Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.008exploits catalogados
34.638CVEs com exploração pública
24.695testados em laboratório
76.008 exploits
GitHub PoC4
Eventin <= 4.0.26 - Missing Authorization to Unauthenticated Privilege Escalation
CVE-2025-47539CRITICAL17 mai 2025
WordPress Eventin plugin <= 4.0.26 - Privilege Escalation Vulnerability
75RISCO
abrir
VulnCheck XDB
local
CVE-2025-0288HIGH17 mai 2025
CVE-2025-0288
41RISCO
abrir
GitHub PoC
CyprianAtsyor/LetsDefend-CVE-2022-41082-Exploitation-Attempt
CVE-2022-41082HIGHsob ataqueransomware16 mai 2025
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC2
WordPress PSW Front-end Login &amp; Registration Plugin <= 1.12 is vulnerable to Broken Authentication
CVE-2025-47646CRITICAL16 mai 2025
WordPress PSW Front-end Login & Registration plugin <= 1.13 - Broken Authentication Vulnerability
68RISCO
abrir
GitHub PoC4
Ivanti EPMM Pre-Auth RCE Chain
CVE-2025-4428HIGHsob ataque16 mai 2025
Remote Code Execution
100RISCO
abrir
GitHub PoC2
GadaLuBau1337/CVE-2025-32583
CVE-2025-32583CRITICAL16 mai 2025
WordPress PDF 2 Post Plugin <= 2.4.0 - Remote Code Execution (RCE) vulnerability
53RISCO
abrir
GitHub PoC
PenguinCabinet/CVE-2024-4367-hands-on
CVE-2024-4367MEDIUM16 mai 2025
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir
Metasploit600
Invision Community 5.0.6 customCss RCE
CVE-2025-47916CRITICAL16 mai 2025
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The
85RISCO
abrir
GitHub PoC
Software Vulnerabilities and mitigation university course, to show exploitation and remediation caused by this vulnerability
CVE-2021-4034HIGHsob ataque16 mai 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataque16 mai 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-4428HIGHsob ataque16 mai 2025
Remote Code Execution
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-4427MEDIUMsob ataque15 mai 2025
Authentication Bypass
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-4428HIGHsob ataque15 mai 2025
Remote Code Execution
100RISCO
abrir
GitHub PoC
Analysis, detection, and mitigation of CVE-2023-20198 exploitation in Cisco IOS XE – QUB CSC3064 Network Security Assessment
CVE-2023-20198CRITICALsob ataque15 mai 2025
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHsob ataque15 mai 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC1
GadaLuBau1337/CVE-2025-3605
CVE-2025-3605CRITICAL15 mai 2025
Frontend Login and Registration Blocks <= 1.1.1 - Unauthenticated Privilege Escalation via Account Takeover
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-3605CRITICAL15 mai 2025
Frontend Login and Registration Blocks <= 1.1.1 - Unauthenticated Privilege Escalation via Account Takeover
63RISCO
abrir
GitHub PoC1
CVE-2025-4094 – WordPress Digits Plugin < 8.4.6.1 - OTP Authentication Bypass
CVE-2025-4094CRITICAL15 mai 2025
Digits < 8.4.6.1 - Auth Bypass via OTP Bruteforcing
53RISCO
abrir
GitHub PoC11
watchtowrlabs/watchTowr-vs-Ivanti-EPMM-CVE-2025-4427-CVE-2025-4428
CVE-2025-4427MEDIUMsob ataque15 mai 2025
Authentication Bypass
100RISCO
abrir
GitHub PoC2
WordPress Plugin Digits < 8.4.6.1 - OTP Auth Bypass via Bruteforce (CVE-2025-4094)
CVE-2025-4094CRITICAL15 mai 2025
Digits < 8.4.6.1 - Auth Bypass via OTP Bruteforcing
53RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALsob ataque15 mai 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC1
(CVE-2024-51793) Wordpress Plugin: Computer Repair Shop <= 3.8115 - Unauthenticated Arbitrary File Upload
CVE-2024-51793CRITICAL15 mai 2025
WordPress RepairBuddy plugin <= 3.8115 - Arbitrary File Upload vulnerability
48RISCO
abrir
GitHub PoC2
演示 Next.js 中的 Middleware 授權繞過漏洞 (CVE-2025-29927) 允許未經授權的用戶存取受保護的資訊。
CVE-2025-29927CRITICAL15 mai 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
VulnCheck XDB
local
CVE-2025-29824HIGHsob ataqueransomware14 mai 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC29
encrypter15/CVE-2025-29824
CVE-2025-29824HIGHsob ataqueransomware14 mai 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC
This contains single-file exploit for cve-2021-4034 which is a Polkit Local Privilege Escalation. Use it wisely!
CVE-2021-4034HIGHsob ataque14 mai 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-27636MEDIUM14 mai 2025
Apache Camel: Camel Message Header Injection via Improper Filtering
55RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-17530CRITICALsob ataque14 mai 2025
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataque14 mai 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
This contains single-file exploit for ProFTPd 1.3.5 mod_copy (CVE-2015-3306) vulnerability, especially for TryHackMe Kenobi Lab.
CVE-2015-330614 mai 2025
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISCO
abrir
anteriorpágina 261 / 2.534próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.