Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.652exploits catalogados
34.545CVEs com exploração pública
24.695testados em laboratório
75.652 exploits
VulnCheck XDB
infoleak
CVE-2025-25231HIGH12 ago 2025
Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to ga
61RISCO
abrir
GitHub PoC8
CVE-2024-47533 is a critical authentication bypass vulnerability in Cobbler (versions 3.0.0 to before 3.2.3 and 3.3.7) allowing unauthenticated remote code execution via the XMLRPC interface.
CVE-2024-47533CRITICAL12 ago 2025
Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes
63RISCO
abrir
GitHub PoC46
WinRAR 0day CVE-2025-8088 PoC RAR Archive
CVE-2025-8088HIGHsob ataque12 ago 2025
Path traversal vulnerability in WinRAR
93RISCO
abrir
Exploit-DB
Ghost CMS 5.42.1 - Path Traversal
CVE-2023-32235HIGHwebappsmultiple11 ago 2025
Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2
68RISCO
abrir
GitHub PoC2
cve-2025-8088_detection
CVE-2025-8088HIGHsob ataque11 ago 2025
Path traversal vulnerability in WinRAR
93RISCO
abrir
Exploit-DB
Ghost CMS 5.59.1 - Arbitrary File Read
CVE-2023-40028MEDIUMwebappsmultiple11 ago 2025
Arbitrary file read via symlinks in Ghost
45RISCO
abrir
GitHub PoC3
CVE-2024-47533: Cobbler Authentication Bypass & Code Execution
CVE-2024-47533CRITICAL11 ago 2025
Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes
63RISCO
abrir
GitHub PoC
These PoC python scripts test the Kemp LoadMaster for remote code execution.
CVE-2024-7591CRITICAL11 ago 2025
Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection
75RISCO
abrir
Exploit-DB
Tigo Energy Cloud Connect Advanced (CCA) 4.0.1 - Command Injection
CVE-2025-7769HIGHremotemultiple11 ago 2025
Improper Neutralization of Special Elements used in a Command ('Command Injection') in Tigo Energy Cloud Connect Advanced
46RISCO
abrir
Exploit-DB
JetBrains TeamCity 2023.11.4 - Authentication Bypass
CVE-2024-27198CRITICALsob ataqueransomwarewebappsmultiple11 ago 2025
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir
Exploit-DB
Belkin F9K1009 F9K1010 2.00.04/2.00.09 - Hard Coded Credentials
CVE-2025-8730CRITICALremotemultiple11 ago 2025
Belkin F9K1009/F9K1010 Web Interface hard-coded credentials
48RISCO
abrir
Exploit-DB
Microsoft Windows - Storage QoS Filter Driver Checker
CVE-2025-49730HIGHlocalwindows11 ago 2025
Microsoft Windows QoS Scheduler Driver Elevation of Privilege Vulnerability
41RISCO
abrir
Exploit-DB
VMware vSphere Client 8.0.3.0 - Reflected Cross-Site Scripting (XSS)
CVE-2025-41228MEDIUMwebappsmultiple11 ago 2025
VMware ESXi and vCenter Server Reflected Cross Site Scripting (XSS) Vulnerability
33RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALsob ataque11 ago 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
Exploit-DB
ServiceNow Multiple Versions - Input Validation & Template Injection
CVE-2024-4879CRITICALsob ataquewebappsmultiple11 ago 2025
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISCO
abrir
GitHub PoC
alexander47777/CVE-2016-10033
CVE-2016-10033CRITICALsob ataque11 ago 2025
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir
Exploit-DB
projectworlds Online Admission System 1.0 - SQL Injection
CVE-2025-8471MEDIUMwebappsmultiple11 ago 2025
projectworlds Online Admission System adminlogin.php sql injection
33RISCO
abrir
Exploit-DB
atjiu pybbs 6.0.0 - Cross Site Scripting (XSS)
CVE-2025-8550MEDIUMwebappsmultiple11 ago 2025
atjiu pybbs list cross site scripting
33RISCO
abrir
Exploit-DB
Microsoft Edge Renderer Process (Mojo IPC) 134.0.6998.177 - Sandbox Escape
CVE-2025-2783HIGHsob ataquewebappswindows11 ago 2025
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
71RISCO
abrir
Exploit-DB
Microsoft SharePoint Server 2019 (16.0.10383.20020) - Remote Code Execution (RCE)
CVE-2025-53770CRITICALsob ataqueransomwareremotewindows11 ago 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir
Exploit-DB
Cisco ISE 3.0 - Remote Code Execution (RCE)
CVE-2025-20124CRITICALremotemultiple11 ago 2025
Cisco Identity Services Engine Java Deserialization Vulnerability
53RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHsob ataqueransomware11 ago 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
Exploit-DB
Citrix NetScaler ADC/Gateway 14.1 - Memory Disclosure
CVE-2025-5777CRITICALsob ataqueransomwareremotemultiple11 ago 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
GitHub PoC
Update the old POC of CVE-2025-5777 Citrix NetScaler Memory leak
CVE-2025-5777CRITICALsob ataqueransomware11 ago 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
Exploit-DB
Grav CMS 1.7.48 - Remote Code Execution (RCE)
CVE-2025-50286HIGHwebappsphp11 ago 2025
A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plug
56RISCO
abrir
GitHub PoC4
Python exploit for vsftpd 2.3.4 - Backdoor Command Execution
CVE-2011-252311 ago 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2016-10033CRITICALsob ataque11 ago 2025
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir
GitHub PoC
Bash POC script for RCE vulnerability in Apache 2.4.49
CVE-2021-41773HIGHsob ataqueransomware11 ago 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC1
Este script explora a vulnerabilidade CVE-2025-24813 em versões específicas do Apache Tomcat, permitindo execução remota de código (RCE) através de um vetor de desserialização Java e abuso do método HTTP PUT para gravação arbitrária de arquivos de sessão.
CVE-2025-24813CRITICALsob ataque11 ago 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
Exploit-DB
Cisco ISE 3.0 - Authorization Bypass
CVE-2025-20125CRITICALremotemultiple11 ago 2025
Cisco Identity Services Engine Insufficient Authorization Bypass Vulnerability
53RISCO
abrir
anteriorpágina 217 / 2.522próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.