Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.453exploits catalogados
37.908CVEs com exploração pública
24.695testados em laboratório
81.453 exploits
Exploit-DB
Apache Tomcat 10.1.39 - Denial of Service (DoS)
CVE-2025-31650HIGHremotemultiple05 jun 2025
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
53RISCO
abrir ↗
Exploit-DB
Microsoft Windows Server 2025 JScript Engine - Remote Code Execution (RCE)
CVE-2025-30397HIGHsob ataqueremotewindows05 jun 2025
Scripting Engine Memory Corruption Vulnerability
76RISCO
abrir ↗
Exploit-DB
macOS LaunchDaemon iOS 17.2 - Privilege Escalation
CVE-2025-24085CRITICALsob ataquelocalmacos05 jun 2025
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, i
83RISCO
abrir ↗
GitHub PoC★ 1
Repositorio de investigación de seguridad que contiene una Prueba de Concepto (PoC) para la vulnerabilidad CVE-2021-4034 (PwnKit) y utilidades de scripting para la demostración de escalada de privilegios y ejecución remota en entornos Linux.
CVE-2021-4034HIGHsob ataqueransomware05 jun 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir ↗
GitHub PoC★ 1
CyberQuestor-infosec/CVE-2022-46604-Responsive-File-Manager
CVE-2022-46604HIGH05 jun 2025
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanis
41RISCO
abrir ↗
GitHub PoC
PoC for CVE-2024-42049
CVE-2024-42049CRITICAL05 jun 2025
TightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pipe via a network connection.
48RISCO
abrir ↗
Exploit-DB
CloudClassroom PHP Project 1.0 - SQL Injection
CVE-2025-45542HIGHwebappsphp05 jun 2025
SQL injection vulnerability in the registrationform endpoint of CloudClassroom-PHP-Project v1.0. The pass parameter is v
41RISCO
abrir ↗
GitHub PoC
Superliverbun/cve-2021-3156-
CVE-2021-3156HIGHsob ataque04 jun 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir ↗
GitHub PoC
Authenticated Remote Command Execution - Webmin <= 1.910
CVE-2019-12840—04 jun 2025
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RISCO
abrir ↗
GitHub PoC
MantisToboggan-git/CVE-2025-4632-POC
CVE-2025-4632CRITICALsob ataque04 jun 2025
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 2
98RISCO
abrir ↗
GitHub PoC
A repository used for Hackthebox ServMon Machine
CVE-2019-20085HIGHsob ataque04 jun 2025
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RISCO
abrir ↗
GitHub PoC
Authenticated Remote Command Execution - Webmin <= 1.910
CVE-2019-12840—04 jun 2025
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2025-4123HIGH04 jun 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISCO
abrir ↗
VulnCheck XDB
local
CVE-2021-3156HIGHsob ataque04 jun 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir ↗
GitHub PoC★ 32
CVE-2025-4123 - Grafana Tool
CVE-2025-4123HIGH04 jun 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-2539HIGH04 jun 2025
File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Read
56RISCO
abrir ↗
GitHub PoC★ 3
CVE-2025-49113 - Roundcube <= 1.6.10 Post-Auth RCE via PHP Object Deserialization
CVE-2025-49113CRITICALsob ataque04 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir ↗
GitHub PoC
An exploit automation script that builds upon the work of Voidzone security.
CVE-2022-44268MEDIUM04 jun 2025
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2019-20085HIGHsob ataque04 jun 2025
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RISCO
abrir ↗
GitHub PoC★ 107
fearsoff-org/CVE-2025-49113
CVE-2025-49113CRITICALsob ataque04 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir ↗
GitHub PoC
gmh5225/cve-2021-3156-
CVE-2021-3156HIGHsob ataque04 jun 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir ↗
GitHub PoC★ 3
pgAdmin Proof of Concept
CVE-2025-2945CRITICAL03 jun 2025
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
75RISCO
abrir ↗
GitHub PoC★ 5
Detection for CVE-2025-49113
CVE-2025-49113CRITICALsob ataque03 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir ↗
GitHub PoC
Authenticated Remote Command Execution – pfSense <= 2.1.3
CVE-2014-4688—03 jun 2025
pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_
23RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2023-27163MEDIUM03 jun 2025
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-3102HIGH03 jun 2025
SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
78RISCO
abrir ↗
GitHub PoC★ 1
A XZ backdoor vulnerability explained in details
CVE-2024-3094CRITICAL03 jun 2025
Xz: malicious code in distributed source
70RISCO
abrir ↗
GitHub PoC★ 2
r007sec/CVE-2024-53677
CVE-2024-53677CRITICAL03 jun 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2025-4123HIGH03 jun 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL03 jun 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir ↗
← anteriorpágina 329 / 2.716próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.