Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
13.307 exploits
GitHub PoC1
Python Exploit for TP-Link TL-WR940N/TL-WR841N Command Injection Vulnerability
CVE-2023-33538HIGHsob ataque22 jun 2025
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerabili
83RISCO
abrir
GitHub PoC17
A script that gives you the credentials of a Pterodactyl panel vulnerable to CVE-2025-49132
CVE-2025-49132CRITICAL22 jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISCO
abrir
GitHub PoC
CVE 2018-9035: CSV Injection in Wordpress with plugin Contact Form 7 to Database Extension 2.10.3
CVE-2018-903522 jun 2025
CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPr
23RISCO
abrir
GitHub PoC
CVE-2024-3094
CVE-2024-3094CRITICAL21 jun 2025
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC
tomcat CVE-2025-24813 反序列化RCE环境
CVE-2025-24813CRITICALsob ataque21 jun 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC
PoC environment and exploit for the Apache Tomcat on Windows Remote Code Execution Vulnerability
CVE-2017-12615HIGHsob ataqueransomware21 jun 2025
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISCO
abrir
GitHub PoC
CVE-2021-44228 Vulnerability Reproduction Environment CVE-2021-44228 漏洞复现环境
CVE-2021-44228CRITICALsob ataqueransomware21 jun 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC2
punitdarji/Grafana-cve-2025-4123
CVE-2025-4123HIGH21 jun 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISCO
abrir
GitHub PoC
Tiny File Manager <= 2.4.6 - Remote Code Execution (RCE)
CVE-2021-4096420 jun 2025
A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to
23RISCO
abrir
GitHub PoC
Rejetto HttpFileServer 2.3.x - Remote Command Execution (RevShell)
CVE-2014-6287CRITICALsob ataque20 jun 2025
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir
GitHub PoC
CVE-2024-50562 is a session management vulnerability in Fortinet SSL-VPN portals
CVE-2024-50562MEDIUM20 jun 2025
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, ve
33RISCO
abrir
GitHub PoC
This is a proof-of-concept Metasploit module exploit for CVE-2015-1578, a buffer overflow vulnerability in Achat 0.150 beta7 on Windows. Exploitation leads to remote code execution via a crafted UDP packet.
CVE-2015-157820 jun 2025
Multiple open redirect vulnerabilities in u5CMS before 3.9.4 allow remote attackers to redirect users to arbitrary web s
23RISCO
abrir
GitHub PoC
typicalsmc/CVE-2025-49132-PoC
CVE-2025-49132CRITICAL20 jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISCO
abrir
GitHub PoC
This is a proof-of-concept exploit for CVE-2015-1578, a buffer overflow vulnerability in Achat 0.150 beta7 on Windows. Exploitation leads to remote code execution via a crafted UDP packet.
CVE-2015-157819 jun 2025
Multiple open redirect vulnerabilities in u5CMS before 3.9.4 allow remote attackers to redirect users to arbitrary web s
23RISCO
abrir
GitHub PoC1
Threat intelligence report analyzing the xz-utils backdoor vulnerability (CVE-2024-3094)
CVE-2024-3094CRITICAL19 jun 2025
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC1
CVE-2025-3248 — Langflow RCE Exploit
CVE-2025-3248CRITICALsob ataqueransomware19 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
GitHub PoC
Unauthenticated RCE via Webmin Backdoor (CVE-2019–15107)
CVE-2019-15107CRITICALsob ataqueransomware19 jun 2025
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
GitHub PoC
DevinLiggins14/SMB-PenTest-Exploiting-CVE-2007-2447-on-Metasploitable-2
CVE-2007-244719 jun 2025
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir
GitHub PoC
Exploit for CVE-2011-2523.
CVE-2011-252319 jun 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
GitHub PoC
CVE-2019–11043: PHP-FPM Nginx Remote Code Execution Vulnerability
CVE-2019-11043HIGHsob ataqueransomware19 jun 2025
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC
punitdarji/roundcube-cve-2025-49113
CVE-2025-49113CRITICALsob ataque18 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
GitHub PoC3
Proof-of-Concept for CVE-2025-33053 Exploiting WebDAV with .url file delivery to demonstrate realistic remote code execution. Includes a decoy PDF payload and a video-only showcase of potential command-and-control capabilities.
CVE-2025-33053HIGHsob ataque18 jun 2025
Internet Shortcut Files Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC1
CVE-2025-33053 Checker and PoC
CVE-2025-33053HIGHsob ataque18 jun 2025
Internet Shortcut Files Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
Exploit for Langflow AI Remote Code Execution (Unauthenticated)
CVE-2025-3248CRITICALsob ataqueransomware18 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
GitHub PoC1
imbas007/CVE-2025-3248
CVE-2025-3248CRITICALsob ataqueransomware18 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
GitHub PoC18
CVE-2025-3248 Langflow RCE Exploit
CVE-2025-3248CRITICALsob ataqueransomware17 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
GitHub PoC
A hands-on vulnerability assessment and exploitation of a Windows 7 VM using the EternalBlue (CVE-2017-0143) exploit. Includes scanning, exploitation with Metasploit, post-exploitation, and remediation steps in a controlled lab environment.
CVE-2017-0143HIGHsob ataqueransomware17 jun 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
GitHub PoC
Explicação + Lab no THM
CVE-2025-49113CRITICALsob ataque17 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
GitHub PoC
EdouardosStav/CVE-2019-15107-RCE-WebMin
CVE-2019-15107CRITICALsob ataqueransomware17 jun 2025
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
GitHub PoC
Kernel Pool Overflow Exploit targeting CVE-2021-31956
CVE-2021-31956HIGHsob ataque17 jun 2025
Windows NTFS Elevation of Privilege Vulnerability
76RISCO
abrir
anteriorpágina 142 / 444próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.