Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.990exploits catalogados
32.218CVEs com exploração pública
1.932testados em laboratório
13.307 exploits
GitHub PoC4
WordPress TI WooCommerce Wishlist Plugin <= 2.9.2 Arbitrary File Upload
CVE-2025-47577CRITICAL30 mai 2025
WordPress TI WooCommerce Wishlist plugin <= 2.9.2 - Arbitrary File Upload Vulnerability
63RISCO
abrir
GitHub PoC
MQKGitHub/Moniker-Link-CVE-2024-21413
CVE-2024-21413CRITICALsob ataque30 mai 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
This script checks for the OpenSSH 7.7 (and prior) username enumeration vulnerability (CVE-2018-15473). It sends a malformed authentication packet and interprets the SSH server’s response to identify valid usernames.
CVE-2018-15473MEDIUM30 mai 2025
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC
Automated bash script which scans an ip for potential vulnerability to eternalblue using nmap and then exploit using metasploit framework which uses the CVE-2017-0144 vulnerability[Code name: EternalBlue] in (windows 7,windows 2008 servers,etc.) to gain access to a windows 7 machine and establish a reverse meterpreter shell.
CVE-2017-0144HIGHsob ataqueransomware30 mai 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
GitHub PoC
vulnerable-nextjs-14-CVE-2025-29927
CVE-2025-29927CRITICAL29 mai 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC5
nkuty/CVE-2025-30208-31125-31486-32395
CVE-2025-30208MEDIUM29 mai 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir
GitHub PoC
thompson005/CVE-2023-22527
CVE-2023-22527CRITICALsob ataqueransomware29 mai 2025
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RISCO
abrir
GitHub PoC
Updated exploit for CVE-2021-22911 (Rocket.Chat 3.12.1 - NoSQL Injection to RCE (Unauthenticated))
CVE-2021-2291129 mai 2025
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISCO
abrir
GitHub PoC11
Critical Unauthenticated API Access in vBulletin
CVE-2025-48827CRITICAL29 mai 2025
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
85RISCO
abrir
GitHub PoC
AzkOsDev/CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware28 mai 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC2
Telerik CVE-2017-9248 Vulnerability Scanner
CVE-2017-9248CRITICALsob ataque28 mai 2025
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RISCO
abrir
GitHub PoC3
Exploited CVE-2025-24071 via SMB by hosting a .library-ms file inside a .tar archive. Using tar x from smbclient, the payload is extracted server-side without user interaction. Responder captures the NTLM hash once the target accesses the library.
CVE-2025-24071MEDIUM28 mai 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
GitHub PoC
KimJuhyeong95/cve-2024-4577
CVE-2024-4577CRITICALsob ataqueransomware27 mai 2025
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
Log4Shell (CVE-2021-44228) exploit demo for SEAS 8405. Includes a vulnerable Spring Boot app, fake LDAP server, Docker setup, MITRE mapping, incident response, and a full screen recording.
CVE-2021-44228CRITICALsob ataqueransomware27 mai 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC2
CVE-2025-24071 Proof Of Concept
CVE-2025-24071MEDIUM27 mai 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
GitHub PoC1
Perform Remote Code Execution using vulnerable API endpoint.
CVE-2025-3248CRITICALsob ataqueransomware27 mai 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
GitHub PoC
The scripts in this repository are made to abuse CVE-2024-42008 and CVE-2024-42009. Both of these CVEs are vulnerabilities found on Roundcube 1.6.7
CVE-2024-42008CRITICAL26 mai 2025
A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7
60RISCO
abrir
GitHub PoC4
JackHars/cve-2020-14008
CVE-2020-1400826 mai 2025
Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in
35RISCO
abrir
GitHub PoC2
UMChacker/CVE-2024-55591-POC
CVE-2024-55591CRITICALsob ataqueransomware26 mai 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISCO
abrir
GitHub PoC3
ov3rf1ow/CVE-2025-27363
CVE-2025-27363HIGHsob ataque26 mai 2025
An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when
76RISCO
abrir
GitHub PoC
Windows File Explorer Spoofing Vulnerability - CVE-2025-24071
CVE-2025-24071MEDIUM26 mai 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
GitHub PoC
🔐 Python-based smart scanner for CVE-2025-29927 — Next.js middleware authentication bypass vulnerability. Detects meta refresh, keyword-based redirects, and more.
CVE-2025-29927CRITICAL26 mai 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
Order Delivery Date Pro for WooCommerce < 12.3.1 - Unauthenticated Arbitrary Option Update
CVE-2025-2907CRITICAL26 mai 2025
Order Delivery Date Pro for WooCommerce < 12.3.1 - Unauthenticated Arbitrary Option Update
63RISCO
abrir
GitHub PoC1
aidana-gift/CVE-2025-0868
CVE-2025-0868CRITICAL25 mai 2025
Remote Code Execution in DocsGPT
68RISCO
abrir
GitHub PoC18
Apache Tomcat - Remote Code Execution via Session Deserialization (CVE-2025-24813)
CVE-2025-24813CRITICALsob ataque25 mai 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC1
PoC CVE-2025-22457
CVE-2025-22457CRITICALsob ataqueransomware25 mai 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7
100RISCO
abrir
GitHub PoC7
CVE-2024-42009 Proof of Concept
CVE-2024-42009CRITICALsob ataque24 mai 2025
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RISCO
abrir
GitHub PoC
0xWhoami35/CVE-2025-2294
CVE-2025-2294CRITICAL24 mai 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISCO
abrir
GitHub PoC1
davidxbors/CVE-2025-25014
CVE-2025-25014CRITICAL24 mai 2025
Kibana arbitrary code execution via prototype pollution
53RISCO
abrir
GitHub PoC5
🛡️ CVE-2025-31161 - CrushFTP User Creation Authentication Bypass Exploit
CVE-2025-31161CRITICALsob ataqueransomware23 mai 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISCO
abrir
anteriorpágina 146 / 444próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.