Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.324exploits catalogados
37.130CVEs com exploração pública
24.695testados em laboratório
15.330 exploits
GitHub PoC
onniio/CVE-2025-32463
CVE-2025-32463CRITICALsob ataque01 out 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC13
watchtowrlabs/watchTowr-vs-WatchGuard-CVE-2025-9242
CVE-2025-9242CRITICALsob ataque01 out 2025
WatchGuard Firebox iked Out of Bounds Write Vulnerability
100RISCO
abrir
GitHub PoC3
ticofookfook/CVE-2025-43300
CVE-2025-43300CRITICALsob ataque30 set 2025
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1
83RISCO
abrir
GitHub PoC1
A Rust implementation of the POC for CVE-2017-7269, targeting the WebDAV service in Microsoft Internet Information Services (IIS) 6.0.
CVE-2017-7269CRITICALsob ataque30 set 2025
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISCO
abrir
GitHub PoC
tno01/cve-2019-3396
CVE-2019-3396CRITICALsob ataqueransomware30 set 2025
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISCO
abrir
GitHub PoC
A Python exploit for CVE-2025-32463, a critical local privilege escalation vulnerability in the Sudo binary on Linux systems. This flaw allows local users to obtain root access by exploiting the --chroot option, which incorrectly uses /etc/nsswitch.conf from a user-controlled directory.
CVE-2025-32463CRITICALsob ataque30 set 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC1
This is POC for IOS 0click CVE-2025-43300
CVE-2025-43300CRITICALsob ataque30 set 2025
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1
83RISCO
abrir
GitHub PoC1
Detection for CVE-2025-41244
CVE-2025-41244HIGHsob ataque30 set 2025
VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)
71RISCO
abrir
GitHub PoC
Tnot123/cve-2017-9822
CVE-2017-9822HIGHsob ataqueransomware30 set 2025
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code e
100RISCO
abrir
GitHub PoC
Log4Shell (CVE-2021-44228) PoC
CVE-2021-44228CRITICALsob ataqueransomware29 set 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
victormbogu1/LetsDefend-SOC342-CVE-2025-53770-SharePoint-ToolShell-Auth-Bypass-andRCE-EventID-320
CVE-2025-53770CRITICALsob ataqueransomware29 set 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
CVE-2024-47051
CVE-2024-47051CRITICAL29 set 2025
Remote Code Execution & File Deletion in Asset Uploads
48RISCO
abrir
GitHub PoC
ethan-repo-lab4b6/CVE-2022-36537
CVE-2022-36537HIGHsob ataqueransomware28 set 2025
ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafte
100RISCO
abrir
GitHub PoC
kuyrathdaro/cve-2025-29927
CVE-2025-29927CRITICAL28 set 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
CVE-2025-10035_GoAnywhere Get RCE
CVE-2025-10035CRITICALsob ataqueransomware27 set 2025
Deserialization Vulnerability in GoAnywhere MFT's License Servlet
100RISCO
abrir
GitHub PoC
A Rust implementation of the POC for the CVE-2009-2265 exploit, targeting Adobe ColdFusion 8.
CVE-2009-226527 set 2025
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RISCO
abrir
GitHub PoC
0xDTC/CrushFTP-auth-bypass-CVE-2025-31161
CVE-2025-31161CRITICALsob ataqueransomware27 set 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISCO
abrir
GitHub PoC
This repository documents how deployment of Microsoft Defender for Endpoint on a Windows 11 device, including onboarding via local script, enabling device discovery, configuring Log4j2 detection (CVE-2021-44228), and validating incident response workflows.
CVE-2021-44228CRITICALsob ataqueransomware27 set 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC2
CVE-2024-6387 and more Checker and Exploiter - Reverse/Bind-Shell Support. education only
CVE-2024-6387HIGH26 set 2025
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir
GitHub PoC
Scans target to see if its vulnerable to CVE-2025-31161
CVE-2025-31161CRITICALsob ataqueransomware26 set 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISCO
abrir
GitHub PoC
Analyzing CVE-2023-36802 (mskssrv.sys) - object type confusion bug
CVE-2023-36802HIGHsob ataque26 set 2025
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC8
CVE-2025-8088 exploit C++ impl
CVE-2025-8088HIGHsob ataqueransomware25 set 2025
Path traversal vulnerability in WinRAR
93RISCO
abrir
GitHub PoC1
JS Archive List <= 6.1.5 - Unauthenticated SQL Injection
CVE-2025-54726CRITICAL25 set 2025
WordPress JS Archive List Plugin < 6.1.6 - SQL Injection Vulnerability
63RISCO
abrir
GitHub PoC
CVE-2025-49132
CVE-2025-49132CRITICAL25 set 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISCO
abrir
GitHub PoC
Example script demonstrating a weak PRNG, CVE-2008-0166
CVE-2008-016625 set 2025
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that ge
45RISCO
abrir
GitHub PoC6
CVE-2025-20352 SNMP Exposure Check (onesixtyone + parser)
CVE-2025-20352HIGHsob ataque25 set 2025
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Softwa
83RISCO
abrir
GitHub PoC
Microsoft HEIF Extension (msheif_store.dll) OOB-read
CVE-2025-62821CRITICAL25 set 2025
Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return suc
48RISCO
abrir
GitHub PoC
CVE-2017-5638- PoC
CVE-2017-5638CRITICALsob ataqueransomware25 set 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC2
An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter.
CVE-2025-56819CRITICAL24 set 2025
An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter.
63RISCO
abrir
GitHub PoC
CVE-2025-57176 - Siklu EtherHaul Series - Unauthenticated Arbitrary File Upload
CVE-2025-57176MEDIUM24 set 2025
On Ceragon Networks / Siklu Communication EtherHaul and MultiHaul Series microwave antennas before 2026-03-10, the rfpip
33RISCO
abrir
anteriorpágina 173 / 511próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.