Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.836exploits catalogados
32.133CVEs com exploração pública
1.932testados em laboratório
8.156 exploits
VulnCheck XDB
client-side
CVE-2025-4123HIGH12 set 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-57819CRITICALsob ataque12 set 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHsob ataque11 set 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataque11 set 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-18935CRITICALsob ataqueransomware11 set 2025
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-29927CRITICAL11 set 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-31161CRITICALsob ataqueransomware10 set 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALsob ataque10 set 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALsob ataque10 set 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
VulnCheck XDB
local
CVE-2025-42957CRITICAL10 set 2025
Code Injection vulnerability in SAP S/4HANA (Private Cloud or On-Premise)
48RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALsob ataqueransomware10 set 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-11776HIGHsob ataque09 set 2025
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALsob ataqueransomware09 set 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-57819CRITICALsob ataque08 set 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM08 set 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-57819CRITICALsob ataque08 set 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir
VulnCheck XDB
local
CVE-2025-21333HIGHsob ataque08 set 2025
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RISCO
abrir
VulnCheck XDB
local
CVE-2025-7771HIGH07 set 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALsob ataque07 set 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-52970HIGH07 set 2025
A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.
56RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-54309CRITICALsob ataque06 set 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-58443CRITICAL06 set 2025
FOG's authentication bypass leads to full SQL DB dump
68RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-22515CRITICALsob ataqueransomware06 set 2025
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2008-4250CRITICALsob ataque06 set 2025
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2008-4250CRITICALsob ataque06 set 2025
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALsob ataqueransomware05 set 2025
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALsob ataque05 set 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALsob ataque05 set 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-5016404 set 2025
Apache Struts: File upload component had a directory traversal vulnerability
45RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-57819CRITICALsob ataque04 set 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir
anteriorpágina 64 / 272próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.