Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.930exploits catalogados
37.572CVEs com exploração pública
24.695testados em laboratório
80.842 exploits
VulnCheck XDB
infoleak
CVE-2022-22536CRITICALsob ataque31 out 2025
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RISCO
abrir
GitHub PoC1
adrianmafandy/CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware31 out 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC25
Proof-of-concept for CVE-2025-49844
CVE-2025-49844CRITICAL31 out 2025
Redis Lua Use-After-Free may lead to remote code execution
85RISCO
abrir
Exploit-DB
Flowise 3.0.4 - Remote Code Execution (RCE)
CVE-2025-59528CRITICALwebappsmultiple31 out 2025
Flowise has Remote Code Execution vulnerability
85RISCO
abrir
GitHub PoC
Fast, socket-level scanner for detecting CVE-2022-22536 in SAP ICM or Web Dispatcher instances. Performs request smuggling tests with a crafted MPI-desync payload. Supports batch scanning IP:PORT targets via plain text files.
CVE-2022-22536CRITICALsob ataque31 out 2025
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RISCO
abrir
GitHub PoC
Y2F05p2w/CVE-2025-24893
CVE-2025-24893CRITICALsob ataque31 out 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC1
shiro 路径穿越
CVE-2010-386331 out 2025
Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the
35RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-64095CRITICAL31 out 2025
DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-50603CRITICALsob ataque30 out 2025
An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutraliza
100RISCO
abrir
GitHub PoC1
WooCommerce Designer Pro 1.9.26 - Arbitrary File Upload
CVE-2025-6440CRITICAL30 out 2025
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-6440CRITICAL30 out 2025
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISCO
abrir
GitHub PoC
Technical examination of CVE-2025-32463 by Muhammed Kaya.
CVE-2025-32463CRITICALsob ataque30 out 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
Metasploit600
WordPress King Addons for Elementor Unauthenticated Privilege Escalation to RCE
CVE-2025-8489CRITICAL30 out 2025
King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor 24.12.92 - 51.1.14 - Unauthenticated Privilege Escalation
43RISCO
abrir
GitHub PoC2
A combined POC for CVE-2021-31955, CVE-2015-4077, and CVE-2015-5736
CVE-2021-31955MEDIUMsob ataque29 out 2025
Windows Kernel Information Disclosure Vulnerability
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALsob ataque29 out 2025
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC2
A combined POC for CVE-2021-31955, CVE-2015-4077, and CVE-2015-5736
CVE-2015-407729 out 2025
The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient b
23RISCO
abrir
Exploit-DB
Casdoor 2.95.0 - Cross-Site Request Forgery (CSRF)
CVE-2023-34927webappsmultiple29 out 2025
Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-passwo
23RISCO
abrir
VulnCheck XDB
local
CVE-2021-31955MEDIUMsob ataque29 out 2025
Windows Kernel Information Disclosure Vulnerability
85RISCO
abrir
GitHub PoC
TranDongA3/Simulation_CVE-2024-46256
CVE-2024-46256CRITICAL29 out 2025
A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add
48RISCO
abrir
GitHub PoC1
A Metasploit module for CVE-2024-35374
CVE-2024-35374CRITICAL28 out 2025
Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-26360HIGHsob ataque28 out 2025
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALsob ataqueransomware28 out 2025
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALsob ataqueransomware28 out 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2018-999528 out 2025
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir
GitHub PoC95
POC of CVE-2018-9995 written in Rust.
CVE-2018-999528 out 2025
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir
Metasploit600
Taiga tribe_gig authenticated unserialize remote code execution
CVE-2025-62368CRITICAL28 out 2025
Taiga Authenticated Remote Code Execution
43RISCO
abrir
GitHub PoC
ict519 assignment
CVE-2023-38831HIGHsob ataqueransomware28 out 2025
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC
Demo of CVE-2021-44228 Log4Shell.
CVE-2021-44228CRITICALsob ataqueransomware28 out 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
Exploit for Remote Code Execution in ColdFusion 2021 (CVE-2023-26360)
CVE-2023-26360HIGHsob ataque28 out 2025
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-59287CRITICALsob ataque28 out 2025
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISCO
abrir
anteriorpágina 258 / 2.695próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.