Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
13.282 exploits
GitHub PoC2
PoC for CVE-2025-54589 – a reflected XSS vulnerability in Copyparty ≤ 1.18.6.
CVE-2025-54589MEDIUM31 jul 2025
copyparty Reflected XSS via Filter Parameter
48RISCO
abrir
GitHub PoC90
CVE-2025-30406 ViewState Exploit PoC
CVE-2025-30406CRITICALsob ataque31 jul 2025
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
100RISCO
abrir
GitHub PoC4
CVE‑2025‑5394 WP Alone ≤ 7.8.3
CVE-2025-5394CRITICAL31 jul 2025
Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation
75RISCO
abrir
GitHub PoC
This rough PoC checker script tests targets for CVE-2025-33073 vulnerability by attempting to perform NTLM reflection attacks using NTLM auth coercion via samba RPC, to do this you need to have account with access to the samba.
CVE-2025-33073HIGHsob ataque31 jul 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RISCO
abrir
GitHub PoC21
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVE-2025-29824HIGHsob ataqueransomware30 jul 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC1
Automates vulnerability check for sudo versions and privilege escalation via sudoedit if exploitable, helping users test and gain root access.
CVE-2023-22809HIGH30 jul 2025
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISCO
abrir
GitHub PoC4
本项目基于 Docker 搭建了一个用于复现和测试 sudo 本地权限提升漏洞 CVE-2025-32463 的实验环境。
CVE-2025-32463CRITICALsob ataque30 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC1
🛠 Exploit the CVE-2025-14847 vulnerability in MongoDB to disclose sensitive heap memory using a Python script that analyzes responses for new leaked data.
CVE-2025-14847HIGHsob ataque30 jul 2025
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir
GitHub PoC
CitrixBleed 2 NetScaler honeypot logs
CVE-2025-5777CRITICALsob ataqueransomware30 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
GitHub PoC
Technical Details and Exploit for CVE-2025-50460
CVE-2025-50460CRITICAL30 jul 2025
A remote code execution (RCE) vulnerability exists in the ms-swift project version 3.3.0 due to unsafe deserialization i
48RISCO
abrir
GitHub PoC1
Technical Details and Exploit for CVE-2025-50472
CVE-2025-50472CRITICAL30 jul 2025
The modelscope/ms-swift library thru 2.6.1 is vulnerable to arbitrary code execution through deserialization of untruste
48RISCO
abrir
GitHub PoC2
A C‑based proof‑of‑concept exploit for CVE‑2025‑54769, automating the creation and upload of a malicious Perl CGI script to LPAR2RRD’s upgrade endpoint, leveraging directory traversal for remote code execution.
CVE-2025-54769HIGH30 jul 2025
KL-001-2025-016: Xorux LPAR2RRD File Upload Directory Traversal
41RISCO
abrir
GitHub PoC
rgvillanueva28/vulnbox-easy-CVE-2025-29927
CVE-2025-29927CRITICAL30 jul 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
Real-time anomaly detection system for Apache Struts CVE-2017-5638 exploit using streaming analytics, 3-gram byte analysis, and Count-Min Sketch. Detects RCE attacks without signatures, with <5ms latency and <0.1% false positives.
CVE-2017-5638CRITICALsob ataqueransomware30 jul 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC
Combined PoCs for rConfig: SQL Injection (CVE-2020-10220) & Command Injection (CVE-2020-10879)
CVE-2020-1022030 jul 2025
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php
60RISCO
abrir
GitHub PoC
→ poc for CVE-2025-29927
CVE-2025-29927CRITICAL29 jul 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC4
Immersive-Labs-Sec/SharePoint-CVE-2025-53770-POC
CVE-2025-53770CRITICALsob ataqueransomware29 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
Ai相关
CVE-2025-54381CRITICAL29 jul 2025
BentoML is Vulnerable to an SSRF Attack Through File Upload Processing
53RISCO
abrir
GitHub PoC1
DLL00P/CVE-2021-1675
CVE-2021-1675HIGHsob ataqueransomware29 jul 2025
Windows Print Spooler Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
Proof of Concept exploit for CVE‑2021‑43857: Authenticated Remote Code Execution in Gerapy (<0.9.8). Updated and automated version of the original Exploit‑DB PoC for educational and authorized testing purposes only.
CVE-2021-43857CRITICAL29 jul 2025
Gerapy may contain remote code execution vulnerability
60RISCO
abrir
GitHub PoC2
CVE-2025-32463 - Sudo Chroot Privilege Escalation Exploit
CVE-2025-32463CRITICALsob ataque29 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC
r0otk3r/CVE-2025-2294
CVE-2025-2294CRITICAL28 jul 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISCO
abrir
GitHub PoC
r3xbugbounty/CVE-2025-53770
CVE-2025-53770CRITICALsob ataqueransomware28 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC2
Exploit for CVE-2022-35411 — Unauthenticated RCE in rpc.py (<= 0.6.0)
CVE-2022-3541128 jul 2025
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header i
35RISCO
abrir
GitHub PoC2
Poc for Unauthenticated Admin Session Hijack - Pie Register Plugin (≤ 3.7.1.4)
CVE-2025-34077CRITICAL28 jul 2025
WordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCE
63RISCO
abrir
GitHub PoC2
A repository containing a PoC exploit for CVE‑2025‑8191 in Swagger UI, leveraging XSS injection to exfiltrate session cookies.
CVE-2025-8191MEDIUM28 jul 2025
macrozheng mall Swagger UI index.html cross site scripting
33RISCO
abrir
GitHub PoC
imbas007/CVE-2025-32429-Checker
CVE-2025-32429CRITICAL28 jul 2025
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
85RISCO
abrir
GitHub PoC1
The vulnerability was found by Rich Mirch. More details on it here: https://cxsecurity.com/issue/WLB-2025070022
CVE-2025-32462LOW28 jul 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RISCO
abrir
GitHub PoC
Tools for detecting and assessing systems vulnerable to CVE-2025-53770 (CWE-502: Deserialization of Untrusted Data).
CVE-2025-53770CRITICALsob ataqueransomware28 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
🎯 Vulnerability scanner for SharePoint servers affected by CVE-2025-53770. Detects unsafe deserialization using ToolPane.aspx with a crafted base64+gzip payload. 🛡️ Developed by Ahmed Tamer.
CVE-2025-53770CRITICALsob ataqueransomware28 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir
anteriorpágina 129 / 443próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.