Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 20.003GitHub PoC 13.307VulnCheck XDB 8.182Nuclei 4.217Metasploit 3.462✓ só verificadosrecentespopularesrisco
13.282 exploits
GitHub PoC★ 8
Cloudflare Image Resizing <= 1.5.6 | Unauthenticated Remote Code Execution
Cloudflare Image Resizing <= 1.5.6 - Missing Authentication to Unauthenticated Remote Code Execution via rest_pre_dispatch Hook
53RISCO
abrir ↗GitHub PoC
shoucheng3/x-stream__xstream_CVE-2013-7285_1-4-6
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a rem
60RISCO
abrir ↗GitHub PoC★ 1
charanvoonna/CVE-2021-41773
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗GitHub PoC
This is a rewritten exploit to work with php
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir ↗GitHub PoC★ 2
Proof of concept for CVE-2020-36708
Epsilon Framework Themes (Various Versions) - Function Injection
75RISCO
abrir ↗GitHub PoC★ 1
harutomo-jp/CVE-2024-28397-RCE
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISCO
abrir ↗GitHub PoC
CVE-2015-6967 PoC Exploit
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to
50RISCO
abrir ↗GitHub PoC
shoucheng3/keycloak__keycloak_CVE-2022-3782_20-0-1
keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs
48RISCO
abrir ↗GitHub PoC
chan-068/CVE-2024-0520_try
Remote Code Execution due to Full Controlled File Write in mlflow/mlflow
48RISCO
abrir ↗GitHub PoC
CyberQuestor-infosec/CVE-2025-49113-Roundcube_1.6.10
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir ↗GitHub PoC★ 3
This is an improved version of the CVE-2025-49132 proof of concept exploit.
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISCO
abrir ↗GitHub PoC★ 1
The CVE-2024-28397 vulnerability affects versions of js2py up to v0.74, a Python library that allows JavaScript code to be executed within the Python interpreter.
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISCO
abrir ↗GitHub PoC★ 3
Proof-of-concept exploit for CVE-2025-4334, a privilege escalation vulnerability in the Simple User Registration WordPress plugin (<= 6.3), allowing unauthenticated attackers to create administrator accounts.
Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation
63RISCO
abrir ↗GitHub PoC
Demo of CVE-2025-29927 for secure programming class
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 21
Detection for CVE-2025-8875 & CVE-2025-8876
Insecure Deserialization Vulnerability
78RISCO
abrir ↗GitHub PoC
Proof-of-Concept exploit script for Xdebug 2.5.5 and earlier versions (CVE-2015-10141).
Xdebug Remote Debugger Unauthenticated OS Command Execution
63RISCO
abrir ↗GitHub PoC★ 2
Proof-of-Concept for CVE-2025-8088 vulnerability in WinRAR (path traversal via ADS)
Path traversal vulnerability in WinRAR
93RISCO
abrir ↗GitHub PoC
shoucheng3/apache__rocketmq_CVE-2023-33246_5-1-0
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISCO
abrir ↗GitHub PoC★ 1
Command Injection in Tenda AC20 16.03.08.12 (/goform/telnet)
Tenda AC20 Telnet Service telnet websFormDefine command injection
38RISCO
abrir ↗GitHub PoC★ 3
PoC exploit for CVE-2025-32778: command injection in Web-Check OSINT tool
Web-Check allows command Injection via Unvalidated URL in Screenshot API
68RISCO
abrir ↗GitHub PoC
CVE-2019-12185 - eLabFTW 1.8.5 Python3 Exploit POC
eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. This may
28RISCO
abrir ↗GitHub PoC
shoucheng3/spring-cloud__spring-cloud-config_CVE-2020-5410_2-1-8-RELEASE
Directory Traversal with spring-cloud-config-server
100RISCO
abrir ↗GitHub PoC
shoucheng3/spring-projects__spring-security_CVE-2011-2732_2-0-6-RELEASE
CRLF injection vulnerability in the logout functionality in VMware SpringSource Spring Security before 2.0.7 and 3.0.x b
23RISCO
abrir ↗GitHub PoC★ 5
This vulnerability arises from incomplete sandboxing in js2py, where crafted JavaScript can traverse Python’s internal object model and access dangerous classes like subprocess.Popen, leading to arbitrary command execution.
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISCO
abrir ↗GitHub PoC
Research Objective: To conduct a comprehensive analysis and successful exploitation of a Remote Code Execution (RCE) vulnerability in Webmin version 1.890 (CVE-2019-15107), ultimately gaining full control over the target system.
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir ↗GitHub PoC★ 1
Ash1996x/CVE-2025-50154-Aggressor-Script
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir ↗GitHub PoC
shoucheng3/apache__rocketmq_CVE-2023-37582_4-9-6
Apache RocketMQ: Possible remote code execution when using the update configuration function
85RISCO
abrir ↗GitHub PoC★ 5
CVE-2025-6934 is a critical vulnerability in the WordPress Opal Estate Pro plugin (<= 1.7.5) that allows unauthenticated attackers to create new administrator accounts through the plugin’s insecure AJAX registration process.
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.