Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.270exploits catalogados
37.818CVEs com exploração pública
24.695testados em laboratório
81.003 exploits
Exploit-DB
WP Publications WordPress Plugin 1.2 - Stored XSS
CVE-2024-11605MEDIUMwebappsmultiple16 jul 2025
WP Publications <= 1.2 - Admin+ Stored XSS
33RISCO
abrir ↗
GitHub PoC
Kalidas-7/CVE-2019-9053
CVE-2019-9053—16 jul 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir ↗
Exploit-DB
NodeJS 24.x - Path Traversal
CVE-2025-27210HIGHremotenodejs16 jul 2025
An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CO
46RISCO
abrir ↗
Exploit-DB
PivotX 3.0.0 RC3 - Remote Code Execution (RCE)
CVE-2025-52367MEDIUMwebappsmultiple16 jul 2025
Cross Site Scripting vulnerability in PivotX CMS v.3.0.0 RC 3 allows a remote attacker to execute arbitrary code via the
48RISCO
abrir ↗
GitHub PoC★ 5
An in-depth analysis of CVE 2023 38408, a critical OpenSSH vulnerability, including technical background, exploitation in controlled environments, and mitigation strategies.
CVE-2023-38408CRITICAL16 jul 2025
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISCO
abrir ↗
Exploit-DB
Langflow 1.2.x - Remote Code Execution (RCE)
CVE-2025-3248CRITICALsob ataqueransomwarewebappsmultiple16 jul 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir ↗
GitHub PoC
rpc.py 0.6.0 - Remote Code Execution (RCE)
CVE-2022-35411—16 jul 2025
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header i
35RISCO
abrir ↗
Exploit-DB
White Star Software Protop 4.4.2-2024-11-27 - Local File Inclusion (LFI)
CVE-2025-44177HIGHwebappsmultiple16 jul 2025
A directory traversal vulnerability was discovered in White Star Software Protop version 4.4.2-2024-11-27, specifically
56RISCO
abrir ↗
GitHub PoC
Exploit for php-cgi
CVE-2024-4577CRITICALsob ataqueransomware16 jul 2025
Argument Injection in PHP-CGI
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALsob ataqueransomware16 jul 2025
Argument Injection in PHP-CGI
100RISCO
abrir ↗
GitHub PoC★ 2
(PoC) CVE-2025-27210, a precise Path Traversal vulnerability affecting Node.js applications running on Microsoft Windows. This vulnerability leverages the specific way Windows handles reserved device file names
CVE-2025-27210HIGH16 jul 2025
An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CO
46RISCO
abrir ↗
GitHub PoC
nguyentranbaotran/cve-2025-48384-poc
CVE-2025-48384HIGHsob ataque16 jul 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir ↗
Exploit-DB
Keras 2.15 - Remote Code Execution (RCE)
CVE-2025-1550HIGHremotepython16 jul 2025
Arbitrary Code Execution via Crafted Keras Config for Model Loading
41RISCO
abrir ↗
GitHub PoC
CVE-2025-53833
CVE-2025-53833CRITICAL16 jul 2025
LaRecipe is vulnerable to Server-Side Template Injection attacks
63RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2025-48384HIGHsob ataque16 jul 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-32432CRITICALsob ataque16 jul 2025
Craft CMS Allows Remote Code Execution
100RISCO
abrir ↗
Exploit-DB
SugarCRM 14.0.0 - SSRF/Code Injection
CVE-2024-58258HIGHwebappsmultiple16 jul 2025
SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can
46RISCO
abrir ↗
Exploit-DB
Microsoft Brokering File System Windows 11 Version 22H2 - Elevation of Privilege
CVE-2025-49677HIGHlocalwindows16 jul 2025
Microsoft Brokering File System Elevation of Privilege Vulnerability
41RISCO
abrir ↗
Exploit-DB
Microsoft Graphics Component Windows 11 Pro (Build 26100+) - Local Elevation of Privileges
CVE-2025-49744HIGHlocalwindows16 jul 2025
Windows Graphics Component Elevation of Privilege Vulnerability
41RISCO
abrir ↗
VulnCheck XDB
local
CVE-2025-32463CRITICALsob ataque16 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-5777CRITICALsob ataqueransomware16 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2025-32463CRITICALsob ataque16 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2025-32463CRITICALsob ataque15 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-5777CRITICALsob ataqueransomware15 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-5777CRITICALsob ataqueransomware15 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-25257CRITICALsob ataque15 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISCO
abrir ↗
GitHub PoC★ 1
PoC for CVE-2025-25257, a critical unauthenticated SQL injection in FortiWeb. Exploits SQLi via the Authorization header to write a webshell and gain RCE. No login required. Fully automated.
CVE-2025-25257CRITICALsob ataque15 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISCO
abrir ↗
GitHub PoC
CVE-2025-5777 (CitrixBleed 2) - [Citrix NetScaler ADC] [Citrix Gateway]
CVE-2025-5777CRITICALsob ataqueransomware15 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir ↗
GitHub PoC★ 3
An advanced, powerful, and easy-to-use tool designed to detect and exploit CVE-2025-5777 (CitrixBleed 2). This script not only identifies the vulnerability but also helps in demonstrating its impact by parsing human-readable information from the memory leak.
CVE-2025-5777CRITICALsob ataqueransomware15 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2018-12613—15 jul 2025
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISCO
abrir ↗
← anteriorpágina 301 / 2.701próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.