Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.930exploits catalogados
37.572CVEs com exploração pública
24.695testados em laboratório
80.842 exploits
GitHub PoC
euxem/Analyse-faille-de-s-curit-CVE-2025-6018-CVE-2025-6019
CVE-2025-6018HIGH30 nov 2025
Pam-config: lpe from unprivileged to allow_active in pam
41RISCO
abrir
GitHub PoC11
Outlook exploitation
CVE-2024-21413CRITICALsob ataque30 nov 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL30 nov 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-21413CRITICALsob ataque30 nov 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
sec-dojo-com/CVE-2020-24186
CVE-2020-24186CRITICAL29 nov 2025
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RISCO
abrir
GitHub PoC
CVE-2018-10933 - LibSSH - Authentication Bypass
CVE-2018-10933CRITICAL29 nov 2025
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC
xi0onamdev/WinRAR-CVE-2025-8088-Exploitation-Toolkit
CVE-2025-8088HIGHsob ataqueransomware29 nov 2025
Path traversal vulnerability in WinRAR
93RISCO
abrir
GitHub PoC1
m2hcz/CVE-2025-6440-Poc-Exploit
CVE-2025-6440CRITICAL29 nov 2025
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-1663CRITICAL29 nov 2025
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
85RISCO
abrir
GitHub PoC
KylVGoi/cve-2019-1663
CVE-2019-1663CRITICAL29 nov 2025
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
85RISCO
abrir
GitHub PoC
AndrewMas99/CVE-2019-11043-Vulnerability
CVE-2019-11043HIGHsob ataqueransomware28 nov 2025
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC
Modified the CVE-2024-25600
CVE-2024-25600CRITICAL28 nov 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-13315CRITICAL28 nov 2025
Unauthenticated log access in Twonky Server
75RISCO
abrir
GitHub PoC
Exploit - CVE-2023-26360
CVE-2023-26360HIGHsob ataque28 nov 2025
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-26360HIGHsob ataque28 nov 2025
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RISCO
abrir
GitHub PoC
MagentaBear/CVE-2019-11043-Vulnerability
CVE-2019-11043HIGHsob ataqueransomware28 nov 2025
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL28 nov 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir
GitHub PoC
CVE-2010-2075
CVE-2010-207528 nov 2025
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RISCO
abrir
VulnCheck XDB
info-leak
CVE-2025-2011HIGH28 nov 2025
Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection via 's' Parameter
68RISCO
abrir
GitHub PoC4
Secure expression evaluator - Drop-in replacement for expr-eval without CVE-2025-12735 vulnerability
CVE-2025-12735CRITICAL27 nov 2025
CVE-2025-12735
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALsob ataqueransomware27 nov 2025
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir
GitHub PoC1
Proof-of-concept exploit for CVE-2025-55315 (.NET HTTP Request Smuggling). Demonstrates how improperly parsed chunked encoding lets attackers smuggle requests past proxies and load balancers in vulnerable ASP.NET Core/Kestrel servers.
CVE-2025-55315CRITICAL27 nov 2025
ASP.NET Security Feature Bypass Vulnerability
60RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-8088HIGHsob ataqueransomware27 nov 2025
Path traversal vulnerability in WinRAR
93RISCO
abrir
GitHub PoC1
CVE-2017-0144
CVE-2017-0144HIGHsob ataqueransomware27 nov 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALsob ataque27 nov 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2017-7921CRITICALsob ataque27 nov 2025
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALsob ataque27 nov 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-2198027 nov 2025
The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with n
23RISCO
abrir
GitHub PoC
TeamCity 2023.05.3 - CVE-2023-42793 - Create username administrator.
CVE-2023-42793CRITICALsob ataqueransomware27 nov 2025
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir
GitHub PoC
Chroot Privilege Escalation
CVE-2025-32463CRITICALsob ataque27 nov 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
anteriorpágina 248 / 2.695próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.