Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.270exploits catalogados
37.818CVEs com exploração pública
24.695testados em laboratório
81.003 exploits
VulnCheck XDB
initial-access
CVE-2025-25257CRITICALsob ataque15 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-49493MEDIUM14 jul 2025
Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.
48RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-25257CRITICALsob ataque14 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-7340CRITICAL14 jul 2025
HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 - Unauthenticated Arbitrary File Upload
48RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-52488HIGH14 jul 2025
DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input
68RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-29927CRITICAL14 jul 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-44137HIGH14 jul 2025
MapTiler Tileserver-php v2.0 is vulnerable to Directory Traversal. The renderTile function within tileserver.php is resp
56RISCO
abrir ↗
GitHub PoC★ 2
Royal Elementor Addons - Unauthenticated Remote Code Execution
CVE-2023-5360—14 jul 2025
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RISCO
abrir ↗
VulnCheck XDB
local
CVE-2025-32463CRITICALsob ataque14 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2025-44136CRITICAL14 jul 2025
MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an e
63RISCO
abrir ↗
GitHub PoC
mheranco/CVE-2025-44136
CVE-2025-44136CRITICAL14 jul 2025
MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an e
63RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-48827CRITICAL14 jul 2025
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
85RISCO
abrir ↗
GitHub PoC★ 1
This repository contains a proof-of-concept exploit for CVE-2025-48827, a critical authentication bypass vulnerability affecting vBulletin 5.0.0–5.7.5 and 6.0.0–6.0.3 when running on PHP 8.1 or later. The vulnerability allows unauthenticated attackers to invoke protected API methods remotely.
CVE-2025-48827CRITICAL14 jul 2025
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
85RISCO
abrir ↗
GitHub PoC★ 7
HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 - Unauthenticated Arbitrary File Upload
CVE-2025-7340CRITICAL14 jul 2025
HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 - Unauthenticated Arbitrary File Upload
48RISCO
abrir ↗
GitHub PoC
CVE-2025-29927 PoC | Auth Bypass Exploit | Python Tool using httpx | Middleware Vulnerability | Ethical Hacking Toolkit
CVE-2025-29927CRITICAL14 jul 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-5360—14 jul 2025
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RISCO
abrir ↗
GitHub PoC★ 48
Privilege escalation to root using sudo chroot, NO NEED for gcc installed.
CVE-2025-32463CRITICALsob ataque14 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗
GitHub PoC★ 2
This repository includes the code and files needed to test and execute a PoC for CVE-2025-41656
CVE-2025-41656CRITICAL14 jul 2025
Pilz: Missing Authentication in Node-RED integration
53RISCO
abrir ↗
GitHub PoC
Armand2002/Exploit-CVE-2025-1974-Lab
CVE-2025-1974CRITICAL14 jul 2025
ingress-nginx admission controller RCE escalation
85RISCO
abrir ↗
GitHub PoC
CVE-2020-35848 impacts Cockpit-CMS v1.7 due to unsafe handling of user inputs in authentication mechanisms, leading to remote code execution. This lab is built for CTF players and bug bounty learners to simulate real-world exploitation workflows including token extraction, password reset, and flag capture.
CVE-2020-35848—13 jul 2025
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.
60RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-34085—13 jul 2025
20RISCO
abrir ↗
GitHub PoC
JayVillain/Scan-CVE-2025-6058
CVE-2025-6058CRITICAL13 jul 2025
WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload
63RISCO
abrir ↗
GitHub PoC★ 2
🚀 Exploit for Moodle 4.4.0 Authenticated RCE (CVE-2024-43425) — run commands remotely ⚡
CVE-2024-43425HIGH13 jul 2025
Moodle: remote code execution via calculated question types
78RISCO
abrir ↗
GitHub PoC★ 14
A detailed walkthrough of TryHackMe's Billing room exploiting CVE-2023-30258 and escalating via fail2ban misconfig
CVE-2023-30258CRITICAL13 jul 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISCO
abrir ↗
GitHub PoC
CVE-2025-32023
CVE-2025-32023HIGH13 jul 2025
Redis allows out of bounds writes in hyperloglog commands leading to RCE
41RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-31125MEDIUMsob ataque13 jul 2025
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
90RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-22457CRITICALsob ataqueransomware13 jul 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7
100RISCO
abrir ↗
GitHub PoC★ 8
Wazuh 8.4 CVE-2025-24016
CVE-2025-24016CRITICALsob ataque13 jul 2025
Remote code execution in Wazuh server
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-24016CRITICALsob ataque13 jul 2025
Remote code execution in Wazuh server
100RISCO
abrir ↗
GitHub PoC★ 14
A detailed walkthrough of Billing room exploiting CVE-2023-30258 and escalating via fail2ban misconfig
CVE-2023-30258CRITICAL13 jul 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISCO
abrir ↗
← anteriorpágina 302 / 2.701próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.