Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.192exploits catalogados
37.765CVEs com exploração pública
24.695testados em laboratório
80.930 exploits
VulnCheck XDB
local
CVE-2013-3900MEDIUMsob ataque18 ago 2025
WinVerifyTrust Signature Validation Vulnerability
75RISCO
abrir
Exploit-DB
Tenda AC20 16.03.08.12 - Command Injection
CVE-2025-9090MEDIUMremotemultiple18 ago 2025
Tenda AC20 Telnet Service telnet websFormDefine command injection
38RISCO
abrir
GitHub PoC1
The CVE-2024-28397 vulnerability affects versions of js2py up to v0.74, a Python library that allows JavaScript code to be executed within the Python interpreter.
CVE-2024-28397MEDIUM18 ago 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISCO
abrir
GitHub PoC5
CVE PoC
CVE-2013-3900MEDIUMsob ataque18 ago 2025
WinVerifyTrust Signature Validation Vulnerability
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL18 ago 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISCO
abrir
GitHub PoC2
Proof of concept for CVE-2020-36708
CVE-2020-36708CRITICAL18 ago 2025
Epsilon Framework Themes (Various Versions) - Function Injection
75RISCO
abrir
Exploit-DB
Microsoft Windows 10.0.19045 - NTLMv2 Hash Disclosure
CVE-2025-50154MEDIUMremotewindows18 ago 2025
Microsoft Windows File Explorer Spoofing Vulnerability
45RISCO
abrir
VulnCheck XDB
local
CVE-2025-7771HIGH18 ago 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RISCO
abrir
GitHub PoC3
Proof-of-concept exploit for CVE-2025-4334, a privilege escalation vulnerability in the Simple User Registration WordPress plugin (<= 6.3), allowing unauthenticated attackers to create administrator accounts.
CVE-2025-4334CRITICAL18 ago 2025
Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation
63RISCO
abrir
GitHub PoC5
This vulnerability arises from incomplete sandboxing in js2py, where crafted JavaScript can traverse Python’s internal object model and access dangerous classes like subprocess.Popen, leading to arbitrary command execution.
CVE-2024-28397MEDIUM17 ago 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-32778CRITICAL17 ago 2025
Web-Check allows command Injection via Unvalidated URL in Screenshot API
68RISCO
abrir
GitHub PoC
Demo of CVE-2025-29927 for secure programming class
CVE-2025-29927CRITICAL17 ago 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
Proof-of-Concept exploit script for Xdebug 2.5.5 and earlier versions (CVE-2015-10141).
CVE-2015-10141CRITICAL17 ago 2025
Xdebug Remote Debugger Unauthenticated OS Command Execution
63RISCO
abrir
GitHub PoC2
Proof-of-Concept for CVE-2025-8088 vulnerability in WinRAR (path traversal via ADS)
CVE-2025-8088HIGHsob ataqueransomware17 ago 2025
Path traversal vulnerability in WinRAR
93RISCO
abrir
GitHub PoC3
PoC exploit for CVE-2025-32778: command injection in Web-Check OSINT tool
CVE-2025-32778CRITICAL17 ago 2025
Web-Check allows command Injection via Unvalidated URL in Screenshot API
68RISCO
abrir
GitHub PoC1
Command Injection in Tenda AC20 16.03.08.12 (/goform/telnet)
CVE-2025-9090MEDIUM17 ago 2025
Tenda AC20 Telnet Service telnet websFormDefine command injection
38RISCO
abrir
GitHub PoC
CVE-2019-12185 - eLabFTW 1.8.5 Python3 Exploit POC
CVE-2019-1218517 ago 2025
eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. This may
28RISCO
abrir
GitHub PoC21
Detection for CVE-2025-8875 & CVE-2025-8876
CVE-2025-8875CRITICALsob ataque17 ago 2025
Insecure Deserialization Vulnerability
78RISCO
abrir
GitHub PoC
shoucheng3/spring-cloud__spring-cloud-config_CVE-2020-5410_2-1-8-RELEASE
CVE-2020-5410HIGHsob ataque17 ago 2025
Directory Traversal with spring-cloud-config-server
100RISCO
abrir
GitHub PoC
shoucheng3/apache__rocketmq_CVE-2023-33246_5-1-0
CVE-2023-33246CRITICALsob ataque17 ago 2025
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISCO
abrir
GitHub PoC
shoucheng3/spring-projects__spring-security_CVE-2011-2732_2-0-6-RELEASE
CVE-2011-273217 ago 2025
CRLF injection vulnerability in the logout functionality in VMware SpringSource Spring Security before 2.0.7 and 3.0.x b
23RISCO
abrir
GitHub PoC
shoucheng3/apache__rocketmq_CVE-2023-37582_4-9-6
CVE-2023-37582CRITICAL16 ago 2025
Apache RocketMQ: Possible remote code execution when using the update configuration function
85RISCO
abrir
VulnCheck XDB
infoleak
CVE-2018-742216 ago 2025
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RISCO
abrir
GitHub PoC1
Exploit for CVE-2018-7422: Local File Inclusion in WordPress Plugin Site Editor 1.1.1 [T1574.008]
CVE-2018-742216 ago 2025
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RISCO
abrir
GitHub PoC
shoucheng3/apache__myfaces_CVE-2011-4367_2-0-11
CVE-2011-436716 ago 2025
Multiple directory traversal vulnerabilities in MyFaces JavaServer Faces (JSF) in Apache MyFaces Core 2.0.x before 2.0.1
35RISCO
abrir
GitHub PoC
shoucheng3/xwiki__xwiki-rendering_CVE-2023-37908_14-10-3
CVE-2023-37908CRITICAL16 ago 2025
org.xwiki.rendering:xwiki-rendering-xml Improper Neutralization of Invalid Characters in Identifiers in Web Pages vulnerability
48RISCO
abrir
GitHub PoC1
Ash1996x/CVE-2025-50154-Aggressor-Script
CVE-2025-50154MEDIUM16 ago 2025
Microsoft Windows File Explorer Spoofing Vulnerability
45RISCO
abrir
GitHub PoC36
Exploit systems using older WinRAR without knowing their username (unlike other projects)
CVE-2025-8088HIGHsob ataqueransomware16 ago 2025
Path traversal vulnerability in WinRAR
93RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-8088HIGHsob ataqueransomware16 ago 2025
Path traversal vulnerability in WinRAR
93RISCO
abrir
GitHub PoC5
CVE-2025-6934 is a critical vulnerability in the WordPress Opal Estate Pro plugin (<= 1.7.5) that allows unauthenticated attackers to create new administrator accounts through the plugin’s insecure AJAX registration process.
CVE-2025-6934CRITICAL16 ago 2025
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RISCO
abrir
anteriorpágina 283 / 2.698próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.