Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.589exploits catalogados
34.508CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.554GitHub PoC 13.689VulnCheck XDB 8.216Nuclei 4.223Metasploit 3.464✓ só verificadosrecentespopularesrisco
75.589 exploits
VulnCheck XDB
initial-access
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir ↗GitHub PoC
PoC for achieving RCE in Langflow versions <1.3.0
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir ↗GitHub PoC★ 1
Shinkirou789/Cve-2025-8088-WinRar-vulnerability
Path traversal vulnerability in WinRAR
93RISCO
abrir ↗GitHub PoC★ 1
Proof-Of-Concept to check privileges of af_packet.c for validating the privileges acquired by any hacker upon successful exploitation of CVE-2021-22600
Double Free in net/packet/af_packet.c leading to priviledge escalation
63RISCO
abrir ↗GitHub PoC
Python tool for CVE-2010-1240 research - generates malicious PDFs exploiting Adobe Reader Launch Actions
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RISCO
abrir ↗VulnCheck XDB
initial-access
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISCO
abrir ↗GitHub PoC
A Rust implementation of the CVE-2014-6287 exploit targeting Rejetto HTTP File Server (HFS) versions 2.3x before 2.3c.
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir ↗VulnCheck XDB
initial-access
Improper limitation of a pathname to a restricted directory (“path traversal”)
100RISCO
abrir ↗Exploit-DB
Mbed TLS 3.6.4 - Use-After-Free
Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance wit
41RISCO
abrir ↗VulnCheck XDB
initial-access
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir ↗Exploit-DB
HTMLDOC 1.9.13 - Stack Buffer Overflow
A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim co
23RISCO
abrir ↗Exploit-DB
ClipBucket 5.5.0 - Arbitrary File Upload
An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in
41RISCO
abrir ↗Exploit-DB
Concrete CMS 9.4.3 - Stored XSS
Concrete CMS 9 through 9.4.2 is vulnerable to Stored XSS from Home Folder on Members Dashboard page
28RISCO
abrir ↗Exploit-DB
dotCMS 25.07.02-1 - Authenticated Blind SQL Injection
dotCMS versions 24.03.22 and after, identified a Boolean-based blind SQLi vulnerability in the /api/v1/contenttype endpo
48RISCO
abrir ↗Exploit-DB
Tourism Management System 2.0 - Arbitrary Shell Upload
A Shell Upload vulnerability in Tourism Management System 2.0 allows an attacker to upload and execute arbitrary PHP she
41RISCO
abrir ↗Exploit-DB
ClipBucket 5.5.2 Build #90 - Server-Side Request Forgery (SSRF)
An issue Clip Bucket v.5.5.2 Build#90 allows a remote attacker to execute arbitrary codes via the file_downloader.php an
33RISCO
abrir ↗GitHub PoC
2 web apps vulnerable to CVE-2025-27210
An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CO
41RISCO
abrir ↗GitHub PoC
PoC for CVE-2025-20265 Cisco Secure FMC Software RADIUS Remote Code Execution Vulnerability
Cisco Secure Firewall Management Center Software Radius Remote Code Execution Vulnerability
53RISCO
abrir ↗GitHub PoC
CVE-2019-3396 confluence SSTI RCE
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISCO
abrir ↗Exploit-DB
HTTP/2 2.0 - Denial Of Service (DOS)
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISCO
abrir ↗Exploit-DB
Casdoor 2.55.0 - Cross-Site Request Forgery (CSRF)
Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-passwo
23RISCO
abrir ↗Exploit-DB
XWiki Platform 15.10.10 - Metasploit Module for Remote Code Execution (RCE)
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir ↗VulnCheck XDB
infoleak
GLPI allows unauthenticated SQL injection through the inventory endpoint
78RISCO
abrir ↗Exploit-DB
ELEX WooCommerce WordPress Plugin 1.4.3 - SQL Injection
ELEX WooCommerce Google Shopping (Google Product Feed) <= 1.4.3 - Authenticated (Admin+) SQL Inejction
33RISCO
abrir ↗GitHub PoC★ 2
RedArrow3.2 是一款用于渗透测试ThinkPHP 5.0.23 远程命令执行漏洞(CVE-2018-20062)的图形化工具。
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RISCO
abrir ↗GitHub PoC★ 2
Example PoC for CVE-2025-24813 (Tomcat RCE)
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗GitHub PoC
0xDTC/js2py-Sandbox-Escape-CVE-2024-28397-RCE
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISCO
abrir ↗GitHub PoC★ 2
Langflow Remote Code Execution
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.