Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.930exploits catalogados
37.572CVEs com exploração pública
24.695testados em laboratório
80.842 exploits
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALsob ataque27 nov 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
GitHub PoC
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
CVE-2025-32433CRITICALsob ataque27 nov 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
GitHub PoC6
XXE through a specific endpoint /geoserver/wms operation GetMap - Geoserver
CVE-2025-58360HIGHsob ataque27 nov 2025
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RISCO
abrir
GitHub PoC
CVE-2025-58360
CVE-2025-58360HIGHsob ataque27 nov 2025
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RISCO
abrir
GitHub PoC1
CVE-2017-0144
CVE-2017-0144HIGHsob ataqueransomware27 nov 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2017-7921CRITICALsob ataque27 nov 2025
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-43798HIGHsob ataque27 nov 2025
Grafana path traversal
100RISCO
abrir
GitHub PoC2
ExtremeUday/CVE-2025-2945-pgAdmin4-Authenticated-RCE-PoC-
CVE-2025-2945CRITICAL26 nov 2025
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALsob ataque26 nov 2025
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-29306CRITICAL26 nov 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISCO
abrir
GitHub PoC
OS command injection vulnerability in Samba that received the maximum possible CVSS v3.1 score of 10.0
CVE-2025-10230CRITICAL26 nov 2025
Samba: command injection in wins server hook script
60RISCO
abrir
GitHub PoC
CVE-2025-6389
CVE-2025-6389CRITICAL26 nov 2025
Sneeit Framework <= 8.3 - Unauthenticated Remote Code Execution in sneeit_articles_pagination_callback
85RISCO
abrir
GitHub PoC
yunus-a1i/veeam-cve-2023-27532-mock
CVE-2023-27532HIGHsob ataqueransomware26 nov 2025
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database
93RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-58360HIGHsob ataque26 nov 2025
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RISCO
abrir
GitHub PoC
Path Traversal Apache HTTP Server 2.4.49/2.4.50
CVE-2021-41773HIGHsob ataqueransomware26 nov 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-41773HIGHsob ataqueransomware26 nov 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-15949HIGHsob ataque26 nov 2025
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios
100RISCO
abrir
GitHub PoC3
PoC RCE exploit for Nostromo nhttpd ≤ 1.9.6
CVE-2019-16278CRITICALsob ataque26 nov 2025
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISCO
abrir
Metasploit300
GeoServer WMS GetMap XXE Arbitrary File Read
CVE-2025-58360HIGHsob ataque25 nov 2025
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RISCO
abrir
GitHub PoC
Proof-of-Concept (PoC) for CVE-2025-62168 👾
CVE-2025-62168CRITICAL25 nov 2025
Squid vulnerable to information disclosure via authentication credential leakage in error handling
75RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-6554HIGHsob ataque25 nov 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
76RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-6389CRITICAL25 nov 2025
Sneeit Framework <= 8.3 - Unauthenticated Remote Code Execution in sneeit_articles_pagination_callback
85RISCO
abrir
VulnCheck XDB
local
CVE-2022-37969HIGHsob ataqueransomware25 nov 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC31
aklnjakln/CVE-2025-6554
CVE-2025-6554HIGHsob ataque25 nov 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
76RISCO
abrir
GitHub PoC2
Tutorial of CVE-2022-37969 with focus on the methodology of Kernel exploitation, not CVE's internal causes
CVE-2022-37969HIGHsob ataqueransomware25 nov 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC2
Reproducing CVE-2024-29943 for Windows, based on https://github.com/bjrjk/CVE-2024-29943
CVE-2024-29943CRITICAL25 nov 2025
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds chec
53RISCO
abrir
GitHub PoC
CVE-2025-61757
CVE-2025-61757CRITICALsob ataque25 nov 2025
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported vers
100RISCO
abrir
GitHub PoC1
A easy poc for CVE-2024-12084.
CVE-2024-12084CRITICAL24 nov 2025
Rsync: heap buffer overflow in rsync due to improper checksum length handling
70RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-36845CRITICALsob ataque24 nov 2025
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISCO
abrir
GitHub PoC
CVE-2012-2122 MySQL Authentication Bypass Home Lab
CVE-2012-212224 nov 2025
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x befor
60RISCO
abrir
anteriorpágina 249 / 2.695próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.