Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.064exploits catalogados
37.667CVEs com exploração pública
24.695testados em laboratório
81.064 exploits
VulnCheck XDB
local
CVE-2025-32463CRITICALsob ataque30 set 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC
Tnot123/cve-2017-9822
CVE-2017-9822HIGHsob ataqueransomware30 set 2025
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code e
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-7269CRITICALsob ataque30 set 2025
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-43300CRITICALsob ataque30 set 2025
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1
83RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-43300CRITICALsob ataque30 set 2025
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1
83RISCO
abrir
GitHub PoC1
A Rust implementation of the POC for CVE-2017-7269, targeting the WebDAV service in Microsoft Internet Information Services (IIS) 6.0.
CVE-2017-7269CRITICALsob ataque30 set 2025
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-41646CRITICAL30 set 2025
RevPi Webstatus application is vulnerable to an authentication bypass
75RISCO
abrir
GitHub PoC
A Python exploit for CVE-2025-32463, a critical local privilege escalation vulnerability in the Sudo binary on Linux systems. This flaw allows local users to obtain root access by exploiting the --chroot option, which incorrectly uses /etc/nsswitch.conf from a user-controlled directory.
CVE-2025-32463CRITICALsob ataque30 set 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC
tno01/cve-2019-3396
CVE-2019-3396CRITICALsob ataqueransomware30 set 2025
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-1974CRITICAL30 set 2025
ingress-nginx admission controller RCE escalation
85RISCO
abrir
GitHub PoC1
This is POC for IOS 0click CVE-2025-43300
CVE-2025-43300CRITICALsob ataque30 set 2025
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1
83RISCO
abrir
GitHub PoC3
ticofookfook/CVE-2025-43300
CVE-2025-43300CRITICALsob ataque30 set 2025
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1
83RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALsob ataqueransomware29 set 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALsob ataqueransomware29 set 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
GitHub PoC
Log4Shell (CVE-2021-44228) PoC
CVE-2021-44228CRITICALsob ataqueransomware29 set 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
victormbogu1/LetsDefend-SOC342-CVE-2025-53770-SharePoint-ToolShell-Auth-Bypass-andRCE-EventID-320
CVE-2025-53770CRITICALsob ataqueransomware29 set 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-36604HIGH29 set 2025
Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('
68RISCO
abrir
GitHub PoC
CVE-2024-47051
CVE-2024-47051CRITICAL29 set 2025
Remote Code Execution & File Deletion in Asset Uploads
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-36537HIGHsob ataqueransomware28 set 2025
ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafte
100RISCO
abrir
GitHub PoC
ethan-repo-lab4b6/CVE-2022-36537
CVE-2022-36537HIGHsob ataqueransomware28 set 2025
ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafte
100RISCO
abrir
GitHub PoC
kuyrathdaro/cve-2025-29927
CVE-2025-29927CRITICAL28 set 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
CVE-2025-10035_GoAnywhere Get RCE
CVE-2025-10035CRITICALsob ataqueransomware27 set 2025
Deserialization Vulnerability in GoAnywhere MFT's License Servlet
100RISCO
abrir
GitHub PoC
This repository documents how deployment of Microsoft Defender for Endpoint on a Windows 11 device, including onboarding via local script, enabling device discovery, configuring Log4j2 detection (CVE-2021-44228), and validating incident response workflows.
CVE-2021-44228CRITICALsob ataqueransomware27 set 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
A Rust implementation of the POC for the CVE-2009-2265 exploit, targeting Adobe ColdFusion 8.
CVE-2009-226527 set 2025
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2009-226527 set 2025
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-31161CRITICALsob ataqueransomware27 set 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-4606CRITICAL27 set 2025
Sala - Startup & SaaS WordPress Theme <= 1.1.4 - Unauthenticated Privilege Escalation via Password Reset/Account Takeover
48RISCO
abrir
GitHub PoC
0xDTC/CrushFTP-auth-bypass-CVE-2025-31161
CVE-2025-31161CRITICALsob ataqueransomware27 set 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISCO
abrir
VulnCheck XDB
local
CVE-2024-0582HIGH26 set 2025
Kernel: io_uring: page use-after-free vulnerability via buffer ring mmap
46RISCO
abrir
VulnCheck XDB
local
CVE-2023-36802HIGHsob ataque26 set 2025
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
76RISCO
abrir
anteriorpágina 268 / 2.703próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.