Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

72.018exploits catalogados
32.219CVEs com exploração pública
1.932testados em laboratório
13.324 exploits
GitHub PoC
The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes it possible for attackers with contributor level access and above to upload malicious files that can be used to obtain remote code execution,
CVE-2021-42362HIGH14 abr 2025
WordPress Popular Posts <= 5.3.2 Authenticated Arbitrary File Upload
78RISCO
abrir
GitHub PoC2
HTTP/2 Rapid Reset Exploit PoC
CVE-2023-44487HIGHsob ataque14 abr 2025
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISCO
abrir
GitHub PoC
PoC for CVE-2023-27350
CVE-2023-27350CRITICALsob ataqueransomware14 abr 2025
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir
GitHub PoC
Kiểm thử xâm nhập
CVE-2021-44228CRITICALsob ataqueransomware14 abr 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
POC CVE-2025-29927
CVE-2025-29927CRITICAL13 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
The goal of this project was to conduct a security audit of a blog recently launched by Ackme Support Incorporated, identifying any critical vulnerabilities before the site goes public. The task involved finding a way to remotely execute code and gain access to the target system.
CVE-2018-1676313 abr 2025
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir
GitHub PoC
ikerSandoval003/CVE-2021-4034
CVE-2021-4034HIGHsob ataque13 abr 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
Este repositorio muestra cómo explotar la vulnerabilidad CVE-2021-4034.
CVE-2021-4034HIGHsob ataque13 abr 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
spyata123/CVE-2023-3128
CVE-2023-3128CRITICAL13 abr 2025
Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique a
48RISCO
abrir
GitHub PoC
nagorealbisu/CVE-2021-4034
CVE-2021-4034HIGHsob ataque13 abr 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
Exploit de la vulneravilidad CVE-2021-4034
CVE-2021-4034HIGHsob ataque13 abr 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC3
A Python proof-of-concept exploit for CVE-2025-24813 - Unauthenticated RCE in Apache Tomcat (v9.0.0-9.0.98/10.1.0-10.1.34/11.0.0-11.0.2) via malicious Java object deserialization. Includes safe detection mode and custom payload support.
CVE-2025-24813CRITICALsob ataque12 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC
This is the Heratbleed bug (CVE-2014-0160) documentation I did for Advenced Cyber Attacks course.
CVE-2014-0160HIGHsob ataque12 abr 2025
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC
ReFlex Gallery (WordPress plugin) =< 3.1.3 CVE-2015-4133 PoC
CVE-2015-413312 abr 2025
Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 f
50RISCO
abrir
GitHub PoC4
CVE-2025-24813-Scanner is a Python-based vulnerability scanner that detects Apache Tomcat servers vulnerable to CVE-2025-24813, an arbitrary file upload vulnerability leading to remote code execution (RCE) via insecure PUT method handling and jsessionid exploitation.
CVE-2025-24813CRITICALsob ataque12 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC
PoC of CVE-2023-1177 vulnerability in MLflow (Reproduce)
CVE-2023-1177CRITICAL12 abr 2025
Path Traversal: '\..\filename' in mlflow/mlflow
75RISCO
abrir
GitHub PoC
nicoleman0/CVE-2016-6210-OpenSSHd-7.2p2
CVE-2016-6210MEDIUM12 abr 2025
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RISCO
abrir
GitHub PoC
PDF host for CVE-2024-4367
CVE-2024-4367MEDIUM12 abr 2025
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir
GitHub PoC
vsFTPd 2.3.4 CVE-2011-2523 PoC
CVE-2011-252312 abr 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
GitHub PoC35
mistymntncop/CVE-2024-7971
CVE-2024-7971HIGHsob ataque12 abr 2025
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a
76RISCO
abrir
GitHub PoC1
PHP CGI CVE-2024-4577 PoC
CVE-2024-4577CRITICALsob ataqueransomware12 abr 2025
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC43
CVE-2024-36401 图形化利用工具,支持各个JDK版本利用以及回显、内存马实现
CVE-2024-36401CRITICALsob ataque11 abr 2025
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir
GitHub PoC1
A Python proof-of-concept exploit for CVE-2019-15107 - an unauthenticated remote code execution vulnerability in Webmin versions 1.890 through 1.920.
CVE-2019-15107CRITICALsob ataqueransomware11 abr 2025
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
GitHub PoC
ngyinkit/cve-2019-18634
CVE-2019-1863411 abr 2025
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISCO
abrir
GitHub PoC
Next.js CVE-2025-29927 Hunter
CVE-2025-29927CRITICAL11 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
PoC for exploitation of vulnerability CVE-2019-10149
CVE-2019-10149CRITICALsob ataque11 abr 2025
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISCO
abrir
GitHub PoC3
Exploit PoC for CVE-2023-20198
CVE-2023-20198CRITICALsob ataque11 abr 2025
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISCO
abrir
GitHub PoC8
CVE-2025-24813 poc
CVE-2025-24813CRITICALsob ataque10 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC18
CVE-2025-22457: Python Exploit POC Scanner to Detect Ivanti Connect Secure RCE
CVE-2025-22457CRITICALsob ataqueransomware10 abr 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7
100RISCO
abrir
GitHub PoC9
A vulnerability scanner for CVE-2025-3248 in Langflow applications. 用于扫描 Langflow 应用中 CVE-2025-3248 漏洞的工具。
CVE-2025-3248CRITICALsob ataqueransomware10 abr 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
anteriorpágina 156 / 445próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.