Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 20.003GitHub PoC 13.307VulnCheck XDB 8.182Nuclei 4.217Metasploit 3.462✓ só verificadosrecentespopularesrisco
71.957 exploits
Exploit-DB
WordPress Backup Migration 1.3.7 - Remote Command Execution
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RISCO
abrir ↗Exploit-DB
Boss Mini v1.4.0 - Local File Inclusion (LFI)
Boss Mini document file inclusion
78RISCO
abrir ↗GitHub PoC
CVE-2025-68613 — n8n RCE via Expression Injection
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISCO
abrir ↗GitHub PoC
CVE-2025-32463
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗GitHub PoC★ 19
Dahua IP camera CVE research toolkit (CVE-2021-33044/33045, CVE-2025-31700/31701)
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISCO
abrir ↗GitHub PoC
CVE-2023-3452 exploit for WordPress Canto plugin RCE, HTTPS support included
Canto <= 3.0.4 - Unauthenticated Remote File Inclusion
63RISCO
abrir ↗Exploit-DB
mailcow 2025-01a - Host Header Password Reset Poisoning
mailcow: dockerized vulnerable to password reset poisoning
41RISCO
abrir ↗GitHub PoC★ 1
Demonstrate a proof-of-concept exploit for CVE-2026-2441, a high-risk Chrome use-after-free vulnerability in the Blink CSS engine.
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside
76RISCO
abrir ↗GitHub PoC
CVE-2024-23897: Jenkins Arbitrary File Read Lead to RCE
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗GitHub PoC★ 9
gowonisgood/CVE-2025-62215-POC
Windows Kernel Elevation of Privilege Vulnerability
71RISCO
abrir ↗VulnCheck XDB
initial-access
MaxSite CMS MarkItUp Preview AJAX Endpoint preview-ajax.php eval code injection
33RISCO
abrir ↗GitHub PoC★ 1
CVE-2025-43529 Test
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
71RISCO
abrir ↗GitHub PoC
CVE-2025-5777
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir ↗VulnCheck XDB
local
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vul
90RISCO
abrir ↗GitHub PoC
PoC of CVE-2021-4034 (PwnKit) for personal training purposes.
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir ↗GitHub PoC
Aryan20057/CVE-2023-4911
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISCO
abrir ↗VulnCheck XDB
client-side
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
71RISCO
abrir ↗VulnCheck XDB
initial-access
Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload
75RISCO
abrir ↗GitHub PoC
Metasploit module to exploit CVE-2024-46987 - an authenticated path traversal vulnerability in Camaleon CMS versions 2.8.0 through 2.8.2 and 2.9.0
Arbitrary path traversal in Camaleon CMS
61RISCO
abrir ↗VulnCheck XDB
initial-access
MaxSite CMS MarkItUp Preview AJAX Endpoint preview-ajax.php eval code injection
33RISCO
abrir ↗GitHub PoC
CVE-2014-0160
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir ↗GitHub PoC
Laravel-RCE: CVE-2017-9841
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISCO
abrir ↗GitHub PoC
This repository provides production-ready detection engineering content for **CVE-2025-25257**, a pre-authentication SQL Injection vulnerability in Fortinet FortiWeb Fabric Connector versions 7.0 through 7.6.x. Successful exploitation can lead to Remote Code Execution without any prior authentication.
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISCO
abrir ↗GitHub PoC
Black box penetration test — WordPress exploitation, privilege escalation via CVE-2022-0847
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir ↗Metasploit600
FreeScout Unauthenticated RCE via ZWSP .htaccess Bypass
FreeScout: Missing .htaccess in Restricted File Extensions Allows Remote Code Execution on Apache
36RISCO
abrir ↗Metasploit600
FreeScout Unauthenticated RCE via ZWSP .htaccess Bypass
FreeScout 1.8.206 Patch Bypass for CVE-2026-27636 via Zero-Width Space Character Leads to Remote Code Execution
55RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.