Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.008exploits catalogados
34.638CVEs com exploração pública
24.695testados em laboratório
75.902 exploits
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM21 abr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware21 abr 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC1
CVE-2025-30208 vite file read nuclei template
CVE-2025-30208MEDIUM21 abr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-28987CRITICALsob ataque21 abr 2025
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RISCO
abrir
GitHub PoC2
mouseos/cve-2019-2215_SH-M08
CVE-2019-2215HIGHsob ataque20 abr 2025
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISCO
abrir
GitHub PoC
Bug Chain XSS (CVE-2020-35730 and CVE-2023-43770) to SQLi (CVE-2021-44026)
CVE-2020-35730MEDIUMsob ataque20 abr 2025
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attack
75RISCO
abrir
GitHub PoC2
nmap scripts for vuln cve-2020-0796 & cve-2019-7238 & cve2019-11580 & cve2017-6327
CVE-2020-0796CRITICALsob ataqueransomware20 abr 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC
Bug Chain XSS (CVE-2020-35730 and CVE-2023-43770) to SQLi (CVE-2021-44026)
CVE-2021-44026CRITICALsob ataque20 abr 2025
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
90RISCO
abrir
GitHub PoC2
nmap scripts for vuln cve-2020-0796 & cve-2019-7238 & cve2019-11580 & cve2017-6327
CVE-2019-7238CRITICALsob ataque20 abr 2025
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RISCO
abrir
GitHub PoC
Bug Chain XSS (CVE-2020-35730 and CVE-2023-43770) to SQLi (CVE-2021-44026)
CVE-2023-43770MEDIUMsob ataque20 abr 2025
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with craft
75RISCO
abrir
VulnCheck XDB
client-side
CVE-2023-43770MEDIUMsob ataque20 abr 2025
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with craft
75RISCO
abrir
VulnCheck XDB
client-side
CVE-2020-35730MEDIUMsob ataque20 abr 2025
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attack
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALsob ataque20 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-7238CRITICALsob ataque20 abr 2025
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RISCO
abrir
VulnCheck XDB
local
CVE-2019-2215HIGHsob ataque20 abr 2025
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISCO
abrir
VulnCheck XDB
client-side
CVE-2021-44026CRITICALsob ataque20 abr 2025
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
90RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-3102HIGH20 abr 2025
SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
78RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-8425CRITICAL19 abr 2025
WooCommerce Ultimate Gift Card <= 2.9.2 - Unauthenticated Arbitrary File Upload
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALsob ataque19 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHsob ataque19 abr 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALsob ataque19 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
GitHub PoC
pruthuraut/CVE-2025-28121
CVE-2025-28121MEDIUM19 abr 2025
code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" p
33RISCO
abrir
GitHub PoC
JenmrR/Node.js-CVE-2024-39943
CVE-2024-39943CRITICAL19 abr 2025
rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote auth
60RISCO
abrir
GitHub PoC6
0xPThree/cve-2025-32433
CVE-2025-32433CRITICALsob ataque19 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
GitHub PoC
Go-based exploit for CVE-2025-32433
CVE-2025-32433CRITICALsob ataque19 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
GitHub PoC7
CVE-2023-38408 SSH Vulnerability Scanner & PoC
CVE-2023-38408CRITICAL19 abr 2025
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISCO
abrir
GitHub PoC1
cybermads/CVE-2020-0796
CVE-2020-0796CRITICALsob ataqueransomware19 abr 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
Exploit-DB
FoxCMS 1.2.5 - Remote Code Execution (RCE)
CVE-2025-29306CRITICALwebappsmultiple19 abr 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISCO
abrir
VulnCheck XDB
client-side
CVE-2023-38408CRITICAL19 abr 2025
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2020-0796CRITICALsob ataqueransomware19 abr 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
anteriorpágina 270 / 2.531próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.