Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
13.282 exploits
GitHub PoC
autocode07/cisagov__check-cve-2019-19781.4142e02b
CVE-2019-19781CRITICALsob ataqueransomware17 out 2025
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
GitHub PoC1
Sudo Vulnerability Local PrivEsc (CVE-2025-32463) POC with Python
CVE-2025-32463CRITICALsob ataque17 out 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC
CVE-2024-27956
CVE-2024-27956CRITICAL17 out 2025
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISCO
abrir
GitHub PoC47
Tool that reproduces CVE-2025-55315 in ASP.NET Core.
CVE-2025-55315CRITICAL16 out 2025
ASP.NET Security Feature Bypass Vulnerability
60RISCO
abrir
GitHub PoC1
The default configuration of LDAP on FortiOS v6.0.x to v6.2.0 does not check server identity for LDAP/S leading to MITM attacks. This PoC demos full exfiltration of credentials sent on the local subnet to an LDAP server that is easily impersonated.
CVE-2019-5591MEDIUMsob ataque16 out 2025
A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept s
83RISCO
abrir
GitHub PoC1
Investigation into the XZ Utils backdoor (CVE-2024-3094): chronology, attack chain, risk to SSH, and supply-chain insights. Includes slides, sources, and mitigations (parity checks, attestations, or SBOMs, as well as SLSA)
CVE-2024-3094CRITICAL16 out 2025
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC
POC of CVE-2025-61882
CVE-2025-61882CRITICALsob ataqueransomware16 out 2025
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integratio
100RISCO
abrir
GitHub PoC13
Proof of concept for CVE-2022-1364 against Alibaba's UC Browser
CVE-2022-1364HIGHsob ataque16 out 2025
Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit
76RISCO
abrir
GitHub PoC
PoC of CVE-2025-60751
CVE-2025-60751HIGH16 out 2025
GeographicLib 2.5 is vulnerable to Buffer Overflow in GeoConvert DMS::InternalDecode.
41RISCO
abrir
GitHub PoC149
Exploit for CVE-2025-11001 or CVE-2025-11002
CVE-2025-11001HIGH15 out 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RISCO
abrir
GitHub PoC1
This repo shows an exploit to CVE-2021-24762. This is an Blind SQLi exploit that, on default config, greps the admin password.
CVE-2021-2476215 out 2025
Perfect Survey < 1.5.2 - Unauthenticated SQL Injection
60RISCO
abrir
GitHub PoC
CVE-2024-53677 관련 컨설턴트용 툴 개발
CVE-2024-53677CRITICAL15 out 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir
GitHub PoC
Oracle WebLogic WLS-WSAT Remote Code Execution Exploit (CVE-2017-10271)
CVE-2017-10271HIGHsob ataqueransomware15 out 2025
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
GitHub PoC8
BYOVD research performed by KOSEC. Includes vulnerable drivers and writeups (CVE-2026-0828).
CVE-2026-0828HIGH15 out 2025
Kernel driver vulnerability in Safetica Endpoint Client
41RISCO
abrir
GitHub PoC
CVE-2024-46256 tool
CVE-2024-46256CRITICAL14 out 2025
A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add
48RISCO
abrir
GitHub PoC20
PoC for CVE-2025-25198: automated Host header poisoning test for Mailcow - HTTPS listener, automatic cookie/CSRF handling, captures first reset link.
CVE-2025-25198HIGH14 out 2025
mailcow: dockerized vulnerable to password reset poisoning
41RISCO
abrir
GitHub PoC
CVE-2025-24893 tool
CVE-2025-24893CRITICALsob ataque14 out 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC1
Poc for CVE-2024-36971
CVE-2024-36971HIGHsob ataque14 out 2025
net: fix __dst_negative_advice() race
71RISCO
abrir
GitHub PoC2
StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload
CVE-2025-7441CRITICAL14 out 2025
StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload
75RISCO
abrir
GitHub PoC
Tnot123/cve-2024-43425
CVE-2024-43425HIGH13 out 2025
Moodle: remote code execution via calculated question types
78RISCO
abrir
GitHub PoC
This script checks if an HP iLO server is vulnerable and can add an admin user
CVE-2017-1254213 out 2025
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RISCO
abrir
GitHub PoC
laachy/CVE-2024-39930-ptrace-detection-mitigation
CVE-2024-39930CRITICAL13 out 2025
The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code
48RISCO
abrir
GitHub PoC1
Reverse shell for CVE-2024-28397.
CVE-2024-28397MEDIUM12 out 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISCO
abrir
GitHub PoC1
PoC of "DEF CON 32 - SQL Injection Isn't Dead Smuggling Queries at the Protocol Level - Paul Gerste"
CVE-2024-27304CRITICAL12 out 2025
pgx SQL Injection via Protocol Message Size Overflow
48RISCO
abrir
GitHub PoC
Scottman625/CVE-2023-29360
CVE-2023-29360HIGHsob ataque12 out 2025
Microsoft Streaming Service Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC
Exploit Title: Node.JS - 'node-serialize' Remote Code Execution (2), Version: 0.0.4, CVE: CVE-2017-5941
CVE-2017-594112 out 2025
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RISCO
abrir
GitHub PoC3
CVE-2024-38856: Apache OFBiz remote code execution Scanner & Exploit
CVE-2024-38856HIGHsob ataque10 out 2025
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISCO
abrir
GitHub PoC
syorik/CVE-2023-42793
CVE-2023-42793CRITICALsob ataqueransomware09 out 2025
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir
GitHub PoC2
CVE-2023-21554 PoC
CVE-2023-21554CRITICAL09 out 2025
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
85RISCO
abrir
GitHub PoC
foregenix/CVE-2023-39143
CVE-2023-39143CRITICAL09 out 2025
PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete
85RISCO
abrir
anteriorpágina 113 / 443próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.