Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.781exploits catalogados
36.771CVEs com exploração pública
24.695testados em laboratório
8.932 exploits
VulnCheck XDB
initial-access
CVE-2025-5394CRITICAL31 jul 2025
Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMsob ataque31 jul 2025
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALsob ataque30 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2023-2533HIGHsob ataque30 jul 2025
PaperCut MF/NG 22.0.10 (Build 65996 2023-03-27) - Remote code execution via CSRF
76RISCO
abrir
VulnCheck XDB
local
CVE-2023-22809HIGH30 jul 2025
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISCO
abrir
VulnCheck XDB
info-leak
CVE-2025-14847HIGHsob ataque30 jul 2025
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-1675HIGHsob ataqueransomware29 jul 2025
Windows Print Spooler Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-29927CRITICAL29 jul 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALsob ataqueransomware29 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALsob ataque29 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALsob ataqueransomware28 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALsob ataqueransomware28 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-2294CRITICAL28 jul 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-48384HIGHsob ataque28 jul 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-32429CRITICAL28 jul 2025
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-47812CRITICALsob ataque27 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALsob ataqueransomware27 jul 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALsob ataqueransomware27 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-32429CRITICAL26 jul 2025
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-54309CRITICALsob ataque26 jul 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALsob ataqueransomware25 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-27372CRITICAL25 jul 2025
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-32429CRITICAL25 jul 2025
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALsob ataque25 jul 2025
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2023-23397CRITICALsob ataque25 jul 2025
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-54782CRITICAL25 jul 2025
@nestjs/devtools-integration's CSRF to Sandbox Escape Allows for RCE against JS Developers
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALsob ataqueransomware25 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALsob ataqueransomware24 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALsob ataqueransomware24 jul 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-6558HIGHsob ataque24 jul 2025
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote at
71RISCO
abrir
anteriorpágina 85 / 298próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.