Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.902exploits catalogados
34.597CVEs com exploração pública
24.695testados em laboratório
75.902 exploits
GitHub PoC
CVE-2019–11043: PHP-FPM Nginx Remote Code Execution Vulnerability
CVE-2019-11043HIGHsob ataqueransomware19 jun 2025
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
Metasploit600
Pterodactyl Panel CVE-2025-49132 Remote Code Execution
CVE-2025-49132CRITICAL19 jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALsob ataqueransomware19 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
GitHub PoC
DevinLiggins14/SMB-PenTest-Exploiting-CVE-2007-2447-on-Metasploitable-2
CVE-2007-244719 jun 2025
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir
VulnCheck XDB
local
CVE-2025-21479HIGHsob ataque19 jun 2025
Incorrect Authorization in Graphics
71RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-41352CRITICALsob ataque19 jun 2025
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through ama
100RISCO
abrir
GitHub PoC
Unauthenticated RCE via Webmin Backdoor (CVE-2019–15107)
CVE-2019-15107CRITICALsob ataqueransomware19 jun 2025
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-398019 jun 2025
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to
23RISCO
abrir
VulnCheck XDB
local
CVE-2025-6019HIGH19 jun 2025
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RISCO
abrir
GitHub PoC1
Threat intelligence report analyzing the xz-utils backdoor vulnerability (CVE-2024-3094)
CVE-2024-3094CRITICAL19 jun 2025
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC
Exploit for CVE-2011-2523.
CVE-2011-252319 jun 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALsob ataqueransomware19 jun 2025
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALsob ataque18 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
VulnCheck XDB
local
CVE-2023-0386HIGHsob ataque18 jun 2025
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-1094HIGH18 jun 2025
PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation
78RISCO
abrir
GitHub PoC
punitdarji/roundcube-cve-2025-49113
CVE-2025-49113CRITICALsob ataque18 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
GitHub PoC2
imbas007/CVE-2025-3248
CVE-2025-3248CRITICALsob ataqueransomware18 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
GitHub PoC
Exploit for Langflow AI Remote Code Execution (Unauthenticated)
CVE-2025-3248CRITICALsob ataqueransomware18 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALsob ataqueransomware18 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
GitHub PoC1
CVE-2025-33053 Checker and PoC
CVE-2025-33053HIGHsob ataque18 jun 2025
Internet Shortcut Files Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALsob ataqueransomware18 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
GitHub PoC3
Proof-of-Concept for CVE-2025-33053 Exploiting WebDAV with .url file delivery to demonstrate realistic remote code execution. Includes a decoy PDF payload and a video-only showcase of potential command-and-control capabilities.
CVE-2025-33053HIGHsob ataque18 jun 2025
Internet Shortcut Files Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALsob ataqueransomware17 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
GitHub PoC
Kernel Pool Overflow Exploit targeting CVE-2021-31956
CVE-2021-31956HIGHsob ataque17 jun 2025
Windows NTFS Elevation of Privilege Vulnerability
76RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-4123HIGH17 jun 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISCO
abrir
GitHub PoC
EdouardosStav/CVE-2019-15107-RCE-WebMin
CVE-2019-15107CRITICALsob ataqueransomware17 jun 2025
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALsob ataque17 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
GitHub PoC
A hands-on vulnerability assessment and exploitation of a Windows 7 VM using the EternalBlue (CVE-2017-0143) exploit. Includes scanning, exploitation with Metasploit, post-exploitation, and remediation steps in a controlled lab environment.
CVE-2017-0143HIGHsob ataqueransomware17 jun 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
GitHub PoC
Explicação + Lab no THM
CVE-2025-49113CRITICALsob ataque17 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
GitHub PoC17
CVE-2025-3248 Langflow RCE Exploit
CVE-2025-3248CRITICALsob ataqueransomware17 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
anteriorpágina 248 / 2.531próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.