Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.445exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.497GitHub PoC 13.627VulnCheck XDB 8.198Nuclei 4.217Metasploit 3.463✓ só verificadosrecentespopularesrisco
13.627 exploits
GitHub PoC★ 1
Exploit for CVE-2023-4220
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir ↗GitHub PoC
This repository contains informaion about the Fortigate firewall vulnerability (CVE-2022-40684) and affected data that were publicly disclosed by the Belsen Group. This information is being shared for security research and defensive purposes to help organizations identify if they were impacted.
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir ↗GitHub PoC★ 1
CVE-2024-3673 Exploit: Local File Inclusion in Web Directory Free WordPress Plugin ( before 1.7.3 )
Web Directory Free < 1.7.3 - Unauthenticated LFI
63RISCO
abrir ↗GitHub PoC★ 1
Proof of Concept for CVE-2024-45337 against Gitea and Forgejo
Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
48RISCO
abrir ↗GitHub PoC
CVE-2017-7921 exploit. Allows admin password retrieval and automatic snapshot download.
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISCO
abrir ↗GitHub PoC★ 1
Course Booking System <= 6.0.5 - Unauthenticated SQL Injection
WordPress Course Booking System plugin <= 6.0.6 - SQL Injection vulnerability
63RISCO
abrir ↗GitHub PoC★ 2
ExploitDB CVE-2024-50379 a vulnerability that enables attackers to upload a JSP shell to a vulnerable server and execute commands remotely. The exploit is especially effective when the /uploads directory is either unprotected or missing on the target server.
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RISCO
abrir ↗GitHub PoC
CVE-2024-38077-POC
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC★ 1
XalfiE/Fortigate-Belsen-Leak-Dump-CVE-2022-40684-
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir ↗GitHub PoC★ 155
This repository contains POC scenarios as part of CVE-2025-0411 MotW bypass.
7-Zip Mark-of-the-Web Bypass Vulnerability
83RISCO
abrir ↗GitHub PoC
In this project, I exploited the CVE-2024-27198-RCE vulnerability to perform a remote code execution (RCE) attack on a vulnerable TeamCity server.
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir ↗GitHub PoC★ 2
Exploit for CVE-2025-0282: A remote unauthenticated stack based buffer overflow affecting Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA gateways
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RISCO
abrir ↗GitHub PoC★ 3
sysirq/fortios-auth-bypass-exploit-CVE-2024-55591
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISCO
abrir ↗GitHub PoC
Exploit for CVE-2024-53704 - SonicWall SonicOS SSLVPN authentication bypass
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe
100RISCO
abrir ↗GitHub PoC★ 26
sysirq/fortios-auth-bypass-poc-CVE-2024-55591
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISCO
abrir ↗GitHub PoC
Grow by Tradedoubler < 2.0.22 - Unauthenticated LFI
Grow by Tradedoubler <= 2.0.21 - Unauthenticated LFI
63RISCO
abrir ↗GitHub PoC
bananoname/CVE-2024-49138-POC
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir ↗GitHub PoC
ekcrsm/CVE-2024-23733
The /WmAdmin/,/invoke/vm.server/login login page in the Integration Server in Software AG webMethods 10.15.0 before Core
41RISCO
abrir ↗GitHub PoC★ 12
Automated Reverse Shell Exploit via WebSocket | Havoc-C2-SSRF with RCE
An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send
48RISCO
abrir ↗GitHub PoC★ 8
This is a modified version of the CVE-2024-41570 SSRF PoC from @chebuya chained with the auth RCE exploit from @hyperreality. This exploit executes code remotely to a target due to multiple vulnerabilities in Havoc C2 Framework. (https://github.com/HavocFramework/Havoc)
An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send
48RISCO
abrir ↗GitHub PoC★ 4
themirze/cve-2024-12084
Rsync: heap buffer overflow in rsync due to improper checksum length handling
70RISCO
abrir ↗GitHub PoC★ 1
CVE-2022-0847
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir ↗GitHub PoC★ 4
This is an altered PoC for d0rb/CVE-2024-6387. This takes glibc addresses and trys to exploit the CVE through them.
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir ↗GitHub PoC★ 2
POC for CVE-2023-40028: Ghost CMS Arbitrary File Read
Arbitrary file read via symlinks in Ghost
45RISCO
abrir ↗GitHub PoC
调试环境
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗GitHub PoC★ 198
Proof of concept & details for CVE-2025-21298
Windows OLE Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC★ 15
CVE-2024-43451 is a Windows NTLM vulnerability that allows an attacker to force authentication and capture NTLM hashes by using malicious shortcuts.
NTLM Hash Disclosure Spoofing Vulnerability
85RISCO
abrir ↗GitHub PoC★ 3
This is a Chained RCE in the Havoc C2 framework using github.com/chebuya and github.com/IncludeSecurity pocs
An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send
48RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.