Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
13.282 exploits
GitHub PoC
ict519 assignment
CVE-2023-38831HIGHsob ataqueransomware28 out 2025
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC1
A Metasploit module for CVE-2024-35374
CVE-2024-35374CRITICAL28 out 2025
Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing
48RISCO
abrir
GitHub PoC
Demo of CVE-2021-44228 Log4Shell.
CVE-2021-44228CRITICALsob ataqueransomware28 out 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
CaelumIsMe/CVE-2020-29607-POC
CVE-2020-2960727 out 2025
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access
35RISCO
abrir
GitHub PoC
Alex-Acero-Security/CVE-2025-20260-POC
CVE-2025-20260CRITICAL27 out 2025
ClamAV PDF Scanning Buffer Overflow Vulnerability
48RISCO
abrir
GitHub PoC
CVE-2021-22204 exiftool rce
CVE-2021-22204MEDIUMsob ataque27 out 2025
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISCO
abrir
GitHub PoC
Exploit Code for CVE-2018-15473
CVE-2018-15473MEDIUM26 out 2025
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC7
mcp-remote exposed to OS command injection
CVE-2025-6514CRITICAL26 out 2025
OS command injection in mcp-remote when connecting to untrusted MCP servers
70RISCO
abrir
GitHub PoC
aadi0258/Exploit-CVE-2024-23897
CVE-2024-23897CRITICALsob ataqueransomware26 out 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
GitHub PoC
kso4more/CVE-2025-0108
CVE-2025-0108HIGHsob ataque25 out 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RISCO
abrir
GitHub PoC3
Exploit for CVE-2019-11043
CVE-2019-11043HIGHsob ataqueransomware24 out 2025
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC1
I was presented with a high-severity alert indicating a potential exploit attempt of CVE-2023-22515, a zero-day vulnerability in Atlassian Confluence. The alert showed a suspicious GET request from an external IP targeting the Confluence server, suggesting an attempt to gain unauthorised admin access.
CVE-2023-22515CRITICALsob ataqueransomware24 out 2025
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISCO
abrir
GitHub PoC
Writeup for Tenda AC15 router firmware rehosting and remote command execution (CVE-2020-10987) exploit replication.
CVE-2020-10987CRITICALsob ataque23 out 2025
The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary s
100RISCO
abrir
GitHub PoC
Exploit for CVE-2019-18935
CVE-2019-18935CRITICALsob ataqueransomware23 out 2025
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISCO
abrir
GitHub PoC
srakkk/cve-2024-32002-demo
CVE-2024-32002CRITICAL23 out 2025
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
GitHub PoC
srakkk/cve-2024-32002-hook
CVE-2024-32002CRITICAL23 out 2025
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
GitHub PoC
cve-2023-2745
CVE-2023-2745MEDIUM22 out 2025
WordPress Core < 6.2.1 - Directory Traversal
70RISCO
abrir
GitHub PoC
Script to obfuscate a payload the same way as it was done by the XZ utils attack (CVE-2024-3094)
CVE-2024-3094CRITICAL22 out 2025
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC
Redux Python3 Version of CVE-2010-2861
CVE-2010-2861CRITICALsob ataqueransomware22 out 2025
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow re
100RISCO
abrir
GitHub PoC
root Privileges
CVE-2021-3493HIGHsob ataque22 out 2025
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISCO
abrir
GitHub PoC
moeinmiadi/CVE-2015-1635_PoC
CVE-2015-1635CRITICALsob ataque20 out 2025
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISCO
abrir
GitHub PoC
CaelumIsMe/CVE-2019-9053-POC
CVE-2019-905319 out 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
GitHub PoC3
Patch for CVE-2025-54236(a.k.a Session Reaper) which allows customer account takeover and RCE under certain conditions. This patch is actually a Magento 2 extension and universal compatible for Magento 2.3 & 2.4. If you cannot upgrade Magento or cannot apply the official hotfix, try this one.
CVE-2025-54236CRITICALsob ataque19 out 2025
Adobe Commerce | Improper Input Validation (CWE-20)
100RISCO
abrir
GitHub PoC1
📋 ملخص مشروع MikroTik RouterOS 6.49.18 Exploit Kit 🎯 نظرة عامة تم إنشاء مشروع احترافي وشامل لاختراق أجهزة MikroTik RouterOS 6.49.18 يتضمن جميع المكونات المطلوبة مع واجهة عربية كاملة وتوثيق مفصل. ✅ المكونات المكتملة 1️⃣ سكربتات الاختراق (7 سكربتات ✅ المميزات الرئيسية 1🎯 دعم CVE-2023-30799 اقراء دليل ملخص شامل للاداة PROJECT_SUMMARY.md
CVE-2023-30799CRITICAL19 out 2025
MikroTik RouterOS Administrator Privilege Escalation
48RISCO
abrir
GitHub PoC
Proof-of-Concept (POC) of a simple firewall in Python designed to mitigate the Spring4Shell (CVE-2022-22965) RCE attack by inspecting and blocking malicious request bodies.
CVE-2022-22965CRITICALsob ataque19 out 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC
Custom vulnerable VM (Ubuntu 14.04) designed for teaching multi-stage penetration testing. Features 10 interconnected challenges across Forensics, Web Exploitation (SQLi, XSS), Cryptography, and Kernel Exploitation (OverlayFS/CVE-2015-1328) to achieve full root compromise.
CVE-2015-132818 out 2025
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISCO
abrir
GitHub PoC
End-to-end Domain Controller exploitation using Metasploit and Impacket: discovered DC10, exploited Zerologon (CVE-2020-1472), extracted NTLM hashes, gained SYSTEM shell, and established a Meterpreter session.
CVE-2020-1472MEDIUMsob ataqueransomware18 out 2025
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC
We are presented with a security alert indicating the detection of the Follina (CVE-2022-30190) vulnerability. A malicious Word document triggered msdt.exe execution, suggesting possible remote code execution on the host JonasPRD. Our task is to investigate the alert, confirm exploitation, assess impact, and recommend remediation.
CVE-2022-30190HIGHsob ataqueransomware18 out 2025
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
0axz-tools/CVE-2024-51793
CVE-2024-51793CRITICAL17 out 2025
WordPress RepairBuddy plugin <= 3.8115 - Arbitrary File Upload vulnerability
48RISCO
abrir
GitHub PoC
CVE-2024-27956
CVE-2024-27956CRITICAL17 out 2025
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISCO
abrir
anteriorpágina 112 / 443próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.