Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 20.003GitHub PoC 13.307VulnCheck XDB 8.182Nuclei 4.217Metasploit 3.462✓ só verificadosrecentespopularesrisco
13.282 exploits
GitHub PoC★ 4
PoC for CVE-2025-5777 – Auth Bypass and RCE in Trend Micro Apex Central
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir ↗GitHub PoC★ 8
Log4Shell / Log4J Payload - CVE-2021-45046 and CVE-2022-42889
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir ↗GitHub PoC★ 1
PoC exploit for CVE-2025-7766 – XXE vulnerability leading to potential RCE.
Lantronix Provisioning Manager Improper Restriction of XML External Entity Reference
41RISCO
abrir ↗GitHub PoC★ 5
A sophisticated, wizard-driven Python exploit tool targeting CVE-2025-53770, a critical (CVSS 9.8) unauthenticated remote code execution (RCE) vulnerability in on-premises Microsoft SharePoint Server (2016, 2019, Subscription Edition)
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC
wyyazjjl/CVE-2024-45195
Apache OFBiz: Confused controller-view authorization logic (forced browsing)
100RISCO
abrir ↗GitHub PoC
Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC★ 31
Integer overflow in FreeType software, which also affects Chrome
An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when
76RISCO
abrir ↗GitHub PoC★ 8
Log4Shell / Log4J Payload - CVE-2021-45046 and CVE-2022-42889
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISCO
abrir ↗GitHub PoC
Proof-of-concept LFI Scanner: Automated detection of /etc/passwd exposures via directory traversal and regex matching.
Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Se
100RISCO
abrir ↗GitHub PoC★ 1
WordPress联系表单插件 - 未授权任意文件上传漏洞
Website Contact Form With File Upload <= 1.3.4 - Arbitrary File Upload
63RISCO
abrir ↗GitHub PoC★ 4
How CVE-2025-29774 Vulnerabilities and the SIGHASH_SINGLE Bug Threaten Multi-Signature Wallet Operational Methods with Fake RawTX
xml-crypto Vulnerable to XML Signature Verification Bypass via Multiple SignedInfo References
48RISCO
abrir ↗GitHub PoC
shan0ar/cve-2025-32756
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RISCO
abrir ↗GitHub PoC
A comprehensive Python testing tool for CVE-2023-44487, the HTTP/2 Rapid Reset vulnerability. This enhanced version provides granular control over testing parameters, multiple attack patterns, and advanced monitoring capabilities.
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISCO
abrir ↗GitHub PoC★ 1
GURJOTEXPERT/CVE-2023-3460
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISCO
abrir ↗GitHub PoC★ 1
tripoloski1337/CVE-2025-53770-scanner
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC★ 1
imbas007/CVE-2025-53770-Vulnerable-Scanner
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC
KiPhuong/cve-2024-3552
Web Directory Free < 1.7.0 - Unauthenticated SQL Injection
75RISCO
abrir ↗GitHub PoC
GreenForceNetworks/Toolshell_CVE-2025-53770
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC★ 2
A Python-based reconnaissance scanner for safely identifying potential exposure to SharePoint vulnerability CVE-2025-53770.
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC
cve-2024-32002
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir ↗GitHub PoC★ 1
WordPress WPBookit ≤ 1.0.4 Unauthenticated File Upload Exploit
WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload
63RISCO
abrir ↗GitHub PoC
Reverse Shell CVE for iDRAC 7 & 8 with firmware 2.52.52.52 and below.
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute
60RISCO
abrir ↗GitHub PoC
Gogs Under Attack: Unpacking the Critical SSH Vulnerability (CVE-2024–39930)
The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code
48RISCO
abrir ↗GitHub PoC★ 1
gmh5225/CVE-2025-6558-exp
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote at
71RISCO
abrir ↗GitHub PoC★ 58
Unauthenticated Remote Code Execution via unsafe deserialization in Microsoft SharePoint Server (CVE-2025-53770)
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC
Unauthenticated Remote Code Execution via unsafe deserialization in Microsoft SharePoint Server (CVE-2025-53770)
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC
CVE-2025-32463
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗GitHub PoC★ 11
A critical zero-auth RCE vulnerability in SharePoint (CVE-2025-53770), now exploited in the wild, building directly on the spoofing flaw CVE-2025-49706.
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.