Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.930exploits catalogados
37.572CVEs com exploração pública
24.695testados em laboratório
80.842 exploits
VulnCheck XDB
initial-access
CVE-2017-1254213 out 2025
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RISCO
abrir
GitHub PoC1
Reverse shell for CVE-2024-28397.
CVE-2024-28397MEDIUM12 out 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISCO
abrir
VulnCheck XDB
local
CVE-2023-29360HIGHsob ataque12 out 2025
Microsoft Streaming Service Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC
Scottman625/CVE-2023-29360
CVE-2023-29360HIGHsob ataque12 out 2025
Microsoft Streaming Service Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC1
PoC of "DEF CON 32 - SQL Injection Isn't Dead Smuggling Queries at the Protocol Level - Paul Gerste"
CVE-2024-27304CRITICAL12 out 2025
pgx SQL Injection via Protocol Message Size Overflow
48RISCO
abrir
GitHub PoC1
Reverse shell for CVE-2024-28397.
CVE-2024-28397MEDIUM12 out 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISCO
abrir
GitHub PoC7
Privilege escalation to root using sudo chroot, NO NEED for gcc installed.
CVE-2025-32463CRITICALsob ataque12 out 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC
Exploit Title: Node.JS - 'node-serialize' Remote Code Execution (2), Version: 0.0.4, CVE: CVE-2017-5941
CVE-2017-594112 out 2025
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-4328711 out 2025
An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default,
43RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-11371HIGHsob ataque11 out 2025
Gladinet CentreStack and TrioFox Local File Inclusion Flaw
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-46982HIGH11 out 2025
Cache Poisoning in next.js
53RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-61882CRITICALsob ataqueransomware10 out 2025
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integratio
100RISCO
abrir
GitHub PoC3
CVE-2024-38856: Apache OFBiz remote code execution Scanner & Exploit
CVE-2024-38856HIGHsob ataque10 out 2025
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-2539HIGH10 out 2025
File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Read
56RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-5947CRITICAL10 out 2025
Service Finder Bookings <= 6.0 - Authentication Bypass via User Switch Cookie
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-38856HIGHsob ataque10 out 2025
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISCO
abrir
GitHub PoC
CVE-2024-32113-Apache-OFBiz<18.12.13-Exploit
CVE-2024-32113CRITICALsob ataque09 out 2025
Apache OFBiz: Path traversal leading to RCE
100RISCO
abrir
GitHub PoC
- Vulnerable: sudo 1.9.14, 1.9.15, 1.9.16, 1.9.17 - Patched in: sudo 1.9.17p1 and later - Legacy versions older than 1.9.14 are not affected, as they don't support the --chroot option.
CVE-2025-32463CRITICALsob ataque09 out 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC
Enviroment and Nuclei template to test CVE-2025-32463
CVE-2025-32463CRITICALsob ataque09 out 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2025-49844CRITICAL09 out 2025
Redis Lua Use-After-Free may lead to remote code execution
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALsob ataqueransomware09 out 2025
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir
GitHub PoC
syorik/CVE-2023-42793
CVE-2023-42793CRITICALsob ataqueransomware09 out 2025
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir
GitHub PoC2
CVE-2023-21554 PoC
CVE-2023-21554CRITICAL09 out 2025
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
85RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-8088HIGHsob ataqueransomware09 out 2025
Path traversal vulnerability in WinRAR
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-32113CRITICALsob ataque09 out 2025
Apache OFBiz: Path traversal leading to RCE
100RISCO
abrir
GitHub PoC
foregenix/CVE-2023-39143
CVE-2023-39143CRITICAL09 out 2025
PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete
85RISCO
abrir
Metasploit600
SmarterTools SmarterMail GUID File Upload Vulnerability
CVE-2025-52691CRITICALsob ataqueransomware09 out 2025
Upload Arbitrary Files
100RISCO
abrir
GitHub PoC
sudo --chroot exploit
CVE-2025-32463CRITICALsob ataque08 out 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC1
Reproduction and fix of the CVE-2025-29927 vulnerability.
CVE-2025-29927CRITICAL08 out 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-10353CRITICAL08 out 2025
Missing Authorization vulnerability in Melis Platform
63RISCO
abrir
anteriorpágina 263 / 2.695próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.