Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
24.466 exploits
Exploit-DB
PHP CGI Module 8.3.4 - Remote Code Execution (RCE)
CVE-2024-4577CRITICALsob ataqueransomwarewebappsphp15 jun 2025
Argument Injection in PHP-CGI
100RISCO
abrir
Exploit-DB
PCMan FTP Server 2.0.7 - Buffer Overflow
CVE-2025-4255MEDIUMremotewindows15 jun 2025
PCMan FTP Server RMD Command buffer overflow
33RISCO
abrir
Exploit-DB
Parrot and DJI variants Drone OSes - Kernel Panic Exploit
CVE-2025-37928localmultiple15 jun 2025
dm-bufio: don't schedule in atomic context
23RISCO
abrir
Exploit-DB
Microsoft Excel Use After Free - Local Code Execution
CVE-2025-27751HIGHlocalwindows15 jun 2025
Microsoft Excel Remote Code Execution Vulnerability
41RISCO
abrir
Exploit-DB
Windows File Explorer Windows 10 Pro x64 - TAR Extraction
CVE-2025-24071MEDIUMremotewindows13 jun 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
Exploit-DB
Freefloat FTP Server 1.0 - Remote Buffer Overflow
CVE-2025-5548MEDIUMremotemultiple13 jun 2025
FreeFloat FTP Server NOOP Command buffer overflow
38RISCO
abrir
Exploit-DB
Roundcube 1.6.10 - Remote Code Execution (RCE)
CVE-2025-49113CRITICALsob ataquewebappsmultiple13 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
Exploit-DB
TightVNC 2.8.83 - Control Pipe Manipulation
CVE-2024-42049CRITICALlocalmultiple09 jun 2025
TightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pipe via a network connection.
48RISCO
abrir
Exploit-DB
Microsoft Windows 11 Version 24H2 Cross Device Service - Elevation of Privilege
CVE-2025-24076HIGHlocalwindows09 jun 2025
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
41RISCO
abrir
Exploit-DB
Laravel Pulse 1.3.1 - Arbitrary Code Injection
CVE-2024-55661HIGHwebappsphp09 jun 2025
Laravel Pulse Allows Remote Code Execution via Unprotected Query Method
46RISCO
abrir
Exploit-DB
ProSSHD 1.2 20090726 - Denial of Service (DoS)
CVE-2024-0725MEDIUMremotewindows09 jun 2025
ProSSHD denial of service
33RISCO
abrir
Exploit-DB
Grandstream GSD3710 1.0.11.13 - Stack Overflow
CVE-2022-2025CRITICALremotemultiple05 jun 2025
Grandstream GSD3710 Stack-based Buffer Overflow
48RISCO
abrir
Exploit-DB
Microsoft Windows Server 2025 JScript Engine - Remote Code Execution (RCE)
CVE-2025-30397HIGHsob ataqueremotewindows05 jun 2025
Scripting Engine Memory Corruption Vulnerability
76RISCO
abrir
Exploit-DB
macOS LaunchDaemon iOS 17.2 - Privilege Escalation
CVE-2025-24085CRITICALsob ataquelocalmacos05 jun 2025
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, i
83RISCO
abrir
Exploit-DB
CloudClassroom PHP Project 1.0 - SQL Injection
CVE-2025-45542HIGHwebappsphp05 jun 2025
SQL injection vulnerability in the registrationform endpoint of CloudClassroom-PHP-Project v1.0. The pass parameter is v
41RISCO
abrir
Exploit-DB
Apache Tomcat 10.1.39 - Denial of Service (DoS)
CVE-2025-31650HIGHremotemultiple05 jun 2025
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
53RISCO
abrir
Exploit-DB
SolarWinds Serv-U 15.4.2 HF1 - Directory Traversal
CVE-2024-28995HIGHsob ataqueremotemultiple29 mai 2025
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISCO
abrir
Exploit-DB
WordPress Digits Plugin 8.4.6.1 - Authentication Bypass via OTP Bruteforcing
CVE-2025-4094CRITICALwebappsmultiple29 mai 2025
Digits < 8.4.6.1 - Auth Bypass via OTP Bruteforcing
53RISCO
abrir
Exploit-DB
Windows File Explorer Windows 11 (23H2) - NTLM Hash Disclosure
CVE-2025-24071MEDIUMremotewindows29 mai 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
Exploit-DB
Fortra GoAnywhere MFT 7.4.1 - Authentication Bypass
CVE-2024-0204CRITICALremotemultiple29 mai 2025
Authentication Bypass in GoAnywhere MFT
85RISCO
abrir
Exploit-DB
Automic Agent 24.3.0 HF4 - Privilege Escalation
CVE-2025-4971HIGHremotemultiple29 mai 2025
Broadcom Automic Automation Agent Unix privilege escalation
41RISCO
abrir
Exploit-DB
Campcodes Online Hospital Management System 1.0 - SQL Injection
CVE-2025-5298MEDIUMwebappsmultiple29 mai 2025
Campcodes Online Hospital Management System betweendates-detailsreports.php sql injection
33RISCO
abrir
Exploit-DB
Grandstream GSD3710 1.0.11.13 - Stack Buffer Overflow
CVE-2022-2070CRITICALremotemultiple25 mai 2025
Grandstream GSD3710 Stack-based Buffer Overflow
48RISCO
abrir
Exploit-DB
WordPress User Registration & Membership Plugin 4.1.2 - Authentication Bypass
CVE-2025-2594HIGHwebappsmultiple25 mai 2025
User Registration & Membership < 4.1.3 - Authentication Bypass
41RISCO
abrir
Exploit-DB
ABB Cylon Aspect Studio 3.08.03 - Binary Planting
CVE-2024-13946HIGHlocalmultiple25 mai 2025
Binary Planting / LoadLibrary DLL's not Signed
41RISCO
abrir
Exploit-DB
Java-springboot-codebase 1.1 - Arbitrary File Read
CVE-2025-46822HIGHwebappsjava25 mai 2025
Unauthenticated Arbitrary File Read via Absolute Path
56RISCO
abrir
Exploit-DB
CrushFTP 11.3.1 - Authentication Bypass
CVE-2025-31161CRITICALsob ataqueransomwareremotemultiple18 mai 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISCO
abrir
Exploit-DB
Invision Community 5.0.6 - Remote Code Execution (RCE)
CVE-2025-47916CRITICALremotemultiple18 mai 2025
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The
85RISCO
abrir
Exploit-DB
Zyxel USG FLEX H series uOS 1.31 - Privilege Escalation
CVE-2025-1731HIGHlocalmultiple18 mai 2025
An incorrect permission assignment vulnerability in the PostgreSQL commands of the Zyxel USG FLEX H series uOS firmware
41RISCO
abrir
Exploit-DB
Kentico Xperience 13.0.178 - Cross Site Scripting (XSS)
CVE-2025-32370HIGHwebappsmultiple13 mai 2025
Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uplo
41RISCO
abrir
anteriorpágina 10 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.