Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

72.018exploits catalogados
32.219CVEs com exploração pública
1.932testados em laboratório
13.334 exploits
GitHub PoC1
Chocapikk/CVE-2025-32463-lab
CVE-2025-32463CRITICALsob ataque06 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC
Citrix Bleed 2 PoC Scanner (CVE-2025-5777)
CVE-2025-5777CRITICALsob ataqueransomware06 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
GitHub PoC9
A PoC exploit for CVE-2025-32463 - Sudo Privilege Escalation
CVE-2025-32463CRITICALsob ataque06 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC
Ruby on Rails Web Console Exploit (CVE-2015-3224)
CVE-2015-322406 jul 2025
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-
50RISCO
abrir
GitHub PoC3
cve-2025-32462' demo
CVE-2025-32462LOW05 jul 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RISCO
abrir
GitHub PoC
CVE-2025-32463
CVE-2025-32463CRITICALsob ataque05 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC
Royall-Researchers/CVE-2024-9264
CVE-2024-9264CRITICAL05 jul 2025
Grafana SQL Expressions allow for remote code execution
85RISCO
abrir
GitHub PoC
Grafana RCE
CVE-2024-9264CRITICAL05 jul 2025
Grafana SQL Expressions allow for remote code execution
85RISCO
abrir
GitHub PoC
Papercut Vulnerability, Affected Versions are PaperCut MF or NG version 8.0 or later (excluding patched versions) on all OS platforms.
CVE-2023-27350CRITICALsob ataqueransomware05 jul 2025
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir
GitHub PoC
CitrixBleed2 poc
CVE-2025-5777CRITICALsob ataqueransomware05 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
GitHub PoC3
Memory disclosure vulnerability in Citrix NetScaler ADC and Gateway when configured as a Gateway (VPN virtual server, ICA proxy, CVPN, RDP Proxy).
CVE-2025-5777CRITICALsob ataqueransomware05 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
GitHub PoC
gmh5225/CVE-2025-6554
CVE-2025-6554HIGHsob ataque05 jul 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RISCO
abrir
GitHub PoC2
gmh5225/CVE-2025-6554-2
CVE-2025-6554HIGHsob ataque05 jul 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RISCO
abrir
GitHub PoC2
ibrahmsql/discourse-CVE-2021-41163
CVE-2021-41163CRITICAL05 jul 2025
RCE via malicious SNS subscription payload
53RISCO
abrir
GitHub PoC3
ibrahmsql/CVE-2021-41163
CVE-2021-41163CRITICAL05 jul 2025
RCE via malicious SNS subscription payload
53RISCO
abrir
GitHub PoC
Royall-Researchers/CVE-2025-24071
CVE-2025-24071MEDIUM05 jul 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
GitHub PoC
r0otk3r/CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware05 jul 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC8
🔓 Local privilege escalation PoC for CVE-2025-32462 (sudo -h bypass) – gain root via misconfigured sudoers
CVE-2025-32462LOW04 jul 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RISCO
abrir
GitHub PoC1
CVE-2025-41646 - Critical Authentication bypass
CVE-2025-41646CRITICAL04 jul 2025
RevPi Webstatus application is vulnerable to an authentication bypass
75RISCO
abrir
GitHub PoC2
POC to exploit WordPress 5.6-5.7 (PHP 8+) Authenticated XXE Injection.
CVE-2021-29447HIGH04 jul 2025
WordPress Authenticated XXE attack when installation is running PHP 8
63RISCO
abrir
GitHub PoC
Remote Command Execution exploit for Wing FTP Server (CVE-2025-47812)
CVE-2025-47812CRITICALsob ataque04 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir
GitHub PoC1
🛡️ Proof of Concept (PoC) for CVE-2025-32463 — Local privilege escalation in sudo (versions 1.9.14 to 1.9.17). This exploit abuses the --chroot option and a malicious nsswitch.conf to execute arbitrary code as root. ⚠️ For educational and authorized testing only.
CVE-2025-32463CRITICALsob ataque04 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC15
# CVE-2025-32463 – Sudo EoP Exploit (PoC) with precompiled .so
CVE-2025-32463CRITICALsob ataque04 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC
Privilege escalation exploit for CVE-2025-32463 using a malicious NSS module injected via sudo -R. This version creates a stealth payload called illdeed, granting root access through a controlled chroot environment.
CVE-2025-32463CRITICALsob ataque04 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC
Exploit for CVE-2024-4040 – Authentication bypass in CrushFTP via CrushAuth cookie and AWS-style header spoofing. Stealthy Python PoC with secure token generation, SSL bypass, and improved output.
CVE-2024-4040CRITICALsob ataque04 jul 2025
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISCO
abrir
GitHub PoC1
CitrixBleed-2 (CVE-2025-5777) – proof-of-concept exploit for NetScaler ADC/Gateway “memory bleed”
CVE-2025-5777CRITICALsob ataqueransomware04 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
GitHub PoC
CVE-2023-46747-RCE PoC
CVE-2023-46747CRITICALsob ataqueransomware04 jul 2025
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RISCO
abrir
GitHub PoC5
Unauthenticated Remote Code Execution exploit for CVE-2025-20281 in Cisco ISE ERS API. Execute commands or launch reverse shells as root — no authentication required.
CVE-2025-20281CRITICALsob ataque04 jul 2025
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
MCP-Inspector-vulncheck is a Python script that checks if an MCP Inspector server is vulnerable to CVE-2025-49596. It tests whether the /sse endpoint responds to unauthenticated requests, indicating a potential security flaw. The script is simple to use and provides clear output on whether the target server is likely vulnerable or patched.
CVE-2025-49596CRITICAL03 jul 2025
MCP Inspector proxy server lacks authentication between the Inspector client and proxy
75RISCO
abrir
GitHub PoC5
Multi-host, multi-port scanner and auditor for CVE-2025-6543-affected NetScaler devices. Supports SNMP and SSH enumeration with optional CSV reporting and exploit stubs.
CVE-2025-6543CRITICALsob ataque03 jul 2025
Memory overflow vulnerability leading to unintended control flow and Denial of Service
78RISCO
abrir
anteriorpágina 139 / 445próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.