Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.008exploits catalogados
34.638CVEs com exploração pública
24.695testados em laboratório
76.008 exploits
VulnCheck XDB
client-side
CVE-2025-24071MEDIUM13 jun 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-27817HIGH12 jun 2025
Apache Kafka Client: Arbitrary file read and SSRF vulnerability
68RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-33053HIGHsob ataque12 jun 2025
Internet Shortcut Files Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-5287HIGH12 jun 2025
Likes and Dislikes Plugin <= 1.0.0 - Unauthenticated SQL Injection
56RISCO
abrir
GitHub PoC
Gigamon Unauth RCE (CVE-2026-36848)
CVE-2026-36848HIGH12 jun 2025
Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traversal in the GVOS H-VUE subsystem.
41RISCO
abrir
GitHub PoC64
CVE-2025-33053 Proof Of Concept (PoC)
CVE-2025-33053HIGHsob ataque12 jun 2025
Internet Shortcut Files Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
PoC for CVE-2021-29447
CVE-2021-29447HIGH12 jun 2025
WordPress Authenticated XXE attack when installation is running PHP 8
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL12 jun 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALsob ataqueransomware12 jun 2025
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
GitHub PoC
In this lab I walked through an end-to-end intrusion that began with an external RDP break-in, used a brand-new CLFS privilege-escalation exploit (CVE-2024–49138), and ended with SYSTEM-level cloud credential harvesting. Below is the story, the evidence, and the lessons I drew from it.
CVE-2024-49138HIGHsob ataque12 jun 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC
amitlttwo/Next.JS-CVE-2025-29927
CVE-2025-29927CRITICAL12 jun 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
Metasploit300
CVE-2025-33053 Exploit via Malicious .URL File and WebDAV
CVE-2025-33053HIGHsob ataque11 jun 2025
Internet Shortcut Files Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
local
CVE-2025-21333HIGHsob ataque11 jun 2025
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHsob ataqueransomware11 jun 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
Hands-on lab on detecting and mitigating web app threats using OWASP ZAP, Burp Suite, and ModSecurity WAF (with OWASP CRS). Case study: Spring4Shell (CVE-2022-22965). Local Docker-based setup.
CVE-2022-22965CRITICALsob ataque11 jun 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC
KimJuhyeong95/cve-2025-24514
CVE-2025-24514HIGH11 jun 2025
ingress-nginx controller - configuration injection via unsanitized auth-url annotation
68RISCO
abrir
GitHub PoC
Exploiting the vulnerability called "Dirty_Sock" (CVE-2019-7304) in the REST API for Canonical's snapd daemon.
CVE-2019-7304HIGH11 jun 2025
Local privilege escalation via snapd socket
53RISCO
abrir
GitHub PoC2
CyberQuestor-infosec/CVE-2021-41773-Apache_2.4.49-Path-traversal-to-RCE
CVE-2021-41773HIGHsob ataqueransomware11 jun 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC2
Detection for CVE-2025-24016 - Deserialization of Untrusted Data Vulnerability in the Wazuh software
CVE-2025-24016CRITICALsob ataque10 jun 2025
Remote code execution in Wazuh server
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALsob ataque10 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
GitHub PoC
CVE-2025-24071
CVE-2025-24071MEDIUM10 jun 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
GitHub PoC6
A PoC exploit for CVE-2017-9841 - PHPUnit Remote Code Execution(RCE)
CVE-2017-9841CRITICALsob ataque10 jun 2025
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-24016CRITICALsob ataque10 jun 2025
Remote code execution in Wazuh server
100RISCO
abrir
Metasploit600
n8n Workflow Expression Remote Code Execution
CVE-2025-68613CRITICALsob ataque10 jun 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISCO
abrir
GitHub PoC6
Proof-of-concept to CVE-2025-49113
CVE-2025-49113CRITICALsob ataque10 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
Metasploit600
Pandora ITSM authenticated command injection leading to RCE via the backup function
CVE-2025-4653HIGH10 jun 2025
Remote Code Execution leads to Command Injection
36RISCO
abrir
GitHub PoC2
This script exploits CVE-2025-49619 in Skyvern to execute a reverse shell command.
CVE-2025-49619HIGH09 jun 2025
Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks suc
61RISCO
abrir
Exploit-DB
ProSSHD 1.2 20090726 - Denial of Service (DoS)
CVE-2024-0725MEDIUMremotewindows09 jun 2025
ProSSHD denial of service
33RISCO
abrir
GitHub PoC3
Security Vulnerability Report: CVE-2025-24071 - Windows File Explorer Spoofing Vulnerability
CVE-2025-24071MEDIUM09 jun 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-26134CRITICALsob ataqueransomware09 jun 2025
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
anteriorpágina 252 / 2.534próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.