Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8.176Nuclei 4.202Metasploit 3.462✓ só verificadosrecentespopularesrisco
13.282 exploits
GitHub PoC
Detection for CVE-2025-34299
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RISCO
abrir ↗GitHub PoC★ 2
CVE-2025-41244 is a critical local privilege escalation vulnerability in VMware Aria Operations and VMware Tools
VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)
71RISCO
abrir ↗GitHub PoC★ 5
Wh04m1001/CVE-2025-60710
Host Process for Windows Tasks Elevation of Privilege Vulnerability
71RISCO
abrir ↗GitHub PoC
CVE-2025-21042
Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitra
76RISCO
abrir ↗GitHub PoC
Exploit cyberpanel version 2.3.6 - 2.3.7
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
100RISCO
abrir ↗GitHub PoC
CVE-2025-25257 PoC for educational use and/or authorised pentesting.
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISCO
abrir ↗GitHub PoC★ 1
Comprehensive Proof of Concept collection for CVE-2025-11953, CVE-2025-59287, CVE-2025-8941 with exploitation frameworks in Python, C, Bash, PowerShell
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
90RISCO
abrir ↗GitHub PoC
Vulnerability for Xwiki
XWiki Platform: Remote code execution as guest via DatabaseSearch
75RISCO
abrir ↗GitHub PoC★ 2
CVE-2025-48703 é uma vulnerabilidade de Execução Remota de Código (RCE) no módulo filemanager de um painel de hospedagem web (por exemplo, cPanel). Ocorre devido ao tratamento de entrada não sanitizado na função acc=changePerm, que permite que um atacante injete e execute comandos.
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell
100RISCO
abrir ↗GitHub PoC
harekrishnarai/CVE-2024-23897-test-windows
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir ↗GitHub PoC★ 2
AstrBot老版本RCE
AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key us
41RISCO
abrir ↗GitHub PoC★ 2
Mitchellzhou1/CVE-2024-48910-PoC
DOMPurify vulnerable to tampering by prototype polution
48RISCO
abrir ↗GitHub PoC★ 1
check if vulnerable python-django version to CVE-2025-64459 bug
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RISCO
abrir ↗GitHub PoC
Exploit and test stand for CVE-2025-2945
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
75RISCO
abrir ↗GitHub PoC
Ghstxz/CVE-2025-32463
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗GitHub PoC★ 1
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISCO
abrir ↗GitHub PoC
A proof of concept for CVE-2025-24054/CVE-2025-24071
NTLM Hash Disclosure Spoofing Vulnerability
75RISCO
abrir ↗GitHub PoC★ 12
CVE-2025-6554
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RISCO
abrir ↗GitHub PoC★ 9
AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation
AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation
85RISCO
abrir ↗GitHub PoC
l1nuxkid/CVE-2025-32433-exploit
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir ↗GitHub PoC
letsr00t/-CVE-2019-18634-sudo-pwfeedback
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISCO
abrir ↗GitHub PoC★ 10
Firefox/Tor Browser 0day exploit analysis (CVE-2024-9680) A UAF in animation timelines leading to RCE. Patched.
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timeli
83RISCO
abrir ↗GitHub PoC★ 1
Emergency Chrome update information and tools for CVE-2023-7024 and other critical vulnerabilities
Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit
71RISCO
abrir ↗GitHub PoC★ 1
Emergency Chrome update information and tools for CVE-2023-7024 and other critical vulnerabilities
Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit
71RISCO
abrir ↗GitHub PoC
Tomcat - PUT Method
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISCO
abrir ↗GitHub PoC★ 2
This repository contains research notes and a high-level proof-of-concept (PoC) for CVE-2024-21413, a vulnerability observed in certain mail clients when handling SMB/moniker-style links embedded in messages. The PoC and experiments documented here were performed in a controlled lab environment on systems.
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC
rockmelodies/django_sqli_target_CVE-2025-64459
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RISCO
abrir ↗GitHub PoC★ 4
demo CVE-2019-2215 (Bad Binder) for Android Q
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.