Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
13.282 exploits
GitHub PoC46
WinRAR 0day CVE-2025-8088 PoC RAR Archive
CVE-2025-8088HIGHsob ataque12 ago 2025
Path traversal vulnerability in WinRAR
93RISCO
abrir
GitHub PoC
Berisi 2 program C dari exploitDB untuk melakukan privillage eskalation untuk ubuntu 16.04
CVE-2017-1699512 ago 2025
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISCO
abrir
GitHub PoC1
00xCanelo/CVE-2024-47533-PoC
CVE-2024-47533CRITICAL12 ago 2025
Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes
63RISCO
abrir
GitHub PoC
Program python untuk melakukan RCE pada drupal versi 7.56
CVE-2018-7600CRITICALsob ataqueransomware12 ago 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC1
Esse script explora a vulnerabilidade CVE-2025-20124 — uma falha de Java Deserialization no Cisco ISE (Identity Services Engine) que permite Remote Code Execution (RCE).
CVE-2025-20124CRITICAL12 ago 2025
Cisco Identity Services Engine Java Deserialization Vulnerability
53RISCO
abrir
GitHub PoC8
CVE-2024-47533 is a critical authentication bypass vulnerability in Cobbler (versions 3.0.0 to before 3.2.3 and 3.3.7) allowing unauthenticated remote code execution via the XMLRPC interface.
CVE-2024-47533CRITICAL12 ago 2025
Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes
63RISCO
abrir
GitHub PoC1
PoC of CVE-2018-7600
CVE-2018-7600CRITICALsob ataqueransomware12 ago 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC
These PoC python scripts test the Kemp LoadMaster for remote code execution.
CVE-2024-7591CRITICAL11 ago 2025
Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection
75RISCO
abrir
GitHub PoC3
CVE-2024-47533: Cobbler Authentication Bypass & Code Execution
CVE-2024-47533CRITICAL11 ago 2025
Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes
63RISCO
abrir
GitHub PoC
Bash POC script for RCE vulnerability in Apache 2.4.49
CVE-2021-41773HIGHsob ataqueransomware11 ago 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
alexander47777/CVE-2016-10033
CVE-2016-10033CRITICALsob ataque11 ago 2025
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir
GitHub PoC1
Este script explora a vulnerabilidade CVE-2025-24813 em versões específicas do Apache Tomcat, permitindo execução remota de código (RCE) através de um vetor de desserialização Java e abuso do método HTTP PUT para gravação arbitrária de arquivos de sessão.
CVE-2025-24813CRITICALsob ataque11 ago 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC
Update the old POC of CVE-2025-5777 Citrix NetScaler Memory leak
CVE-2025-5777CRITICALsob ataqueransomware11 ago 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
GitHub PoC4
Python exploit for vsftpd 2.3.4 - Backdoor Command Execution
CVE-2011-252311 ago 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
GitHub PoC2
cve-2025-8088_detection
CVE-2025-8088HIGHsob ataque11 ago 2025
Path traversal vulnerability in WinRAR
93RISCO
abrir
GitHub PoC10
Python tool for safe archive handling, path traversal awareness, and secure extraction. Inspired by CVE-2025-8088.
CVE-2025-8088HIGHsob ataque10 ago 2025
Path traversal vulnerability in WinRAR
93RISCO
abrir
GitHub PoC
kylew1004/cve-2017-5941-poc-docker-lab
CVE-2017-594110 ago 2025
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RISCO
abrir
GitHub PoC
BiiTts/POC-IngressNightmare-CVE-2025-1974
CVE-2025-1974CRITICAL10 ago 2025
ingress-nginx admission controller RCE escalation
85RISCO
abrir
GitHub PoC6
POC for CVE-2025-4404
CVE-2025-4404CRITICAL09 ago 2025
Freeipa: idm: privilege escalation from host to domain admin in freeipa
48RISCO
abrir
GitHub PoC4
POC exploit for CVE-2025-24893
CVE-2025-24893CRITICALsob ataque09 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC
RAJMadhusankha/Shellshock-CVE-2014-6271-Exploitation-and-Analysis
CVE-2014-6271CRITICALsob ataque09 ago 2025
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC
A POC for CVE-2025-24893 written in python
CVE-2025-24893CRITICALsob ataque09 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC
TryHackMe CTF writeup — WordPress RCE via CVE-2024-25600, crypto miner forensics, and LockBit ransomware group identification
CVE-2024-25600CRITICAL09 ago 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir
GitHub PoC13
This CVE addresses a vulnerability in sudo versions 1.9.14 to 1.9.17, enabling unauthorized local privilege escalation to root access.
CVE-2025-32463CRITICALsob ataque08 ago 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC
This repository contains a completely original and self-developed Proof-of-Concept (PoC) for CVE-2018-7600, also known as Drupalgeddon 2 — a critical remote code execution vulnerability affecting Drupal 7 and 8 core versions.
CVE-2018-7600CRITICALsob ataqueransomware08 ago 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC6
This vulnerability could allow a malicious user to execute remote code by sending appropriately crafted requests to the default search engine SolrSearch
CVE-2025-24893CRITICALsob ataque08 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC
一个由AI生成的漏洞验证应用
CVE-2022-22947CRITICALsob ataque08 ago 2025
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC
POC
CVE-2025-24893CRITICALsob ataque08 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC
XWiki 15.10.11, 16.4.1 and 16.5.0RC1 Unauthenticated Remote code execution POC
CVE-2025-24893CRITICALsob ataque08 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC2
Exploit demonstrating an authentication bypass vulnerability in the web interface of Belkin F9K1009 and F9K1010 routers.
CVE-2025-8730CRITICAL08 ago 2025
Belkin F9K1009/F9K1010 Web Interface hard-coded credentials
48RISCO
abrir
anteriorpágina 126 / 443próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.