Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.836exploits catalogados
32.133CVEs com exploração pública
1.932testados em laboratório
8.150 exploits
VulnCheck XDB
client-side
CVE-2025-4123HIGH06 jun 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware06 jun 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALsob ataque06 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM06 jun 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2025-32756CRITICALsob ataque05 jun 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALsob ataque05 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2022-46604HIGH05 jun 2025
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanis
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALsob ataque05 jun 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHsob ataque04 jun 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-4123HIGH04 jun 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-2539HIGH04 jun 2025
File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Read
56RISCO
abrir
VulnCheck XDB
infoleak
CVE-2019-20085HIGHsob ataque04 jun 2025
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL03 jun 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-4123HIGH03 jun 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-27163MEDIUM03 jun 2025
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-3102HIGH03 jun 2025
SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
78RISCO
abrir
VulnCheck XDB
initial-access
CVE-2008-4250CRITICALsob ataque02 jun 2025
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2018-999502 jun 2025
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir
VulnCheck XDB
infoleak
CVE-2023-25690CRITICAL01 jun 2025
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
70RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-48827CRITICAL31 mai 2025
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALsob ataqueransomware31 mai 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-30397HIGHsob ataque31 mai 2025
Scripting Engine Memory Corruption Vulnerability
76RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-5287HIGH31 mai 2025
Likes and Dislikes Plugin <= 1.0.0 - Unauthenticated SQL Injection
56RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-26828HIGHsob ataque30 mai 2025
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and exe
83RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-7399HIGHsob ataque30 mai 2025
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 2
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM29 mai 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-48827CRITICAL29 mai 2025
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
85RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-2291129 mai 2025
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL29 mai 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-5287HIGH28 mai 2025
Likes and Dislikes Plugin <= 1.0.0 - Unauthenticated SQL Injection
56RISCO
abrir
anteriorpágina 81 / 272próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.