Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.409exploits catalogados
37.196CVEs com exploração pública
24.695testados em laboratório
15.347 exploits
GitHub PoC
punitdarji/roundcube-cve-2025-49113
CVE-2025-49113CRITICALsob ataque18 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
GitHub PoC
Exploit for Langflow AI Remote Code Execution (Unauthenticated)
CVE-2025-3248CRITICALsob ataqueransomware18 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
GitHub PoC17
CVE-2025-3248 Langflow RCE Exploit
CVE-2025-3248CRITICALsob ataqueransomware17 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
GitHub PoC
Kernel Pool Overflow Exploit targeting CVE-2021-31956
CVE-2021-31956HIGHsob ataque17 jun 2025
Windows NTFS Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC
EdouardosStav/CVE-2019-15107-RCE-WebMin
CVE-2019-15107CRITICALsob ataqueransomware17 jun 2025
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
GitHub PoC
PoC Exploit for the NTLM reflection SMB flaw.
CVE-2025-33073HIGHsob ataque17 jun 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RISCO
abrir
GitHub PoC
A hands-on vulnerability assessment and exploitation of a Windows 7 VM using the EternalBlue (CVE-2017-0143) exploit. Includes scanning, exploitation with Metasploit, post-exploitation, and remediation steps in a controlled lab environment.
CVE-2017-0143HIGHsob ataqueransomware17 jun 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
GitHub PoC
Explicação + Lab no THM
CVE-2025-49113CRITICALsob ataque17 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
GitHub PoC
A Python-based Exploit Script for CVE-2016-3088
CVE-2016-3088CRITICALsob ataque16 jun 2025
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISCO
abrir
GitHub PoC4
SolarWinds Serv-U 15.4.2 HF1 - Directory Traversal
CVE-2024-28995HIGHsob ataque15 jun 2025
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISCO
abrir
GitHub PoC
Exerrdev/CVE-2024-9264-Fixed
CVE-2024-9264CRITICAL15 jun 2025
Grafana SQL Expressions allow for remote code execution
85RISCO
abrir
GitHub PoC2
CrushFTP 11.3.1 - Authentication Bypass
CVE-2025-31161CRITICALsob ataqueransomware15 jun 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISCO
abrir
GitHub PoC3
CVE-2023-1698 exploit with golang
CVE-2023-1698CRITICAL15 jun 2025
WAGO: WBM Command Injection in multiple products
85RISCO
abrir
GitHub PoC2
Fortra GoAnywhere MFT 7.4.1 - Authentication Bypass
CVE-2024-0204CRITICAL15 jun 2025
Authentication Bypass in GoAnywhere MFT
85RISCO
abrir
GitHub PoC3
CVE-2024-4577.py
CVE-2024-4577CRITICALsob ataqueransomware15 jun 2025
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC8
This project is a research-oriented and educational simulation designed to demonstrate the concept of a sandbox escape vulnerability within Google Chrome (version 134.0.6998.177), leveraging improper handle , validation via Mojo IPC.
CVE-2025-2783HIGHsob ataque15 jun 2025
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
71RISCO
abrir
GitHub PoC
CVE-2014-6271(RCE) poc Exploit
CVE-2014-6271CRITICALsob ataque14 jun 2025
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC
MAHABUB122003/Atlassian-CVE-2022-26134
CVE-2022-26134CRITICALsob ataqueransomware14 jun 2025
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC
maqeel-git/CVE-2020-0796
CVE-2020-0796CRITICALsob ataqueransomware14 jun 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC1
LipeOzyy/CVE-2010-1872-BlazeDVD-SEH-Exploit
CVE-2010-187214 jun 2025
Cross-site scripting (XSS) vulnerability in cPlayer.php in FlashCard 2.6.5 and 3.0.1 allows remote attackers to inject a
23RISCO
abrir
GitHub PoC1
grass341/CVE-2022-37969
CVE-2022-37969HIGHsob ataqueransomware14 jun 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC2
Checks if your Chrome version is vulnerable to CVE-2025-5419, from the browser
CVE-2025-5419HIGHsob ataque14 jun 2025
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially expl
71RISCO
abrir
GitHub PoC1
This Python script checks for the presence of CVE-2024-40898, a critical vulnerability in Apache HTTP Server that may allow SSL/TLS certificate verification bypass under certain misconfigurations. It initiates an SSL connection to the target server and sends a HEAD request.
CVE-2024-40898CRITICAL14 jun 2025
Apache HTTP Server: SSRF with mod_rewrite in server/vhost context on Windows
48RISCO
abrir
GitHub PoC
Privilege Escalation on HTB "Poison" using PwnKit (CVE-2021-4034)
CVE-2021-4034HIGHsob ataqueransomware13 jun 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
CVE-2017-8291 CTF with docker and examples
CVE-2017-8291HIGHsob ataque13 jun 2025
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion
100RISCO
abrir
GitHub PoC1
CVE-2025-24071: NTLMv2 Hash Disclosure via .library-ms File
CVE-2025-24071MEDIUM13 jun 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
GitHub PoC717
PoC Exploit for the NTLM reflection SMB flaw.
CVE-2025-33073HIGHsob ataque13 jun 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RISCO
abrir
GitHub PoC1
Stored XSS in Nagios Log Server 2024R1.3.1
CVE-2025-29471HIGH13 jun 2025
Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code
41RISCO
abrir
GitHub PoC
CVE-2025-31650
CVE-2025-31650HIGH13 jun 2025
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
53RISCO
abrir
GitHub PoC
CVE-2025-31650
CVE-2025-31650HIGH13 jun 2025
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
53RISCO
abrir
anteriorpágina 202 / 512próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.