Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.640exploits catalogados
34.544CVEs com exploração pública
24.695testados em laboratório
75.589 exploits
GitHub PoC
PoC exploit for CVE-2024-28397 – Remote Code Execution in pyload-ng via js2py sandbox escape
CVE-2024-28397MEDIUM06 set 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISCO
abrir
GitHub PoC1
This repository contains some python scripts implementation for the MS08-067 Windows Server Service vulnerability (CVE-2008-4250). This is a classic remote code execution vulnerability affecting older Windows systems.
CVE-2008-4250CRITICALsob ataque06 set 2025
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-22515CRITICALsob ataqueransomware06 set 2025
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISCO
abrir
GitHub PoC
shoucheng3/ff4j__ff4j_CVE-2022-44262_1_8_13_fixed
CVE-2022-44262CRITICAL06 set 2025
ff4j 1.8.1 is vulnerable to Remote Code Execution (RCE).
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2008-4250CRITICALsob ataque06 set 2025
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2008-4250CRITICALsob ataque06 set 2025
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-58443CRITICAL06 set 2025
FOG's authentication bypass leads to full SQL DB dump
68RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-54309CRITICALsob ataque06 set 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RISCO
abrir
GitHub PoC
This repository contains a Metasploit module implementation for the MS08-067 Windows Server Service vulnerability (CVE-2008-4250). This is a classic remote code execution vulnerability affecting older Windows systems.
CVE-2008-4250CRITICALsob ataque06 set 2025
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RISCO
abrir
GitHub PoC2
FOGProject Authentication bypass CVE-2025-58443 Exploit
CVE-2025-58443CRITICAL06 set 2025
FOG's authentication bypass leads to full SQL DB dump
68RISCO
abrir
GitHub PoC
tranphuc2005/CVE-2023-22515
CVE-2023-22515CRITICALsob ataqueransomware06 set 2025
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISCO
abrir
GitHub PoC
cve-2025-33073/cve-2025-33073
CVE-2025-33073HIGHsob ataque06 set 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RISCO
abrir
GitHub PoC
oukridrig772/-WinVerifyTrust-Signature-Validation-CVE-2013-3900-Mitigation
CVE-2013-3900MEDIUMsob ataque06 set 2025
WinVerifyTrust Signature Validation Vulnerability
75RISCO
abrir
GitHub PoC
whisperer1290/CVE-2025-54309__Enhanced_exploit
CVE-2025-54309CRITICALsob ataque06 set 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RISCO
abrir
GitHub PoC2
PoC for CVE-2015-5736
CVE-2015-573606 set 2025
The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitrary code with kernel
23RISCO
abrir
GitHub PoC
andwati/CVE-2025-24893
CVE-2025-24893CRITICALsob ataque05 set 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC
Python script to execute CVE-2025-24071
CVE-2025-24071MEDIUM05 set 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
GitHub PoC1
Miraculous Core (kamleshyadav) ≤ 2.0.7 — Unauthenticated Privilege Escalation
CVE-2025-49388CRITICAL05 set 2025
WordPress Miraculous Core Plugin Plugin <= 2.0.7 - Privilege Escalation Vulnerability
48RISCO
abrir
GitHub PoC
Una herramienta avanzada de escaneo, explotación e interacción remota diseñada para detectar y aprovechar la vulnerabilidad Apache Path Traversal + RCE (CVE-2021-42013) en servidores mal configurados.
CVE-2021-42013CRITICALsob ataqueransomware05 set 2025
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALsob ataque05 set 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALsob ataqueransomware05 set 2025
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALsob ataque05 set 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC
blackcat4347/CVE-2025-32463_PoC
CVE-2025-32463CRITICALsob ataque05 set 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALsob ataqueransomware04 set 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-57819CRITICALsob ataque04 set 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-53772HIGH04 set 2025
Web Deploy Remote Code Execution Vulnerability
46RISCO
abrir
VulnCheck XDB
local
CVE-2024-1086HIGHsob ataqueransomware04 set 2025
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-5016404 set 2025
Apache Struts: File upload component had a directory traversal vulnerability
45RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-8088HIGHsob ataque04 set 2025
Path traversal vulnerability in WinRAR
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-7961CRITICALsob ataque04 set 2025
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISCO
abrir
anteriorpágina 205 / 2.520próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.