Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.589exploits catalogados
34.508CVEs com exploração pública
24.695testados em laboratório
75.589 exploits
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALsob ataqueransomware17 set 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
GitHub PoC
PoC for achieving RCE in Langflow versions <1.3.0
CVE-2025-3248CRITICALsob ataqueransomware17 set 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
GitHub PoC1
Shinkirou789/Cve-2025-8088-WinRar-vulnerability
CVE-2025-8088HIGHsob ataque17 set 2025
Path traversal vulnerability in WinRAR
93RISCO
abrir
GitHub PoC1
Proof-Of-Concept to check privileges of af_packet.c for validating the privileges acquired by any hacker upon successful exploitation of CVE-2021-22600
CVE-2021-22600MEDIUMsob ataque17 set 2025
Double Free in net/packet/af_packet.c leading to priviledge escalation
63RISCO
abrir
GitHub PoC
Python tool for CVE-2010-1240 research - generates malicious PDFs exploiting Adobe Reader Launch Actions
CVE-2010-124017 set 2025
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-29927CRITICAL17 set 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-3396CRITICALsob ataqueransomware16 set 2025
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-1709CRITICALsob ataqueransomware16 set 2025
Authentication bypass using an alternate path or channel
100RISCO
abrir
GitHub PoC
A Rust implementation of the CVE-2014-6287 exploit targeting Rejetto HTTP File Server (HFS) versions 2.3x before 2.3c.
CVE-2014-6287CRITICALsob ataque16 set 2025
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-1708HIGHsob ataqueransomware16 set 2025
Improper limitation of a pathname to a restricted directory (“path traversal”)
100RISCO
abrir
Exploit-DB
Mbed TLS 3.6.4 - Use-After-Free
CVE-2025-47917HIGHlocalmultiple16 set 2025
Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance wit
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2014-6287CRITICALsob ataque16 set 2025
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir
Exploit-DB
HTMLDOC 1.9.13 - Stack Buffer Overflow
CVE-2021-43579remotemultiple16 set 2025
A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim co
23RISCO
abrir
Exploit-DB
ClipBucket 5.5.0 - Arbitrary File Upload
CVE-2025-55912HIGHremotemultiple16 set 2025
An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in
41RISCO
abrir
Exploit-DB
Concrete CMS 9.4.3 - Stored XSS
CVE-2025-8573LOWwebappsmultiple16 set 2025
Concrete CMS 9 through 9.4.2 is vulnerable to Stored XSS from Home Folder on Members Dashboard page
28RISCO
abrir
Exploit-DB
dotCMS 25.07.02-1 - Authenticated Blind SQL Injection
CVE-2025-8311CRITICALwebappsmultiple16 set 2025
dotCMS versions 24.03.22 and after, identified a Boolean-based blind SQLi vulnerability in the /api/v1/contenttype endpo
48RISCO
abrir
Exploit-DB
Tourism Management System 2.0 - Arbitrary Shell Upload
CVE-2025-57642HIGHwebappsmultiple16 set 2025
A Shell Upload vulnerability in Tourism Management System 2.0 allows an attacker to upload and execute arbitrary PHP she
41RISCO
abrir
Exploit-DB
ClipBucket 5.5.2 Build #90 - Server-Side Request Forgery (SSRF)
CVE-2025-55911MEDIUMremotemultiple16 set 2025
An issue Clip Bucket v.5.5.2 Build#90 allows a remote attacker to execute arbitrary codes via the file_downloader.php an
33RISCO
abrir
GitHub PoC
2 web apps vulnerable to CVE-2025-27210
CVE-2025-27210HIGH16 set 2025
An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CO
41RISCO
abrir
GitHub PoC
PoC for CVE-2025-20265 Cisco Secure FMC Software RADIUS Remote Code Execution Vulnerability
CVE-2025-20265CRITICAL16 set 2025
Cisco Secure Firewall Management Center Software Radius Remote Code Execution Vulnerability
53RISCO
abrir
GitHub PoC
CVE-2019-3396 confluence SSTI RCE
CVE-2019-3396CRITICALsob ataqueransomware16 set 2025
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISCO
abrir
Exploit-DB
HTTP/2 2.0 - Denial Of Service (DOS)
CVE-2023-44487HIGHsob ataqueremotemultiple16 set 2025
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISCO
abrir
Exploit-DB
Casdoor 2.55.0 - Cross-Site Request Forgery (CSRF)
CVE-2023-34927webappsmultiple16 set 2025
Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-passwo
23RISCO
abrir
Exploit-DB
XWiki Platform 15.10.10 - Metasploit Module for Remote Code Execution (RCE)
CVE-2025-24893CRITICALsob ataquewebappsmultiple16 set 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-24799HIGH16 set 2025
GLPI allows unauthenticated SQL injection through the inventory endpoint
78RISCO
abrir
Exploit-DB
ELEX WooCommerce WordPress Plugin 1.4.3 - SQL Injection
CVE-2025-10046MEDIUMwebappsmultiple16 set 2025
ELEX WooCommerce Google Shopping (Google Product Feed) <= 1.4.3 - Authenticated (Admin+) SQL Inejction
33RISCO
abrir
GitHub PoC2
RedArrow3.2 是一款用于渗透测试ThinkPHP 5.0.23 远程命令执行漏洞(CVE-2018-20062)的图形化工具。
CVE-2018-20062CRITICALsob ataque16 set 2025
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RISCO
abrir
GitHub PoC2
Example PoC for CVE-2025-24813 (Tomcat RCE)
CVE-2025-24813CRITICALsob ataque16 set 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC
0xDTC/js2py-Sandbox-Escape-CVE-2024-28397-RCE
CVE-2024-28397MEDIUM15 set 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISCO
abrir
GitHub PoC2
Langflow Remote Code Execution
CVE-2025-3248CRITICALsob ataqueransomware15 set 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
anteriorpágina 201 / 2.520próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.