Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
13.282 exploits
GitHub PoC
This project demonstrates a simulated exploitation of the WinRAR vulnerability CVE-2023-38831 to execute a reverse shell. The purpose of this task was to showcase how attackers can weaponize compressed archive files to gain remote access to a target machine.
CVE-2023-38831HIGHsob ataqueransomware03 ago 2025
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC
A short and sweet simple exploit script for the CVE-2012-2982 Authenticated RCE vulnerability in the /file/show.cgi/bin endpoint.
CVE-2012-298203 ago 2025
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISCO
abrir
GitHub PoC5
this is a poc for the CVE-2025-24893
CVE-2025-24893CRITICALsob ataque03 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC
dhiaZnaidi/CVE-2025-24893-PoC
CVE-2025-24893CRITICALsob ataque03 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC5
Modified exploit for CVE-2025-24893
CVE-2025-24893CRITICALsob ataque03 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC
PoC for CVE-2025-48384
CVE-2025-48384HIGHsob ataque03 ago 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC
fluoworite/CVE-2025-48384-sub
CVE-2025-48384HIGHsob ataque03 ago 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC
beishanxueyuan/CVE-2025-48384
CVE-2025-48384HIGHsob ataque03 ago 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC
CVE-2024-2771 Proof-of-Concept
CVE-2024-2771CRITICAL03 ago 2025
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Settings Update and Limited Privilege Escalation
63RISCO
abrir
GitHub PoC
This is a small script for the rce vulnerability for CVE-2025-24893. It supports basic input/output
CVE-2025-24893CRITICALsob ataque03 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC
Reverse Shell Payload for CVE-2025-24893
CVE-2025-24893CRITICALsob ataque03 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC6
PoC exploits CVE-2025-24893 , a remote code execution (RCE) vulnerability in XWiki caused by improper sandboxing in Groovy macros rendered asynchronously. It allows arbitrary command execution through injection into RSS-based SolrSearch endpoints.
CVE-2025-24893CRITICALsob ataque03 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC
Demo web server
CVE-2025-34100CRITICAL02 ago 2025
BuilderEngine 3.5.0 RCE via Unauthenticated Arbitrary File Upload
63RISCO
abrir
GitHub PoC1
A critical vulnerability in Microsoft SharePoint Server allows unauthenticated remote code execution via deserialization of untrusted data. Microsoft is aware of active exploitation; apply CVE mitigations immediately. Severity: Critical.
CVE-2025-53770CRITICALsob ataqueransomware02 ago 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC3
Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation
CVE-2025-5394CRITICAL02 ago 2025
Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation
75RISCO
abrir
GitHub PoC1
AdnanApriliyansyahh/CVE-2022-1592
CVE-2022-1592CRITICAL02 ago 2025
Server-Side Request Forgery in scout in clinical-genomics/scout
48RISCO
abrir
GitHub PoC
CVE-2025-46811
CVE-2025-46811CRITICAL02 ago 2025
SUSE Multi Linux Manager allows code execution via unprotected websocket endpoint
53RISCO
abrir
GitHub PoC1
Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation
CVE-2025-5394CRITICAL02 ago 2025
Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation
75RISCO
abrir
GitHub PoC2
PoC for CVE-2025-41373 Authenticated SQL Injection in Gandia Integra Total v2.1.2217.3–4.4.2236.1
CVE-2025-41373HIGH01 ago 2025
SQL injection vulnerability in Gandia Integra Total
41RISCO
abrir
GitHub PoC1
This Python exploit targets a critical unauthenticated Remote Code Execution (RCE) vulnerability in the BigUp plugin of SPIP CMS (≤ 4.3.1, 4.2.15, 4.1.17). It abuses the bigup_retrouver_fichiers parameter, allowing attackers to execute arbitrary PHP via upload progress features, without authentication.
CVE-2024-8517CRITICAL01 ago 2025
SPIP Bigup Multipart File Upload OS Command Injection
85RISCO
abrir
GitHub PoC2
Comprehensive Android security vulnerability demonstrations featuring CVE-2017-13156 (Janus), broadcast receiver exploitation, external storage threats, and rooted device attacks. Educational PoCs with working code, exploitation scripts, and security controls for developers and researchers. To be updated...
CVE-2017-1315601 ago 2025
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RISCO
abrir
GitHub PoC
Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class.
CVE-2017-1262901 ago 2025
Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction wi
60RISCO
abrir
GitHub PoC
CVE-2025-48703 là lỗ hổng mức độ nghiêm trọng trong CentOS Web Panel (CWP) cho phép kẻ tấn công không xác thực (unauthenticated) có thể thực thi mã từ xa (RCE) thông qua bỏ qua cơ chế xác thực và thực thi câu lệnh hệ thống. Lỗ hổng ảnh hưởng CWP từ phiên bản 0.9.8.1204 trở về trước, và đã được vá trên phiên bản mới nhất 0.9.8.1205.
CVE-2025-48703CRITICALsob ataque01 ago 2025
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell
100RISCO
abrir
GitHub PoC
Spring4Shell (POC)
CVE-2022-22965CRITICALsob ataque01 ago 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC
Python-based simulated firewall to detect and block Spring4Shell (CVE-2022-22965) exploit attempts. This project filters HTTP requests by identifying malicious payload patterns using a custom firewall_server.py and tests them with test_requests.py.
CVE-2022-22965CRITICALsob ataque01 ago 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC
test for CVE-2025-48384
CVE-2025-48384HIGHsob ataque01 ago 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC
maxntv/CVE-2023-22894-PoC
CVE-2023-22894CRITICAL31 jul 2025
Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting
48RISCO
abrir
GitHub PoC90
CVE-2025-30406 ViewState Exploit PoC
CVE-2025-30406CRITICALsob ataque31 jul 2025
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
100RISCO
abrir
GitHub PoC
mouftan/CVE-2022-44268
CVE-2022-44268MEDIUM31 jul 2025
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISCO
abrir
GitHub PoC2
PoC for CVE-2025-54589 – a reflected XSS vulnerability in Copyparty ≤ 1.18.6.
CVE-2025-54589MEDIUM31 jul 2025
copyparty Reflected XSS via Filter Parameter
48RISCO
abrir
anteriorpágina 128 / 443próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.