Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.270exploits catalogados
37.818CVEs com exploração pública
24.695testados em laboratório
81.003 exploits
GitHub PoC★ 11
This repository contains a Proof of Concept (PoC) exploit for the **CVE-2025-47175** vulnerability found in Microsoft PowerPoint. The vulnerability is a Use-After-Free (UAF) bug that allows an attacker to execute arbitrary code by tricking a user into opening a specially crafted PPTX file.
CVE-2025-47175HIGH02 jul 2025
Microsoft PowerPoint Remote Code Execution Vulnerability
41RISCO
abrir ↗
GitHub PoC★ 3
Wing FTP Server RCE via Lua Injection
CVE-2025-47812CRITICALsob ataque02 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir ↗
GitHub PoC★ 477
Local Privilege Escalation to Root via Sudo chroot in Linux
CVE-2025-32463CRITICALsob ataque02 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALsob ataque02 jul 2025
Unauthenticated Command Injection
100RISCO
abrir ↗
GitHub PoC★ 4
SysMancer/CVE-2025-32463
CVE-2025-32463CRITICALsob ataque02 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗
GitHub PoC
zhaduchanhzz/CVE-2025-32463_POC
CVE-2025-32463CRITICALsob ataque02 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗
GitHub PoC★ 1
CVE-2025-6934 POC
CVE-2025-6934CRITICAL02 jul 2025
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RISCO
abrir ↗
VulnCheck XDB
local
CVE-2025-32463CRITICALsob ataque02 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2025-32463CRITICALsob ataque02 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗
GitHub PoC
neko205-mx/CVE-2025-32463_Exploit
CVE-2025-32463CRITICALsob ataque02 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗
Exploit-DB
Moodle 4.4.0 - Authenticated Remote Code Execution
CVE-2024-43425HIGHwebappsmultiple02 jul 2025
Moodle: remote code execution via calculated question types
78RISCO
abrir ↗
VulnCheck XDB
local
CVE-2025-32463CRITICALsob ataque02 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2025-32463CRITICALsob ataque02 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗
VulnCheck XDB
local
CVE-2025-32463CRITICALsob ataque02 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗
Exploit-DB
gogs 0.13.0 - Remote Code Execution (RCE)
CVE-2024-39930CRITICALremotemultiple02 jul 2025
The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code
48RISCO
abrir ↗
Exploit-DB
Wing FTP Server 7.4.3 - Unauthenticated Remote Code Execution (RCE)
CVE-2025-47812CRITICALsob ataqueremotemultiple02 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir ↗
GitHub PoC
robbert1978/CVE-2025-32463_POC
CVE-2025-32463CRITICALsob ataque02 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗
GitHub PoC
B1gN0Se/Tomcat-CVE-2025-31650
CVE-2025-31650HIGH02 jul 2025
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
53RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2021-41773HIGHsob ataqueransomware02 jul 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗
Exploit-DB
Microsoft SharePoint 2019 - NTLM Authentication
CVE-2025-47166HIGHremotewindows02 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
46RISCO
abrir ↗
GitHub PoC★ 3
Exploit for Local Privilege Escalation in Sudo via Malicious nsswitch.conf with sudo -R. (CVE-2025-32463)
CVE-2025-32463CRITICALsob ataque02 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗
GitHub PoC★ 1
MAVRICK-1/cve-2024-23113-test-env
CVE-2024-23113CRITICALsob ataque02 jul 2025
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-47812CRITICALsob ataque02 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-49493MEDIUM01 jul 2025
Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.
48RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-47812CRITICALsob ataque01 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir ↗
GitHub PoC
POC script for CVE-2025-32462 a vulnerability in sudo
CVE-2025-32462LOW01 jul 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RISCO
abrir ↗
GitHub PoC★ 10
End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full memory and network forensic analysis.
CVE-2025-32463CRITICALsob ataque01 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗
GitHub PoC★ 2
WordPress Custom Login And Signup Widget Plugin <= 1.0 is vulnerable to Arbitrary Code Execution
CVE-2025-49029CRITICAL01 jul 2025
WordPress Custom Login And Signup Widget plugin <= 1.0 - Arbitrary Code Execution vulnerability
63RISCO
abrir ↗
GitHub PoC★ 8
Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution in WonderCMS. This tool uses PentestMonkey's PHP reverse shell script as the payload
CVE-2023-41425MEDIUM01 jul 2025
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISCO
abrir ↗
GitHub PoC★ 1
Proof of concept of CVE-2025-20282, the perfect 10.
CVE-2025-20282CRITICAL01 jul 2025
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
68RISCO
abrir ↗
← anteriorpágina 311 / 2.701próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.