir
VulnCheck XDB
local
CVE-2019-2215HIGHsob ataque06 nov 2025
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-14883HIGHsob ataque05 nov 2025
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC1
RestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT
CVE-2025-9209CRITICAL05 nov 2025
RestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALsob ataqueransomware05 nov 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC8
CVE-2025-53690 POC
CVE-2025-53690CRITICALsob ataque05 nov 2025
Sitecore Products ViewState Deserialization Vulnerability
90RISCO
abrir
GitHub PoC
A Dockerized setup for running a vulnerable CrushFTP 10 server instance (CVE-2024-4040).
CVE-2024-4040CRITICALsob ataque05 nov 2025
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISCO
abrir
GitHub PoC
Billing CTF Machine_CVE-2023-30258_Remote Code Execution
CVE-2023-30258CRITICAL05 nov 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-11953CRITICALsob ataque05 nov 2025
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
90RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-53690CRITICALsob ataque05 nov 2025
Sitecore Products ViewState Deserialization Vulnerability
90RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-5932CRITICAL04 nov 2025
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-11953CRITICALsob ataque04 nov 2025
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
90RISCO
abrir
Metasploit600
WordPress AI Engine Plugin MCP Unauthenticated Admin Creation to RCE
CVE-2025-11749CRITICAL04 nov 2025
AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation
85RISCO
abrir
GitHub PoC
PoC for CVE-2024-5932.
CVE-2024-5932CRITICAL04 nov 2025
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RISCO
abrir
GitHub PoC10
Breaking down CVE-2025-54253 — an Adobe AEM-Forms exploit path from XXE to full remote code execution and its real-world impact.
CVE-2025-54253CRITICALsob ataque04 nov 2025
Adobe Experience Manager | Incorrect Authorization (CWE-863)
100RISCO
abrir
GitHub PoC4
CVE-2025-11953 demonstration: Critical RCE vulnerability in React Native CLI (CVSS 9.8). Educational security research with proof-of-concept exploits and mitigation strategies.
CVE-2025-11953CRITICALsob ataque04 nov 2025
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
90RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALsob ataque04 nov 2025
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC8
A vulnerability in fiberhome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-shared key) to be predicted from the SSID
CVE-2025-63353CRITICAL04 nov 2025
A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-s
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-59287CRITICALsob ataque03 nov 2025
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALsob ataque03 nov 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC1
XWiki Unauthenticated RCE Exploit for Reverse Shell
CVE-2025-24893CRITICALsob ataque03 nov 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALsob ataque03 nov 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC1
Exploit for CVE-2025-2011
CVE-2025-2011HIGH02 nov 2025
Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection via 's' Parameter
68RISCO
abrir
GitHub PoC1
My view on IngressNightmare vulnerability (CVE-2025-1974)
CVE-2025-1974CRITICAL02 nov 2025
ingress-nginx admission controller RCE escalation
85RISCO
abrir
GitHub PoC1
This is a customized script to help solve the lab on remote code execution under the CVE-2015-3306 lab.
CVE-2015-330602 nov 2025
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-8088HIGHsob ataque02 nov 2025
Path traversal vulnerability in WinRAR
93RISCO
abrir
anteriorpágina 189 / 2.520próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.