Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.902exploits catalogados
34.597CVEs com exploração pública
24.695testados em laboratório
75.902 exploits
GitHub PoC
r0otk3r/CVE-2025-41646
CVE-2025-41646CRITICAL19 jul 2025
RevPi Webstatus application is vulnerable to an authentication bypass
75RISCO
abrir
GitHub PoC5
Public PoC for CVE-2025-25257: FortiWeb pre-auth SQLi to RCE
CVE-2025-25257CRITICALsob ataque19 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISCO
abrir
GitHub PoC
PoC for CVE-2024-47575
CVE-2024-47575CRITICALsob ataque19 jul 2025
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2
100RISCO
abrir
GitHub PoC
alm6no5/CVE-2024-20767
CVE-2024-20767HIGHsob ataque19 jul 2025
ColdFusion | Improper Access Control (CWE-284)
100RISCO
abrir
GitHub PoC14
PoC for NVIDIAScape bug
CVE-2025-23266CRITICAL19 jul 2025
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, wher
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-25257CRITICALsob ataque19 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-25257CRITICALsob ataque19 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALsob ataque19 jul 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-20767HIGHsob ataque19 jul 2025
ColdFusion | Improper Access Control (CWE-284)
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-41646CRITICAL19 jul 2025
RevPi Webstatus application is vulnerable to an authentication bypass
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-31161CRITICALsob ataqueransomware19 jul 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISCO
abrir
GitHub PoC1
Zenar CMS 9.3 suffers from an ​​unrestricted file upload vulnerability​​ in its file management module, allowing authenticated attackers (with minimal privileges) to upload arbitrary files, including malicious PHP scripts, to the web server.
CVE-2022-44136CRITICAL18 jul 2025
Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).
48RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-47176HIGH18 jul 2025
Microsoft Outlook Remote Code Execution Vulnerability
41RISCO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALsob ataque18 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALsob ataque18 jul 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHsob ataque18 jul 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC8
Exploit para explotar la vulnerabilidad CVE-2025-32463
CVE-2025-32463CRITICALsob ataque18 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC32
POC of CVE-2025-7783
CVE-2025-7783CRITICAL18 jul 2025
Usage of unsafe random function in form-data for choosing boundary
48RISCO
abrir
GitHub PoC8
Exploit para explotar la vulnerabilidad CVE-2025-32463
CVE-2021-3156HIGHsob ataque18 jul 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC1
Joelp03/CVE-2025-49113
CVE-2025-49113CRITICALsob ataque18 jul 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
GitHub PoC
Local Privilege Escalation to Root via Sudo chroot in Linux
CVE-2025-32463CRITICALsob ataque18 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC1
blindma1den/CVE-2025-47812
CVE-2025-47812CRITICALsob ataque17 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir
GitHub PoC
This is the exploit for the CVE-2025-32463
CVE-2025-32463CRITICALsob ataque17 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC
simplyfurious/CVE-2025-48384-submodule_test
CVE-2025-48384HIGHsob ataque17 jul 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-47812CRITICALsob ataque17 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALsob ataque17 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC
PoC of cve-2016-6210
CVE-2016-6210MEDIUM17 jul 2025
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RISCO
abrir
GitHub PoC
admin-ping/CVE-2025-48384-RCE
CVE-2025-48384HIGHsob ataque17 jul 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC2
(PoC) CVE-2025-27210, a precise Path Traversal vulnerability affecting Node.js applications running on Microsoft Windows. This vulnerability leverages the specific way Windows handles reserved device file names
CVE-2025-27210HIGH16 jul 2025
An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CO
41RISCO
abrir
GitHub PoC
Kalidas-7/CVE-2019-9053
CVE-2019-905316 jul 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
anteriorpágina 231 / 2.531próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.