Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
13.282 exploits
GitHub PoC31
A scanner for the FortiNet vulnerability CVE-2025-64446
CVE-2025-64446CRITICALsob ataque17 nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISCO
abrir
GitHub PoC
FortiWeb Unauthenticated RCE via Path Traversal & CGI Auth Bypass
CVE-2025-64446CRITICALsob ataque17 nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISCO
abrir
GitHub PoC
Hands-on exploitation lab for Roundcube Webmail CVE-2025-49113 (authenticated PHP object deserialization → RCE) to read /secret.txt.
CVE-2025-49113CRITICALsob ataque17 nov 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
GitHub PoC
CVE-2025-33073
CVE-2025-33073HIGHsob ataque17 nov 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RISCO
abrir
GitHub PoC2
This Python PoC script detects the Heartbleed vulnerability (CVE-2014-0160) by performing a TLS handshake with heartbeat extension and sending a crafted heartbeat request. It parses responses to identify leaked memory, helping assess server susceptibility to this critical OpenSSL flaw.
CVE-2014-0160HIGHsob ataque17 nov 2025
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC
This lab simulates CVE-2019-9193 - PostgreSQL COPY FROM PROGRAM RCE
CVE-2019-919317 nov 2025
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISCO
abrir
GitHub PoC
honeyvig/CVE-2022-0847-DirtyPipe-Exploit
CVE-2022-0847HIGHsob ataque16 nov 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC
This repository contains my work for a cybersecurity assignment where I exploited the real-world Log4Shell (CVE-2021-44228) vulnerability inside a safe, controlled virtual machine. The project followed a Capture-the-Flag format with multiple exploitation tasks to retrieve hidden flags.
CVE-2021-44228CRITICALsob ataqueransomware16 nov 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Practical security research project exploiting CVE-2025-32463 to gain root access on a vulnerable sudo version. Includes write-up, PoC, and mitigation steps.
CVE-2025-32463CRITICALsob ataque16 nov 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC1
CMS Made Simple < 2.2.10 - SQL Injection . Actual working version
CVE-2019-905316 nov 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
GitHub PoC
placeholder for CitrixBleed 2.0 CVE-2025-5777
CVE-2025-5777CRITICALsob ataqueransomware16 nov 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
GitHub PoC
D-link AX1500 Vulnerability
CVE-2025-60854CRITICAL16 nov 2025
A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during
48RISCO
abrir
GitHub PoC13
Unauthenticated RCE PoC in Microsoft Windows Server Update Service (WSUS) - CVE-2025-59287 & CVE-2023-35317
CVE-2025-59287CRITICALsob ataque16 nov 2025
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC1
CVE-2025-64328 FreePBX Authenticated Command Injection in the framework module.
CVE-2025-64328HIGHsob ataque15 nov 2025
FreePBX Administration GUI is Vulnerable to Authenticated Command Injection
100RISCO
abrir
GitHub PoC
Detection, Exploit and Mitigation for CVE 2023 46604.
CVE-2023-46604CRITICALsob ataqueransomware15 nov 2025
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISCO
abrir
GitHub PoC13
soltanali0/CVE-2025-64446-Exploit
CVE-2025-64446CRITICALsob ataque15 nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISCO
abrir
GitHub PoC2
Python3-converted exploit and research notes for CMS Made Simple (CVE-2019-9053) — Unauthenticated SQL Injection vulnerability. Includes original PoC, improved Python3 version, usage instructions, and lab testing reference.
CVE-2019-905315 nov 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
GitHub PoC1
Twodimensionalitylevelcrossing817/CVE-2025-59287
CVE-2025-59287CRITICALsob ataque15 nov 2025
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC1
PoC for CVE-2025-64513 — Milvus Proxy Authentication Bypass Vulnerability Batch scanner to verify unauthorized access and gather Milvus version, health, and database info. For security research and defensive validation only.
CVE-2025-64513CRITICAL14 nov 2025
Milvus Proxy has Critical Authentication Bypass Vulnerability
48RISCO
abrir
GitHub PoC68
Universal exploitation tool for CVE-2025-33073 targeting Windows Domain Controllers with DNSAdmins privileges and WinRM enabled.
CVE-2025-33073HIGHsob ataque14 nov 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RISCO
abrir
GitHub PoC32
CVE-2025-62215 is an Elevation of Privilege (EoP) vulnerability in the Windows Kernel, disclosed in November 2025 and confirmed to be actively exploited as a zero-day.
CVE-2025-62215HIGHsob ataque14 nov 2025
Windows Kernel Elevation of Privilege Vulnerability
71RISCO
abrir
GitHub PoC7
# CVE-2025-64446 PoC - FortiWeb Path Traversal Proof of Concept para la vulnerabilidad de path traversal en Fortinet FortiWeb que permite ejecución remota de comandos. Incluye herramienta de detección para fines educativos. **⚠️ SOLO USO EDUCATIVO - NO PARA EXPLOTACIÓN ⚠️**
CVE-2025-64446CRITICALsob ataque14 nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISCO
abrir
GitHub PoC13
sxyrxyy/CVE-2025-64446-FortiWeb-CGI-Bypass-PoC
CVE-2025-64446CRITICALsob ataque14 nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISCO
abrir
GitHub PoC
CVE-2022-22965 proof of concept for CS4239 report
CVE-2022-22965CRITICALsob ataque14 nov 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC
cyhe50/cve-2025-32434-poc
CVE-2025-32434CRITICAL13 nov 2025
PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
48RISCO
abrir
GitHub PoC
keyuraghao/CVE-2025-20260
CVE-2025-20260CRITICAL13 nov 2025
ClamAV PDF Scanning Buffer Overflow Vulnerability
48RISCO
abrir
GitHub PoC6
PoC Exploit CVE-2018-6389
CVE-2018-638913 nov 2025
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISCO
abrir
GitHub PoC14
Arbitrary physical memory read/write exploitation using ThrottleStop.sys (CVE-2025-7771) with superfetch address translation - Windows kernel security research
CVE-2025-7771HIGH13 nov 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RISCO
abrir
GitHub PoC
Alex-Acero-Security/CVE-2024-48910-POC
CVE-2024-48910CRITICAL12 nov 2025
DOMPurify vulnerable to tampering by prototype polution
48RISCO
abrir
GitHub PoC24
redpack-kr/CVE-2025-60710
CVE-2025-60710HIGHsob ataque12 nov 2025
Host Process for Windows Tasks Elevation of Privilege Vulnerability
71RISCO
abrir
anteriorpágina 109 / 443próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.