Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

72.018exploits catalogados
32.219CVEs com exploração pública
1.932testados em laboratório
13.334 exploits
GitHub PoC
Critical Sudo Vulnerabilities Let Local Users Gain Root Access on Linux, Impacting Major Distros
CVE-2025-32462LOW11 jul 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RISCO
abrir
GitHub PoC
r0otk3r/CVE-2024-10915
CVE-2024-10915CRITICAL11 jul 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir
GitHub PoC
This repository contains Detailed explanation and working poc for Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution.
CVE-2014-6287CRITICALsob ataque11 jul 2025
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir
GitHub PoC
hackmelocal/CVE-2025-49113-Simulation
CVE-2025-49113CRITICALsob ataque11 jul 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
GitHub PoC
CVE-2025-6554 PoC
CVE-2025-6554HIGHsob ataque10 jul 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RISCO
abrir
GitHub PoC
Exploit for CVE-2025-32023
CVE-2025-32023HIGH10 jul 2025
Redis allows out of bounds writes in hyperloglog commands leading to RCE
41RISCO
abrir
GitHub PoC98
watchtowrlabs/watchTowr-vs-FortiWeb-CVE-2025-25257
CVE-2025-25257CRITICALsob ataque10 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISCO
abrir
GitHub PoC18
CVE-2025-6218 is a directory traversal vulnerability in WinRAR that allows an attacker to place files outside the intended extraction directory when a user extracts a specially crafted
CVE-2025-6218HIGHsob ataque10 jul 2025
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
93RISCO
abrir
GitHub PoC
r0otk3r/CVE-2024-27954
CVE-2024-27954CRITICAL10 jul 2025
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability
85RISCO
abrir
GitHub PoC
r0otk3r/CVE-2024-25600
CVE-2024-25600CRITICAL10 jul 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir
GitHub PoC30
CVE-2025-5777 Citrix NetScaler Memory Leak Exploit (CitrixBleed 2)
CVE-2025-5777CRITICALsob ataqueransomware10 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
GitHub PoC
Citrix NetScaler Memory Leak PoC
CVE-2025-5777CRITICALsob ataqueransomware10 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
GitHub PoC
altm4n/cve-2025-48384-hub
CVE-2025-48384HIGHsob ataque10 jul 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC
altm4n/cve-2025-48384
CVE-2025-48384HIGHsob ataque10 jul 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC14
This report outlines a structured VAPT engagement focusing on PCI DSS compliance, SMB service enumeration, and exploitation of CVE-2017-0144 (EternalBlue) on a Windows 10 machine within a finance-oriented infrastructure.
CVE-2017-0144HIGHsob ataqueransomware10 jul 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
GitHub PoC
CVE-2025-48384
CVE-2025-48384HIGHsob ataque10 jul 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC
Praktische Demonstration der Log4Shell-Sicherheitslücke (CVE-2021-44228)
CVE-2021-44228CRITICALsob ataqueransomware10 jul 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
greatyy/CVE-2025-48384-p
CVE-2025-48384HIGHsob ataque10 jul 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC
漏洞测试
CVE-2025-48384HIGHsob ataque10 jul 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC
ppd520/CVE-2025-48384
CVE-2025-48384HIGHsob ataque09 jul 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC
fishyyh/CVE-2025-48384-POC
CVE-2025-48384HIGHsob ataque09 jul 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC
kallydev/cve-2025-48384-hook
CVE-2025-48384HIGHsob ataque09 jul 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC
CitrixBleed2 powershell version
CVE-2025-5777CRITICALsob ataqueransomware09 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
GitHub PoC
for CVE-2025-48384 test
CVE-2025-48384HIGHsob ataque09 jul 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC21
PoC for CVE-2025-48384
CVE-2025-48384HIGHsob ataque09 jul 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC
liamg/CVE-2025-48384-submodule
CVE-2025-48384HIGHsob ataque09 jul 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC6
WordPress Pie Register ≤ 3.7.1.4 - Admin Privilege Escalation (Unauthenticated)
CVE-2025-34077CRITICAL09 jul 2025
WordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCE
63RISCO
abrir
GitHub PoC1
ghostn4444/POC-CVE-2025-6554
CVE-2025-6554HIGHsob ataque09 jul 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RISCO
abrir
GitHub PoC
rpgsec/Roundcube-CVE-2024-42008-POC
CVE-2024-42008CRITICAL09 jul 2025
A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7
60RISCO
abrir
GitHub PoC1
0xb0rn3/CVE-2025-32463-EXPLOIT
CVE-2025-32463CRITICALsob ataque09 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
anteriorpágina 137 / 445próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.