Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.192exploits catalogados
37.765CVEs com exploração pública
24.695testados em laboratório
80.930 exploits
VulnCheck XDB
client-side
CVE-2025-8088HIGHsob ataqueransomware13 ago 2025
Path traversal vulnerability in WinRAR
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALsob ataque13 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC
CyprianAtsyor/ToolShell-CVE-2025-53770-SharePoint-Exploit-Lab-LetsDefend
CVE-2025-53770CRITICALsob ataqueransomware13 ago 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-24054MEDIUMsob ataque13 ago 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALsob ataque13 ago 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
GitHub PoC
PoC exploit for XWiki Remote Code Execution Vulnerability (CVE-2025-24893)
CVE-2025-24893CRITICALsob ataque13 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC
benguelmas/cve-2017-0143
CVE-2017-0143HIGHsob ataqueransomware13 ago 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
GitHub PoC
Proof of concept for the vulnerability CVE-2025-50428: Authenticated OS Command Injection in RaspAP
CVE-2025-50428CRITICAL13 ago 2025
In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script.
48RISCO
abrir
GitHub PoC
oob_entry tfp0 kernel exploit for armv7 iOS (iOS 3.0–10.3.4), using CVE-2023-32434. We will publish a write-up detailing the methods in the coming weeks. 🐙
CVE-2023-32434HIGHsob ataque13 ago 2025
An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11
83RISCO
abrir
VulnCheck XDB
client-side
CVE-2017-11882HIGHsob ataqueransomware13 ago 2025
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir
GitHub PoC7
CVE-2025-32433 PoC: Unauthenticated Remote Code Execution (RCE) in Erlang/OTP SSH. A proof-of-concept exploit for CVE-2025-32433
CVE-2025-32433CRITICALsob ataque13 ago 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
GitHub PoC
Dissecting CVEin Chrome
CVE-2025-5419HIGHsob ataque13 ago 2025
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially expl
71RISCO
abrir
GitHub PoC1
PoC of CVE-2025-47533 Clobber RCE
CVE-2024-47533CRITICAL13 ago 2025
Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes
63RISCO
abrir
GitHub PoC8
CVE-2024-47533 is a critical authentication bypass vulnerability in Cobbler (versions 3.0.0 to before 3.2.3 and 3.3.7) allowing unauthenticated remote code execution via the XMLRPC interface.
CVE-2024-47533CRITICAL12 ago 2025
Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes
63RISCO
abrir
GitHub PoC
Berisi 2 program C dari exploitDB untuk melakukan privillage eskalation untuk ubuntu 16.04
CVE-2017-1699512 ago 2025
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISCO
abrir
GitHub PoC
Program python untuk melakukan RCE pada drupal versi 7.56
CVE-2018-7600CRITICALsob ataqueransomware12 ago 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC1
PoC of CVE-2018-7600
CVE-2018-7600CRITICALsob ataqueransomware12 ago 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC1
Esse script explora a vulnerabilidade CVE-2025-20124 — uma falha de Java Deserialization no Cisco ISE (Identity Services Engine) que permite Remote Code Execution (RCE).
CVE-2025-20124CRITICAL12 ago 2025
Cisco Identity Services Engine Java Deserialization Vulnerability
53RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-25231HIGH12 ago 2025
Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to ga
61RISCO
abrir
GitHub PoC46
WinRAR 0day CVE-2025-8088 PoC RAR Archive
CVE-2025-8088HIGHsob ataqueransomware12 ago 2025
Path traversal vulnerability in WinRAR
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALsob ataqueransomware12 ago 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALsob ataqueransomware12 ago 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC1
00xCanelo/CVE-2024-47533-PoC
CVE-2024-47533CRITICAL12 ago 2025
Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes
63RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-53770CRITICALsob ataqueransomware12 ago 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir
Exploit-DB
projectworlds Online Admission System 1.0 - SQL Injection
CVE-2025-8471MEDIUMwebappsmultiple11 ago 2025
projectworlds Online Admission System adminlogin.php sql injection
33RISCO
abrir
Exploit-DB
JetBrains TeamCity 2023.11.4 - Authentication Bypass
CVE-2024-27198CRITICALsob ataqueransomwarewebappsmultiple11 ago 2025
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir
GitHub PoC
Update the old POC of CVE-2025-5777 Citrix NetScaler Memory leak
CVE-2025-5777CRITICALsob ataqueransomware11 ago 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-5777CRITICALsob ataqueransomware11 ago 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
Exploit-DB
atjiu pybbs 6.0.0 - Cross Site Scripting (XSS)
CVE-2025-8550MEDIUMwebappsmultiple11 ago 2025
atjiu pybbs list cross site scripting
33RISCO
abrir
GitHub PoC4
Python exploit for vsftpd 2.3.4 - Backdoor Command Execution
CVE-2011-252311 ago 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
anteriorpágina 285 / 2.698próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.