Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.589exploits catalogados
34.508CVEs com exploração pública
24.695testados em laboratório
75.589 exploits
GitHub PoC
CVE-2024-53677 관련 컨설턴트용 툴 개발
CVE-2024-53677CRITICAL15 out 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir
GitHub PoC1
This repo shows an exploit to CVE-2021-24762. This is an Blind SQLi exploit that, on default config, greps the admin password.
CVE-2021-2476215 out 2025
Perfect Survey < 1.5.2 - Unauthenticated SQL Injection
60RISCO
abrir
GitHub PoC151
Exploit for CVE-2025-11001 or CVE-2025-11002
CVE-2025-11001HIGH15 out 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-2476215 out 2025
Perfect Survey < 1.5.2 - Unauthenticated SQL Injection
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHsob ataqueransomware15 out 2025
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL15 out 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir
VulnCheck XDB
local
CVE-2025-11001HIGH15 out 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-7441CRITICAL14 out 2025
StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload
75RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-4123HIGH14 out 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-6554HIGHsob ataque14 out 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-48384HIGHsob ataque14 out 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
VulnCheck XDB
local
CVE-2025-11001HIGH14 out 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RISCO
abrir
GitHub PoC
CVE-2025-24893 tool
CVE-2025-24893CRITICALsob ataque14 out 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC20
PoC for CVE-2025-25198: automated Host header poisoning test for Mailcow - HTTPS listener, automatic cookie/CSRF handling, captures first reset link.
CVE-2025-25198HIGH14 out 2025
mailcow: dockerized vulnerable to password reset poisoning
41RISCO
abrir
Metasploit500
Windows Server Update Service Deserialization Remote Code Execution
CVE-2025-59287CRITICALsob ataque14 out 2025
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC1
Poc for CVE-2024-36971
CVE-2024-36971HIGHsob ataque14 out 2025
net: fix __dst_negative_advice() race
71RISCO
abrir
GitHub PoC
CVE-2024-46256 tool
CVE-2024-46256CRITICAL14 out 2025
A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add
48RISCO
abrir
GitHub PoC3
StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload
CVE-2025-7441CRITICAL14 out 2025
StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALsob ataque14 out 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC
This script checks if an HP iLO server is vulnerable and can add an admin user
CVE-2017-1254213 out 2025
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-1254213 out 2025
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RISCO
abrir
GitHub PoC
Tnot123/cve-2024-43425
CVE-2024-43425HIGH13 out 2025
Moodle: remote code execution via calculated question types
78RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-61884HIGHsob ataqueransomware13 out 2025
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions
100RISCO
abrir
GitHub PoC
laachy/CVE-2024-39930-ptrace-detection-mitigation
CVE-2024-39930CRITICAL13 out 2025
The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code
48RISCO
abrir
GitHub PoC1
Reverse shell for CVE-2024-28397.
CVE-2024-28397MEDIUM12 out 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISCO
abrir
GitHub PoC
Exploit Title: Node.JS - 'node-serialize' Remote Code Execution (2), Version: 0.0.4, CVE: CVE-2017-5941
CVE-2017-594112 out 2025
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RISCO
abrir
GitHub PoC1
Reverse shell for CVE-2024-28397.
CVE-2024-28397MEDIUM12 out 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISCO
abrir
VulnCheck XDB
local
CVE-2023-29360HIGHsob ataque12 out 2025
Microsoft Streaming Service Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC
Scottman625/CVE-2023-29360
CVE-2023-29360HIGHsob ataque12 out 2025
Microsoft Streaming Service Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC1
PoC of "DEF CON 32 - SQL Injection Isn't Dead Smuggling Queries at the Protocol Level - Paul Gerste"
CVE-2024-27304CRITICAL12 out 2025
pgx SQL Injection via Protocol Message Size Overflow
48RISCO
abrir
anteriorpágina 194 / 2.520próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.