Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.524exploits catalogados
37.962CVEs com exploração pública
24.695testados em laboratório
81.524 exploits
Metasploit600
pgAdmin Query Tool authenticated RCE (CVE-2025-2945)
CVE-2025-2945CRITICAL03 abr 2025
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
75RISCO
abrir ↗
GitHub PoC★ 7
CVE-2025-30208 - Vite Arbitrary File Read PoC
CVE-2025-30208MEDIUM03 abr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗
Exploit-DB
Vite 6.2.2 - Arbitrary File Read
CVE-2025-30208MEDIUMremotemultiple03 abr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗
Metasploit600
Gladinet CentreStack/Triofox ASP.NET ViewState Deserialization
CVE-2025-30406CRITICALsob ataque03 abr 2025
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
100RISCO
abrir ↗
GitHub PoC
Next.js Middleware Authorization Bypass Tool (CVE-2025-29927)
CVE-2025-29927CRITICAL03 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL03 abr 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir ↗
GitHub PoC
Mongo Vulnub Lab...Try to Hack IT.....!
CVE-2024-53900CRITICAL03 abr 2025
Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.
63RISCO
abrir ↗
Exploit-DB
AppSmith 1.47 - Remote Code Execution (RCE)
CVE-2024-55963MEDIUMwebappsjava03 abr 2025
An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the
45RISCO
abrir ↗
Exploit-DB
Webmin Usermin 2.100 - Username Enumeration
CVE-2024-44762MEDIUMwebappsperl03 abr 2025
A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid
48RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-24799HIGH03 abr 2025
GLPI allows unauthenticated SQL injection through the inventory endpoint
78RISCO
abrir ↗
Exploit-DB
Microsoft Office 2019 MSO Build 1808 - NTLMv2 Hash Disclosure
CVE-2024-38200MEDIUMremotewindows03 abr 2025
Microsoft Office Spoofing Vulnerability
38RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-24799HIGH03 abr 2025
GLPI allows unauthenticated SQL injection through the inventory endpoint
78RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM03 abr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-2825—03 abr 2025
35RISCO
abrir ↗
Exploit-DB
ABB Cylon Aspect 3.07.01 - Hard-coded Default Credentials
CVE-2024-4007HIGHwebappsphp03 abr 2025
Hard coded default credential contained in install package
41RISCO
abrir ↗
GitHub PoC★ 1
h4ckxel/CVE-2025-2005
CVE-2025-2005CRITICAL03 abr 2025
Front-End-Only-Users <= 3.2.32 - Unauthenticated Arbitrary File Upload
53RISCO
abrir ↗
GitHub PoC★ 1
mass scan for CVE-2025-30208
CVE-2025-30208MEDIUM02 abr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗
GitHub PoC
User Registration & Membership <= 4.1.2 - Authentication Bypass
CVE-2025-2594HIGH02 abr 2025
User Registration & Membership < 4.1.3 - Authentication Bypass
41RISCO
abrir ↗
GitHub PoC★ 2
Detection of malicious VHD files for CVE-2025-24985
CVE-2025-24985HIGHsob ataque02 abr 2025
Windows Fast FAT File System Driver Remote Code Execution Vulnerability
71RISCO
abrir ↗
Exploit-DB
SAP NetWeaver - 7.53 - HTTP Request Smuggling
CVE-2022-22536CRITICALsob ataqueremotemultiple02 abr 2025
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RISCO
abrir ↗
GitHub PoC
A basic proof of concept of the CVE-2025-29927 vulnerability that allows to bypass the middleware scripts.
CVE-2025-29927CRITICAL02 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗
GitHub PoC★ 9
WordPress Front End Users Plugin <= 3.2.32 is vulnerable to Arbitrary File Upload
CVE-2025-2005CRITICAL02 abr 2025
Front-End-Only-Users <= 3.2.32 - Unauthenticated Arbitrary File Upload
53RISCO
abrir ↗
Exploit-DB
ABB Cylon Aspect 3.08.01 - Remote Code Execution (RCE)
CVE-2024-6298CRITICALwebappsmultiple02 abr 2025
remote code execution
53RISCO
abrir ↗
Exploit-DB
ABB Cylon Aspect 3.08.01 - Arbitrary File Delete
CVE-2024-6209CRITICALwebappsphp02 abr 2025
unauthorized file access
53RISCO
abrir ↗
VulnCheck XDB
client-side
CVE-2021-44026CRITICALsob ataque02 abr 2025
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
90RISCO
abrir ↗
GitHub PoC
Next.js and the corrupt middleware...TRY TO HACK IT..!
CVE-2025-29927CRITICAL02 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗
Exploit-DB
Elaine's Realtime CRM Automation 6.18.17 - Reflected XSS
CVE-2024-42831MEDIUMwebappsphp02 abr 2025
A reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to ex
33RISCO
abrir ↗
GitHub PoC
0xshaheen/CVE-2025-30208
CVE-2025-30208MEDIUM02 abr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗
GitHub PoC
corsisechero/CVE-2019-9193byVulHub
CVE-2019-9193—02 abr 2025
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISCO
abrir ↗
GitHub PoC
A demo exploit for CVE-2021-44026, a SQL injection in Roundcube
CVE-2021-44026CRITICALsob ataque02 abr 2025
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
90RISCO
abrir ↗
← anteriorpágina 359 / 2.718próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.