Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 20.003GitHub PoC 13.307VulnCheck XDB 8.182Nuclei 4.217Metasploit 3.462✓ só verificadosrecentespopularesrisco
13.307 exploits
GitHub PoC
POC script for CVE-2025-32462 a vulnerability in sudo
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RISCO
abrir ↗GitHub PoC★ 1
depers-rus/CVE-2007-4559
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows
53RISCO
abrir ↗GitHub PoC★ 1
Detects Apache HTTP Server path traversal vulnerabilities (CVE-2021-41773, CVE-2021-42013) by checking for exposure of /etc/passwd through various traversal techniques.
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗GitHub PoC★ 9
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RISCO
abrir ↗GitHub PoC★ 2
WordPress Custom Login And Signup Widget Plugin <= 1.0 is vulnerable to Arbitrary Code Execution
WordPress Custom Login And Signup Widget plugin <= 1.0 - Arbitrary Code Execution vulnerability
63RISCO
abrir ↗GitHub PoC★ 54
Wing FTP Server Remote Code Execution (RCE) Exploit (CVE-2025-47812)
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir ↗GitHub PoC★ 527
Escalation of Privilege to the root through sudo binary with chroot option. CVE-2025-32463
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗GitHub PoC★ 31
Proof of Concept for CVE-2025-6218, demonstrating the exploitation of a vulnerability in WinRAR versions 7.11 and under, involving improper handling of archive extraction paths.
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
93RISCO
abrir ↗GitHub PoC★ 1
4f-kira/CVE-2025-32463
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗GitHub PoC
DirtyPipe (CVE-2022-0847) exploit written in Rust
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir ↗GitHub PoC★ 29
CVE-2025-32463 Proof of concept
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗GitHub PoC★ 1
Proof of concept of CVE-2025-20282, the perfect 10.
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
53RISCO
abrir ↗GitHub PoC★ 2
7r00t/cve-2025-32463-lab
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗GitHub PoC★ 10
End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full memory and network forensic analysis.
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗GitHub PoC★ 13
Simple exploit for Wing FTP Server RCE (CVE-2025-47812) to run commands and get a reverse shell. For educational use only.
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir ↗GitHub PoC
Simulação educacional de exploração de falha em dispositivos IoT com base no CVE-2017-17761
An issue was discovered on Ichano AtHome IP Camera devices. The device runs the "noodles" binary - a service on port 130
23RISCO
abrir ↗GitHub PoC★ 17
详细讲解CitrixBleed 2 — CVE-2025-5777(越界泄漏)PoC 和检测套件
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir ↗GitHub PoC
Citrix Bleed 2 PoC
Memory overflow vulnerability leading to unintended control flow and Denial of Service
78RISCO
abrir ↗GitHub PoC★ 2
This Python script is a Proof-of-Concept (PoC) scanner for detecting the vulnerability CVE-2024-40898, which affects Apache HTTP Server’s SSL certificate validation.
Apache HTTP Server: SSRF with mod_rewrite in server/vhost context on Windows
48RISCO
abrir ↗GitHub PoC★ 1
CVE‑2025‑30208 is a medium-severity arbitrary file read vulnerability in the Vite development server (a popular frontend build tool)
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗GitHub PoC
Exploit Code for CVE-2024-39930 gogs ssh server RCE
The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code
48RISCO
abrir ↗GitHub PoC★ 13
A simple proof of concept for WinRAR Path Traversal | RCE | CVE-2025-6218
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
93RISCO
abrir ↗GitHub PoC
obscura-cert/CVE-2025-31650
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
53RISCO
abrir ↗GitHub PoC★ 1
POC for PDF JS' CVE-2024-4367 vuln
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir ↗GitHub PoC★ 1
obscura-cert/CVE-2025-33073
Windows SMB Client Elevation of Privilege Vulnerability
93RISCO
abrir ↗GitHub PoC
aninfosec/CVE-2024-43425-Poc
Moodle: remote code execution via calculated question types
78RISCO
abrir ↗GitHub PoC★ 10
CVE‑2025‑30208 is a medium-severity arbitrary file read vulnerability in the Vite development server (a popular frontend build tool)
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗GitHub PoC★ 3
Proof-of-concept and analysis for CVE-2025-32711
M365 Copilot Information Disclosure Vulnerability
48RISCO
abrir ↗GitHub PoC
The objective of this project was to assess a remote host for the Heartbleed vulnerability (CVE-2014-0160), verify its presence, and exploit it to extract potentially sensitive information from server memory over the TLS protocol.
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.