Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.652exploits catalogados
34.545CVEs com exploração pública
24.695testados em laboratório
75.652 exploits
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALsob ataque26 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALsob ataque26 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
Exploit-DB
Birth Chart Compatibility WordPress Plugin 2.0 - Full Path Disclosure
CVE-2025-6082MEDIUMwebappsmultiple26 ago 2025
Birth Chart Compatibility <= 2.0 - Unauthenticated Full Path Exposure
33RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-5419HIGHsob ataque25 ago 2025
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially expl
71RISCO
abrir
GitHub PoC
his project demonstrates the exploitation of the vsFTPd 2.3.4 backdoor vulnerability (CVE-2011-2523) using Metasploitable 2 and Kali Linux with Metasploit. It includes reconnaissance, exploitation, and defensive measures, with a detailed report and lab setup for learning ethical hacking and security best practices.
CVE-2011-252325 ago 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALsob ataqueransomware25 ago 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC2
Odoo ≤17 is vulnerable to CVE-2024-4367, allowing arbitrary JavaScript execution via PDF.js.
CVE-2024-4367MEDIUM25 ago 2025
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHsob ataque25 ago 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALsob ataqueransomware25 ago 2025
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC10
zenzue/CVE-2025-9074
CVE-2025-9074CRITICAL25 ago 2025
Docker Desktop allows unauthenticated access to Docker Engine API from containers
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-54309CRITICALsob ataque25 ago 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RISCO
abrir
GitHub PoC28
watchtowrlabs/watchTowr-vs-CrushFTP-Authentication-Bypass-CVE-2025-54309
CVE-2025-54309CRITICALsob ataque25 ago 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RISCO
abrir
GitHub PoC95
mistymntncop/CVE-2025-5419
CVE-2025-5419HIGHsob ataque25 ago 2025
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially expl
71RISCO
abrir
GitHub PoC
a1ex-var1amov/ctf-cve-2024-4577
CVE-2024-4577CRITICALsob ataqueransomware25 ago 2025
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
PoC
CVE-2025-48384HIGHsob ataque25 ago 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC
A research regarding the exisiting CVE exploit : CVE-2021-3156(Sudo BufferOverflow)
CVE-2021-3156HIGHsob ataque25 ago 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC
TamatahYT/CVE-2017-8481
CVE-2017-848125 ago 2025
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RISCO
abrir
GitHub PoC3
Apache Struts2 CVE-2017-5638 (Safe Educational Demo)
CVE-2017-5638CRITICALsob ataqueransomware25 ago 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
VulnCheck XDB
local
CVE-2023-21768HIGH25 ago 2025
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RISCO
abrir
GitHub PoC5
POC of CVE-2025-49113
CVE-2025-49113CRITICALsob ataque24 ago 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
GitHub PoC
Quick and easy exploitation of CVE-2024-4956 for LFI.
CVE-2024-4956HIGH24 ago 2025
Nexus Repository 3 - Path Traversal
61RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALsob ataque24 ago 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
VulnCheck XDB
local
CVE-2025-43300CRITICALsob ataque24 ago 2025
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1
83RISCO
abrir
GitHub PoC114
This is POC for IOS 0click CVE-2025-43300
CVE-2025-43300CRITICALsob ataque24 ago 2025
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1
83RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-3864624 ago 2025
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISCO
abrir
GitHub PoC1
Este repositório contém um script de prova de conceito (PoC) que demonstra uma vulnerabilidade crítica encontrada no plugin Simple File List para WordPress.
CVE-2020-36847CRITICAL23 ago 2025
Simple File List < 4.2.3 - Remote Code Execution
68RISCO
abrir
GitHub PoC
Sequelize Sql Injection 취약점 구현
CVE-2023-25813CRITICAL23 ago 2025
SQL Injection via replacements in sequelize
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-36847CRITICAL23 ago 2025
Simple File List < 4.2.3 - Remote Code Execution
68RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-33053HIGHsob ataque23 ago 2025
Internet Shortcut Files Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
donmedfor/CVE-2015-3306
CVE-2015-330623 ago 2025
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISCO
abrir
anteriorpágina 211 / 2.522próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.