Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.526exploits catalogados
34.478CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.534GitHub PoC 13.654VulnCheck XDB 8.213Nuclei 4.218Metasploit 3.464✓ só verificadosrecentespopularesrisco
75.526 exploits
VulnCheck XDB
initial-access
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISCO
abrir ↗GitHub PoC
OS command injection vulnerability in Samba that received the maximum possible CVSS v3.1 score of 10.0
Samba: command injection in wins server hook script
60RISCO
abrir ↗GitHub PoC★ 2
Tutorial of CVE-2022-37969 with focus on the methodology of Kernel exploitation, not CVE's internal causes
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir ↗Metasploit300
GeoServer WMS GetMap XXE Arbitrary File Read
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RISCO
abrir ↗GitHub PoC
Proof-of-Concept (PoC) for CVE-2025-62168 👾
Squid vulnerable to information disclosure via authentication credential leakage in error handling
75RISCO
abrir ↗VulnCheck XDB
local
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir ↗GitHub PoC
CVE-2025-61757
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported vers
100RISCO
abrir ↗GitHub PoC★ 31
aklnjakln/CVE-2025-6554
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RISCO
abrir ↗VulnCheck XDB
initial-access
Sneeit Framework <= 8.3 - Unauthenticated Remote Code Execution in sneeit_articles_pagination_callback
60RISCO
abrir ↗VulnCheck XDB
client-side
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RISCO
abrir ↗GitHub PoC★ 2
Reproducing CVE-2024-29943 for Windows, based on https://github.com/bjrjk/CVE-2024-29943
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds chec
53RISCO
abrir ↗GitHub PoC★ 1
A easy poc for CVE-2024-12084.
Rsync: heap buffer overflow in rsync due to improper checksum length handling
70RISCO
abrir ↗GitHub PoC
IS8123/CVE-2025-54381
BentoML is Vulnerable to an SSRF Attack Through File Upload Processing
53RISCO
abrir ↗VulnCheck XDB
local
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RISCO
abrir ↗VulnCheck XDB
initial-access
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISCO
abrir ↗GitHub PoC
CVE-2025-12762
Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)
53RISCO
abrir ↗VulnCheck XDB
infoleak
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the con
60RISCO
abrir ↗GitHub PoC
CVE-2012-2122 MySQL Authentication Bypass Home Lab
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x befor
60RISCO
abrir ↗GitHub PoC
Juniper JunOS J-Web PHP external variable modification (CVE-2023-36845) exploit.
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISCO
abrir ↗VulnCheck XDB
infoleak
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir ↗GitHub PoC★ 1
CVE-2025-10230 PoC - Samba WINS Hook Command Injection
Samba: command injection in wins server hook script
60RISCO
abrir ↗GitHub PoC
CVE-2025-11833 Checker
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Log Disclosure
75RISCO
abrir ↗GitHub PoC
rashedhasan090/CVE-2025-5777
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir ↗GitHub PoC★ 1
This repository contains a full blue-team malware analysis of a real malicious DOCX exploiting CVE-2017-0199. The lab includes sandbox execution, network forensics, IOC extraction, MITRE ATT&CK mapping, dropped files review, and detection rules. Evidence screenshots are included inside the evidence folder for professional documentation.
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir ↗GitHub PoC★ 2
Windows File Explorer Zero Click NTLMv2-SSP Hash Disclosure
NTLM Hash Disclosure Spoofing Vulnerability
75RISCO
abrir ↗GitHub PoC
Custom Docker Image
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISCO
abrir ↗GitHub PoC
POC
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir ↗GitHub PoC
ranasen-rat/CVE-2025-11001
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.