Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 20.003GitHub PoC 13.307VulnCheck XDB 8.182Nuclei 4.217Metasploit 3.462✓ só verificadosrecentespopularesrisco
13.282 exploits
GitHub PoC
shoucheng3/apache__rocketmq_CVE-2023-37582_4-9-6
Apache RocketMQ: Possible remote code execution when using the update configuration function
85RISCO
abrir ↗GitHub PoC
shoucheng3/apache__myfaces_CVE-2011-4367_2-0-11
Multiple directory traversal vulnerabilities in MyFaces JavaServer Faces (JSF) in Apache MyFaces Core 2.0.x before 2.0.1
35RISCO
abrir ↗GitHub PoC★ 36
Exploit systems using older WinRAR without knowing their username (unlike other projects)
Path traversal vulnerability in WinRAR
93RISCO
abrir ↗GitHub PoC
shoucheng3/xwiki__xwiki-rendering_CVE-2023-37908_14-10-3
org.xwiki.rendering:xwiki-rendering-xml Improper Neutralization of Invalid Characters in Identifiers in Web Pages vulnerability
48RISCO
abrir ↗GitHub PoC
shoucheng3/apache__shiro_CVE-2023-34478_1-11-0
Apache Shiro before 1.12.0, or 2.0.0-alpha-3, may be susceptible to a path traversal attack when used together with APIs or other web frameworks that route requests based on non-normalized requests.
48RISCO
abrir ↗GitHub PoC★ 110
PoC and technical details of CVE-2025-24204
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access pr
48RISCO
abrir ↗GitHub PoC★ 1
0xAbolfazl/CVE-2025-8088-WinRAR-PathTraversal-PoC
Path traversal vulnerability in WinRAR
93RISCO
abrir ↗GitHub PoC★ 22
sap netweaver 0day poc by shinyhunters (scattered lapsus$ hunters) affecting all 7.x CVE-2025-31324
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISCO
abrir ↗GitHub PoC★ 1
0xr2r/CVE-2017-11317-auto-exploit-
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload
100RISCO
abrir ↗GitHub PoC
hlc23/CVE-2024-5932-web-ui
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RISCO
abrir ↗GitHub PoC★ 4
A PoC for CVE-2024-3660. Arbitrary Code Execution in Keras.
Arbitrary code injection vulnerability in Keras framework < 2.13
48RISCO
abrir ↗GitHub PoC★ 2
MailPoet Newsletters <= Arbitrary File Upload (exploiter)
The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authen
50RISCO
abrir ↗GitHub PoC★ 4
Safe Python script to detect Cisco FMC instances potentially vulnerable to CVE-2025-20265. Uses official FMC API to check version, supports single/multi-target scanning, and includes a harmless local PoC marker.
Cisco Secure Firewall Management Center Software Radius Remote Code Execution Vulnerability
53RISCO
abrir ↗GitHub PoC★ 1
okkotsu1/CVE-2024-47533
Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes
63RISCO
abrir ↗GitHub PoC
Kento-Sec/CVE-2024-34102
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir ↗GitHub PoC
n0m-d/CVE-2018-0114-Go
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISCO
abrir ↗GitHub PoC★ 56
Advanced WinRAR Path Traversal Exploit Tool for CVE-2025-8088
Path traversal vulnerability in WinRAR
93RISCO
abrir ↗GitHub PoC
CVE-2025-53770 - SharePoint
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC
Exploration of the Follina (CVE-2022-30190) Microsoft Office vulnerability, including a detailed analysis, proof-of-concept exploitation in a controlled lab, and mitigation strategies. For educational and research purposes only.
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC
CyprianAtsyor/ToolShell-CVE-2025-53770-SharePoint-Exploit-Lab-LetsDefend
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC
PoC exploit for XWiki Remote Code Execution Vulnerability (CVE-2025-24893)
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir ↗GitHub PoC
benguelmas/cve-2017-0143
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir ↗GitHub PoC★ 7
CVE-2025-32433 PoC: Unauthenticated Remote Code Execution (RCE) in Erlang/OTP SSH. A proof-of-concept exploit for CVE-2025-32433
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir ↗GitHub PoC★ 54
POCs for CVE-2025-50154 and CVE-2025-59214, zero day vulnerabilities on windows file explorer disclosing NTLMv2-SSP without user interaction. It is a bypass for the CVE-2025-24054 Security Patch
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir ↗GitHub PoC★ 71
CVE-2025-8088 WinRAR Proof of Concept (PoC-Exploit)
Path traversal vulnerability in WinRAR
93RISCO
abrir ↗GitHub PoC★ 3
zenzue/CVE-2025-50154
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir ↗GitHub PoC
Dissecting CVEin Chrome
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially expl
71RISCO
abrir ↗GitHub PoC★ 1
PoC of CVE-2025-47533 Clobber RCE
Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes
63RISCO
abrir ↗GitHub PoC
Proof of concept for the vulnerability CVE-2025-50428: Authenticated OS Command Injection in RaspAP
In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script.
48RISCO
abrir ↗GitHub PoC
oob_entry tfp0 kernel exploit for armv7 iOS (iOS 3.0–10.3.4), using CVE-2023-32434. We will publish a write-up detailing the methods in the coming weeks. 🐙
An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11
83RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.