Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8.176Nuclei 4.202Metasploit 3.462✓ só verificadosrecentespopularesrisco
13.282 exploits
GitHub PoC★ 5
Detection for CVE-2025-53690
Sitecore Products ViewState Deserialization Vulnerability
90RISCO
abrir ↗GitHub PoC★ 1
FreePBX CVE-2025-57819 lab (Docker) + Nuclei POC for unauth SQLi (time-based).
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir ↗GitHub PoC★ 40
A sophisticated GUI tool for creating malicious RAR archives that exploit the WinRAR path traversal vulnerability (CVE-2025-8088) using ADS and RAR5 header manipulation.
Path traversal vulnerability in WinRAR
93RISCO
abrir ↗GitHub PoC
neverhavenamee/CVE-2020-7961
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISCO
abrir ↗GitHub PoC
Educational, non-functional Linux kernel exploit template for CVE-2024-1086 — lab-only security research and teaching (use in controlled VMs only).
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISCO
abrir ↗GitHub PoC★ 1
CVE-2016-15042 lab: Dockerized WordPress PoC for unauthenticated file upload in Frontend File Manager <4.0 and N‑Media Post Front‑end Form <1.1
Frontend File Manager < 4.0 & N-Media Post Front-end Form < 1.1 & - Arbitrary File Upload
63RISCO
abrir ↗GitHub PoC★ 8
New vulnerability found in Docker. Credit for finding the vulnerability goes to Felix Boulet
Docker Desktop allows unauthenticated access to Docker Engine API from containers
48RISCO
abrir ↗GitHub PoC★ 11
b0ySie7e/CVE-2025-24893
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir ↗GitHub PoC
This repository provides a modified version of the original CVE-2017-6074 exploit (use-after-free in the Linux kernel DCCP subsystem), designed only to demonstrate Denial of Service (DoS) impact. An authenticated local user can trigger a kernel panic, causing a total loss of system availability.
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST p
23RISCO
abrir ↗GitHub PoC★ 2
Exploitation scripts for the CrushFTP CVE-2025-54309: vulnerability
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RISCO
abrir ↗GitHub PoC
This is a PoC for the CVE-2025-24813 and tested in different environments.
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗GitHub PoC
CVE-2025-3248
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir ↗GitHub PoC★ 2
Reproducible lab for CVE-2020-0610 (BlueGate) - Windows RD Gateway UDP/DTLS remote code execution vulnerability. Includes PowerShell scripts, setup guide, and nuclei template validation examples.
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
35RISCO
abrir ↗GitHub PoC★ 1
This is a PoC/Exploit for the CVE-2024-47875 PhpSpreadsheet XSS Vuln
DOMPurify nesting-based mXSS
48RISCO
abrir ↗GitHub PoC★ 1
jsnv-dev/CVE-2024-51568---CyberPanel-Command-Injection-Nuclei-Template
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecut
75RISCO
abrir ↗GitHub PoC★ 1
Version detection PowerShell
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service
83RISCO
abrir ↗GitHub PoC★ 2
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RISCO
abrir ↗GitHub PoC
Python3 port of the original Joomla Core (1.5.0 through 3.9.4) - Directory Traversal && Authenticated Arbitrary File Deletion
An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder param
35RISCO
abrir ↗GitHub PoC★ 1
CVE-2025-23266 – Fully Weaponized NVIDIA Container Toolkit Exploit
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, wher
48RISCO
abrir ↗GitHub PoC★ 6
FreePBX SQL Injection Exploit
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir ↗GitHub PoC★ 1
a proof of concept of CVE-2024-53677
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir ↗GitHub PoC★ 1
Sawtooth Lighthouse Studio存在模板注入漏洞CVE-2025-34300
Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE
75RISCO
abrir ↗GitHub PoC★ 1
HTML cache poisoning through unsafe reflections
HTML Cache Poisoning through Unsafe Reflections
53RISCO
abrir ↗GitHub PoC★ 1
jeecg-boot getDictItemsByTable接口存在SQL注入漏洞
JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalD
75RISCO
abrir ↗GitHub PoC★ 2
Detection for CVE-2025-7775
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service
83RISCO
abrir ↗GitHub PoC★ 17
CVE-2025-7771: Arbitrary physical memory and I/O port read/write via ThrottleStop driver
Code Execution / Escalation of Privileges in ThrottleStop
41RISCO
abrir ↗GitHub PoC
CTF_WRITEUPS/TryHackMe /CVE-2021-41773/
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗GitHub PoC★ 20
Apache (CVE-2025-24813) GOExploiter Checker & Exploiter very Fast
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗GitHub PoC
It shook the world in 2017 and has evolved into today’s CVE‑2025‑2776. Microsoft still relies on SMBv1, this article will explain how attackers have tweaked the chain from a simple DLL to a full reverse‑shell stack, and what that means for the defenders.
SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.