Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.565exploits catalogados
34.501CVEs com exploração pública
24.695testados em laboratório
75.526 exploits
GitHub PoC
anelya0333/Exploiting-CVE-2023-38831
CVE-2023-38831HIGHsob ataqueransomware20 nov 2025
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC
On February 13th, 2024, Microsoft announced a Microsoft Outlook RCE & credential leak vulnerability with the assigned CVE of CVE-2024-21413 (Moniker Link). Haifei Li of Check Point Research is credited with discovering the vulnerability. The vulnerability bypasses Outlook's security mechanisms when handing a specific type of hyperlink .
CVE-2024-21413CRITICALsob ataque20 nov 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC1
Fully automated Spring4Shell (CVE-2022-22965) + GitLab RCE framework
CVE-2022-22965CRITICALsob ataque20 nov 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC3
A comprehensive Python exploitation framework for testing and demonstrating CVE-2025-3248, a critical unauthenticated remote code execution vulnerability in Langflow versions ≤ 1.3.0.
CVE-2025-3248CRITICALsob ataqueransomware20 nov 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
GitHub PoC1
A comprehensive Python-based vulnerability scanner for detecting CVE-2021-41773 and CVE-2021-42013 path traversal and remote code execution vulnerabilities in Apache HTTP Server versions 2.4.49 and 2.4.50.
CVE-2021-42013CRITICALsob ataqueransomware19 nov 2025
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC
Loaxert/CVE-2018-15133-PoC
CVE-2018-15133HIGHsob ataque19 nov 2025
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISCO
abrir
GitHub PoC19
This tool is a modern evolution of older PoCs like those for CVE-2017-7921 and ICSA-17-124-01, updated for 2025 with live console output, threading for speed, and honeypot filtering (skips devices with >12 open ports). It's built for red teamers, bug bounty hunters, and security researchers to identify
CVE-2017-7921CRITICALsob ataque19 nov 2025
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISCO
abrir
GitHub PoC
C# and Impacket implementation of PrintNightmare CVE-2021-1675/CVE-2021-34527
CVE-2021-1675HIGHsob ataqueransomware19 nov 2025
Windows Print Spooler Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
This repository is a complete walkthrough of the Simple CTF challenge on TryHackMe, featuring Nmap scanning, directory enumeration with Gobuster, exploitation of CVE-2019-9053, SSH access, and privilege escalation via sudo permissions.
CVE-2019-905319 nov 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
GitHub PoC4
MonstaFTP Unauthenticated File Upload
CVE-2025-34299CRITICAL19 nov 2025
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RISCO
abrir
GitHub PoC
CVE-2021-22205& GitLab CE/EE RCE
CVE-2021-22205CRITICALsob ataqueransomware19 nov 2025
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISCO
abrir
GitHub PoC
Death112233/CVE-2025-64446-
CVE-2025-64446CRITICALsob ataque19 nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-58034MEDIUMsob ataque19 nov 2025
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vul
90RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2018-15133HIGHsob ataque19 nov 2025
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-34299CRITICAL19 nov 2025
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-1675HIGHsob ataqueransomware19 nov 2025
Windows Print Spooler Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)
CVE-2022-40684CRITICALsob ataqueransomware19 nov 2025
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir
VulnCheck XDB
local
CVE-2025-62215HIGHsob ataque18 nov 2025
Windows Kernel Elevation of Privilege Vulnerability
71RISCO
abrir
VulnCheck XDB
info-leak
CVE-2025-11833CRITICAL18 nov 2025
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Log Disclosure
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALsob ataque18 nov 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-64446CRITICALsob ataque18 nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISCO
abrir
GitHub PoC
CVE-2022-0543 - Redis RCE Vulnerability home lab for Red Teaming, Penetration Testing Training with just one DOCKER
CVE-2022-0543CRITICALsob ataque18 nov 2025
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RISCO
abrir
GitHub PoC14
FortiWeb Remote Code Execution (RCE) Exploit via CVE-2025-64446 + CVE-2025-58034 Chain
CVE-2025-64446CRITICALsob ataque18 nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISCO
abrir
GitHub PoC
0xr2r/CVE-2025-64095
CVE-2025-64095CRITICAL18 nov 2025
DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite
75RISCO
abrir
GitHub PoC3
Hands‑on analysis of CVE‑2025‑62215, a Windows Kernel race condition exploited in the wild. Demonstrates privilege escalation to SYSTEM, detection scripts, and patch validation strategies for enterprise defenders and red teamers.
CVE-2025-62215HIGHsob ataque18 nov 2025
Windows Kernel Elevation of Privilege Vulnerability
71RISCO
abrir
GitHub PoC19
This PoC demonstrates a race condition in the Windows kernel leading to a double-free vulnerability, allowing local privilege escalation to SYSTEM. The exploit uses multithreaded handle manipulation and heap spraying to trigger the flaw under controlled conditions.
CVE-2025-62215HIGHsob ataque18 nov 2025
Windows Kernel Elevation of Privilege Vulnerability
71RISCO
abrir
GitHub PoC
Technical deep dive into Apache Log4j2 JNDI injection vulnerability. Features static code analysis, patch comparison, attack vectors (LDAP/RMI/DNS), and enterprise mitigation guidance.
CVE-2021-44228CRITICALsob ataqueransomware18 nov 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
CVE-2015-3306 - ProFTPD - RCE Home Lab setup (Docker) easy to use for Red Teaming or Penetration Testing
CVE-2015-330617 nov 2025
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISCO
abrir
GitHub PoC
Hands-on exploitation lab for Roundcube Webmail CVE-2025-49113 (authenticated PHP object deserialization → RCE) to read /secret.txt.
CVE-2025-49113CRITICALsob ataque17 nov 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
GitHub PoC
CVE-2025-33073
CVE-2025-33073HIGHsob ataque17 nov 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RISCO
abrir
anteriorpágina 183 / 2.518próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.