Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.366exploits catalogados
37.872CVEs com exploração pública
24.695testados em laboratório
81.064 exploits
Exploit-DB
freeSSHd 1.0.9 - Denial of Service (DoS)
CVE-2024-0723MEDIUMremotewindows26 jun 2025
freeSSHd denial of service
33RISCO
abrir ↗
Exploit-DB
OneTrust SDK 6.33.0 - Denial Of Service (DoS)
CVE-2024-57708MEDIUMremotelinux26 jun 2025
An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __
33RISCO
abrir ↗
VulnCheck XDB
local
CVE-2019-5736—25 jun 2025
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALsob ataqueransomware25 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir ↗
GitHub PoC
hdgokani/CVE-2018-1273
CVE-2018-1273CRITICALsob ataqueransomware25 jun 2025
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-48828CRITICAL25 jun 2025
Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the t
75RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM25 jun 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2018-1273CRITICALsob ataqueransomware25 jun 2025
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-10924CRITICAL25 jun 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir ↗
GitHub PoC
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
CVE-2025-3248CRITICALsob ataqueransomware25 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir ↗
GitHub PoC
Poc - CVE-2025-49132
CVE-2025-49132CRITICAL25 jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISCO
abrir ↗
GitHub PoC
C-based PoC for CVE-2019-5736
CVE-2019-5736—25 jun 2025
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir ↗
GitHub PoC
TI WooCommerce Wishlist (WordPress plugin) <= 2.9.2 CVE-2025-47577 PoC
CVE-2025-47577CRITICAL25 jun 2025
WordPress TI WooCommerce Wishlist plugin <= 2.9.2 - Arbitrary File Upload Vulnerability
63RISCO
abrir ↗
Metasploit300
Multiple Brother devices authentication bypass via default administrator password generation
CVE-2024-51978CRITICAL25 jun 2025
Authentication bypass via default password generation affecting multiple models from Brother Industries, Ltd, Toshiba Tec, and Konica Minolta, Inc.
68RISCO
abrir ↗
GitHub PoC
Batch RCE scanner for vulnerable vBulletin instances using replaceAdTemplate exploit.
CVE-2025-48828CRITICAL25 jun 2025
Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the t
75RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-43917CRITICAL25 jun 2025
WordPress TI WooCommerce Wishlist plugin <= 2.8.2 - SQL Injection vulnerability
68RISCO
abrir ↗
Metasploit300
Multiple Brother devices authentication bypass via default administrator password generation
CVE-2024-51977MEDIUM25 jun 2025
Unauthenticated leak of sensitive information affecting multiple models from Brother Industries, Ltd., FUJIFILM Business Innovation, Ricoh, Toshiba Tec, and Konica Minolta, Inc.
70RISCO
abrir ↗
GitHub PoC★ 3
ademto/wordpress-cve-2024-10924-pentest
CVE-2024-10924CRITICAL25 jun 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-49132CRITICAL25 jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISCO
abrir ↗
GitHub PoC
luckyman2907/SMB-Protocol-Vulnerability_CVE-2017-0144
CVE-2017-0144HIGHsob ataqueransomware25 jun 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir ↗
GitHub PoC
Exploit para escalada de privilegios en Linux basado en la vulnerabilidad Dirty Cow (CVE-2016-5195). Incluye binario, código fuente e instrucciones para su uso en entornos controlados.
CVE-2016-5195HIGHsob ataque25 jun 2025
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir ↗
GitHub PoC
TI WooCommerce Wishlist (WordPress plugin) <= 2.8.2 CVE-2024-43917 PoC
CVE-2024-43917CRITICAL25 jun 2025
WordPress TI WooCommerce Wishlist plugin <= 2.8.2 - SQL Injection vulnerability
68RISCO
abrir ↗
GitHub PoC
Rust Macros No Recoil Guide 🚀 Boost Aim Like a Pro in C and Python
CVE-2025-0411HIGHsob ataque24 jun 2025
7-Zip Mark-of-the-Web Bypass Vulnerability
83RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL24 jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISCO
abrir ↗
GitHub PoC
CVE-2025-4322 – Unauthenticated Privilege Escalation via Password Update "Account Takeover" 🔥
CVE-2025-4322CRITICAL24 jun 2025
Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover
68RISCO
abrir ↗
GitHub PoC★ 5
PoCs for CVE-2025-49132
CVE-2025-49132CRITICAL24 jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISCO
abrir ↗
GitHub PoC
A script is a PoC for CVE-2022-1257, a vulnerability in the McAfee Agent (Trellix Agent) when working with it's database. The vulnerability allows attackers to retrieve and decrypt credentials from the McAfee Agent database file (`ma.db`) due to improper encryption key handling.
CVE-2022-1257MEDIUM24 jun 2025
Improper Verification of Cryptographic Signature by McAfee Agent
33RISCO
abrir ↗
GitHub PoC★ 3
Mass-CVE-2025-3248
CVE-2025-3248CRITICALsob ataqueransomware23 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir ↗
GitHub PoC★ 2
Exploit (C) CVE-2024-4577 on PHP CGI
CVE-2024-4577CRITICALsob ataqueransomware23 jun 2025
Argument Injection in PHP-CGI
100RISCO
abrir ↗
GitHub PoC★ 1
CVE-2023-33538 - TP-Link Command Injection Ruby module for Metasploit Framework
CVE-2023-33538HIGHsob ataque23 jun 2025
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerabili
83RISCO
abrir ↗
← anteriorpágina 315 / 2.703próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.