Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
13.307 exploits
GitHub PoC21
Unauthenticated Python PoC for CVE-2025-20281 RCE against ISE ERS API
CVE-2025-20281CRITICALsob ataque27 jun 2025
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC3
Proof-of-concept and analysis for CVE-2025-32711
CVE-2025-32711CRITICAL27 jun 2025
M365 Copilot Information Disclosure Vulnerability
48RISCO
abrir
GitHub PoC
The objective of this project was to assess a remote host for the Heartbleed vulnerability (CVE-2014-0160), verify its presence, and exploit it to extract potentially sensitive information from server memory over the TLS protocol.
CVE-2014-0160HIGHsob ataque27 jun 2025
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC
loganpkinfosec/CVE-2020-7378
CVE-2020-7378CRITICAL27 jun 2025
CRIXP OpenCRX Unverified Password Change
48RISCO
abrir
GitHub PoC4
Remote Code execution in CentOS web panel
CVE-2025-48703CRITICALsob ataque26 jun 2025
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell
100RISCO
abrir
GitHub PoC7
Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation
CVE-2025-4334CRITICAL26 jun 2025
Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation
63RISCO
abrir
GitHub PoC5
Script para determinar si Citrix es vulnerable al CVE-2025-6543
CVE-2025-6543CRITICALsob ataque26 jun 2025
Memory overflow vulnerability leading to unintended control flow and Denial of Service
78RISCO
abrir
GitHub PoC
Batch RCE scanner for vulnerable vBulletin instances using replaceAdTemplate exploit.
CVE-2025-48828CRITICAL25 jun 2025
Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the t
75RISCO
abrir
GitHub PoC
TI WooCommerce Wishlist (WordPress plugin) <= 2.9.2 CVE-2025-47577 PoC
CVE-2025-47577CRITICAL25 jun 2025
WordPress TI WooCommerce Wishlist plugin <= 2.9.2 - Arbitrary File Upload Vulnerability
63RISCO
abrir
GitHub PoC
luckyman2907/SMB-Protocol-Vulnerability_CVE-2017-0144
CVE-2017-0144HIGHsob ataqueransomware25 jun 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
GitHub PoC
Poc - CVE-2025-49132
CVE-2025-49132CRITICAL25 jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISCO
abrir
GitHub PoC
Exploit para escalada de privilegios en Linux basado en la vulnerabilidad Dirty Cow (CVE-2016-5195). Incluye binario, código fuente e instrucciones para su uso en entornos controlados.
CVE-2016-5195HIGHsob ataque25 jun 2025
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC
hdgokani/CVE-2018-1273
CVE-2018-1273CRITICALsob ataqueransomware25 jun 2025
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property
100RISCO
abrir
GitHub PoC
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
CVE-2025-3248CRITICALsob ataqueransomware25 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
GitHub PoC2
ademto/wordpress-cve-2024-10924-pentest
CVE-2024-10924CRITICAL25 jun 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir
GitHub PoC
C-based PoC for CVE-2019-5736
CVE-2019-573625 jun 2025
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
GitHub PoC
TI WooCommerce Wishlist (WordPress plugin) <= 2.8.2 CVE-2024-43917 PoC
CVE-2024-43917CRITICAL25 jun 2025
WordPress TI WooCommerce Wishlist plugin <= 2.8.2 - SQL Injection vulnerability
68RISCO
abrir
GitHub PoC
Rust Macros No Recoil Guide 🚀 Boost Aim Like a Pro in C and Python
CVE-2025-0411HIGHsob ataque24 jun 2025
7-Zip Mark-of-the-Web Bypass Vulnerability
83RISCO
abrir
GitHub PoC5
PoCs for CVE-2025-49132
CVE-2025-49132CRITICAL24 jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISCO
abrir
GitHub PoC
CVE-2025-4322 – Unauthenticated Privilege Escalation via Password Update "Account Takeover" 🔥
CVE-2025-4322CRITICAL24 jun 2025
Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover
68RISCO
abrir
GitHub PoC4
Pterodactyl翼龙面板CVE-2025-49132批量检测☝️🤓
CVE-2025-49132CRITICAL23 jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISCO
abrir
GitHub PoC
CVE-2025-3248
CVE-2025-3248CRITICALsob ataqueransomware23 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
GitHub PoC7
Remote Code Execution Exploit for Langflow (CVE-2025-3248) - [ By S4Tech ]
CVE-2025-3248CRITICALsob ataqueransomware23 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
GitHub PoC1
CVE-2023-33538 - TP-Link Command Injection Ruby module for Metasploit Framework
CVE-2023-33538HIGHsob ataque23 jun 2025
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerabili
83RISCO
abrir
GitHub PoC3
Mass-CVE-2025-3248
CVE-2025-3248CRITICALsob ataqueransomware23 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
GitHub PoC
cuerv0x/CVE-2015-6967
CVE-2015-696723 jun 2025
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to
50RISCO
abrir
GitHub PoC2
Check a list of Pterodactyl panels for vulnerabilities from a file.
CVE-2025-49132CRITICAL23 jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISCO
abrir
GitHub PoC2
Exploit (C) CVE-2024-4577 on PHP CGI
CVE-2024-4577CRITICALsob ataqueransomware23 jun 2025
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
gmh5225/CVE-2025-1562
CVE-2025-1562CRITICAL22 jun 2025
Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit <= 3.5.3 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation
63RISCO
abrir
GitHub PoC1
Python Exploit for TP-Link TL-WR940N/TL-WR841N Command Injection Vulnerability
CVE-2023-33538HIGHsob ataque22 jun 2025
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerabili
83RISCO
abrir
anteriorpágina 141 / 444próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.