Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.270exploits catalogados
37.818CVEs com exploração pública
24.695testados em laboratório
81.003 exploits
GitHub PoC★ 1
🛡️ Proof of Concept (PoC) for CVE-2025-32463 - Local privilege escalation in sudo (versions 1.9.14 to 1.9.17). This exploit abuses the --chroot option and a malicious nsswitch.conf to execute arbitrary code as root. ⚠️ For educational and authorized testing only.
CVE-2025-32463CRITICALsob ataque04 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗
GitHub PoC
A Writeup for Sleirsgoevy's version of the Exploit Implementation of CVE-2018-4386 by Fire30 called Bad_Hoist
CVE-2018-4386—03 jul 2025
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
23RISCO
abrir ↗
GitHub PoC
Mr.CIA's manual patching guide for CVE-2025-32463 (Sudo local privilege escalation) on Kali Linux and Ubuntu WSL.
CVE-2025-32463CRITICALsob ataque03 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗
GitHub PoC
CVE-2025-32462 exploit code
CVE-2025-32462LOW03 jul 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RISCO
abrir ↗
GitHub PoC★ 7
This script checks for the presence of the **CVE-2025-20281** vulnerability in Cisco Identity Services Engine (ISE) and ISE-PIC, which allows **unauthenticated remote code execution (RCE)** as root due to insufficient input validation in a specific API.
CVE-2025-20281CRITICALsob ataque03 jul 2025
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-49596CRITICAL03 jul 2025
MCP Inspector proxy server lacks authentication between the Inspector client and proxy
75RISCO
abrir ↗
GitHub PoC★ 25
PoC for CVE-2025-32463 - Sudo chroot Elevation of Privilege Vulnerability
CVE-2025-32463CRITICALsob ataque03 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗
GitHub PoC
0xAkarii/CVE-2025-32463
CVE-2025-32463CRITICALsob ataque03 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗
GitHub PoC★ 2
Sudo Local Privilege Escalation CVE-2025-32463 (Best For Cases Where the shell is not stable to spawn a new root shell)
CVE-2025-32463CRITICALsob ataque03 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗
GitHub PoC
CVE-2024-48061 Langflow vulnerable to remote code execution. Poc
CVE-2024-48061CRITICAL03 jul 2025
langflow <=1.0.18 is vulnerable to Remote Code Execution (RCE) as any component provided the code functionality and the
48RISCO
abrir ↗
GitHub PoC★ 1
CVE-2025-32462 Exploit
CVE-2025-32462LOW03 jul 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RISCO
abrir ↗
GitHub PoC★ 11
RARLAB WinRAR Directory Traversal Remote Code Execution
CVE-2025-6218HIGHsob ataque03 jul 2025
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
93RISCO
abrir ↗
GitHub PoC★ 6
Exploit for CVE-2025-6019
CVE-2025-6018HIGH03 jul 2025
Pam-config: lpe from unprivileged to allow_active in pam
41RISCO
abrir ↗
GitHub PoC
yaleman/cve-2025-24813-poc
CVE-2025-24813CRITICALsob ataque03 jul 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2025-6019HIGH03 jul 2025
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2025-6218HIGHsob ataque03 jul 2025
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
93RISCO
abrir ↗
VulnCheck XDB
local
CVE-2025-32463CRITICALsob ataque03 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2025-32463CRITICALsob ataque03 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2025-32463CRITICALsob ataque03 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2012-1823CRITICALsob ataque03 jul 2025
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2025-32463CRITICALsob ataque03 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALsob ataque03 jul 2025
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir ↗
GitHub PoC★ 1
iamgithubber/CVE-2025-6018-19-exploit
CVE-2025-6018HIGH03 jul 2025
Pam-config: lpe from unprivileged to allow_active in pam
41RISCO
abrir ↗
VulnCheck XDB
local
CVE-2025-32463CRITICALsob ataque03 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗
GitHub PoC★ 1
san8383/CVE-2025-32463
CVE-2025-32463CRITICALsob ataque03 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗
GitHub PoC★ 5
Multi-host, multi-port scanner and auditor for CVE-2025-6543-affected NetScaler devices. Supports SNMP and SSH enumeration with optional CSV reporting and exploit stubs.
CVE-2025-6543CRITICALsob ataque03 jul 2025
Memory overflow vulnerability leading to unintended control flow and Denial of Service
83RISCO
abrir ↗
GitHub PoC
MCP-Inspector-vulncheck is a Python script that checks if an MCP Inspector server is vulnerable to CVE-2025-49596. It tests whether the /sse endpoint responds to unauthenticated requests, indicating a potential security flaw. The script is simple to use and provides clear output on whether the target server is likely vulnerable or patched.
CVE-2025-49596CRITICAL03 jul 2025
MCP Inspector proxy server lacks authentication between the Inspector client and proxy
75RISCO
abrir ↗
GitHub PoC★ 12
A easy sudo poc by cryingn.
CVE-2025-32462LOW03 jul 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RISCO
abrir ↗
Exploit-DB
Wing FTP Server 7.4.3 - Unauthenticated Remote Code Execution (RCE)
CVE-2025-47812CRITICALsob ataqueremotemultiple02 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir ↗
GitHub PoC★ 3
Exploit for Local Privilege Escalation in Sudo via Malicious nsswitch.conf with sudo -R. (CVE-2025-32463)
CVE-2025-32463CRITICALsob ataque02 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗
← anteriorpágina 310 / 2.701próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.