Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.902exploits catalogados
34.597CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.624GitHub PoC 13.727VulnCheck XDB 8.410Nuclei 4.231Metasploit 3.467✓ só verificadosrecentespopularesrisco
75.902 exploits
Exploit-DB
Keras 2.15 - Remote Code Execution (RCE)
Arbitrary Code Execution via Crafted Keras Config for Model Loading
41RISCO
abrir ↗Exploit-DB
PivotX 3.0.0 RC3 - Remote Code Execution (RCE)
Cross Site Scripting vulnerability in PivotX CMS v.3.0.0 RC 3 allows a remote attacker to execute arbitrary code via the
48RISCO
abrir ↗VulnCheck XDB
infoleak
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir ↗GitHub PoC★ 5
An in-depth analysis of CVE 2023 38408, a critical OpenSSH vulnerability, including technical background, exploitation in controlled environments, and mitigation strategies.
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISCO
abrir ↗Metasploit600
Template Injection Vulnerability in Sawtooth Software's Lighthouse Studio (CVE-2025-34300)
Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE
75RISCO
abrir ↗GitHub PoC★ 2
(PoC) CVE-2025-27210, a precise Path Traversal vulnerability affecting Node.js applications running on Microsoft Windows. This vulnerability leverages the specific way Windows handles reserved device file names
An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CO
41RISCO
abrir ↗GitHub PoC
CVE-2025-53833
LaRecipe is vulnerable to Server-Side Template Injection attacks
63RISCO
abrir ↗Exploit-DB
White Star Software Protop 4.4.2-2024-11-27 - Local File Inclusion (LFI)
A directory traversal vulnerability was discovered in White Star Software Protop version 4.4.2-2024-11-27, specifically
56RISCO
abrir ↗GitHub PoC
Kalidas-7/CVE-2019-9053
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir ↗GitHub PoC
nguyentranbaotran/cve-2025-48384-poc
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir ↗Exploit-DB
TOTOLINK N300RB 8.54 - Command Execution
A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenti
41RISCO
abrir ↗GitHub PoC
Floodnut/CVE-2025-32463
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗GitHub PoC★ 2
joelczk/CVE-2025-52688
Command Injection Vulnerability in the OmniAccess Stellar Web Management Interface
53RISCO
abrir ↗GitHub PoC
malaya-m/cve-2013-3900-remediation-report
WinVerifyTrust Signature Validation Vulnerability
75RISCO
abrir ↗GitHub PoC
rpc.py 0.6.0 - Remote Code Execution (RCE)
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header i
35RISCO
abrir ↗Exploit-DB
NodeJS 24.x - Path Traversal
An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CO
41RISCO
abrir ↗GitHub PoC★ 1
krypton-0x00/CVE-2025-32463-Chwoot-POC
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗Exploit-DB
SugarCRM 14.0.0 - SSRF/Code Injection
SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can
46RISCO
abrir ↗Exploit-DB
Microsoft Graphics Component Windows 11 Pro (Build 26100+) - Local Elevation of Privileges
Windows Graphics Component Elevation of Privilege Vulnerability
41RISCO
abrir ↗GitHub PoC
Detection for CVE-2025-47812
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir ↗Exploit-DB
Microsoft Brokering File System Windows 11 Version 22H2 - Elevation of Privilege
Microsoft Brokering File System Elevation of Privilege Vulnerability
41RISCO
abrir ↗Exploit-DB
MikroTik RouterOS 7.19.1 - Reflected XSS
Cross-site scripting via dst parameter in RouterOS WiFi hotspot
33RISCO
abrir ↗Exploit-DB
WP Publications WordPress Plugin 1.2 - Stored XSS
WP Publications <= 1.2 - Admin+ Stored XSS
33RISCO
abrir ↗VulnCheck XDB
local
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗VulnCheck XDB
local
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗Exploit-DB
Langflow 1.2.x - Remote Code Execution (RCE)
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir ↗GitHub PoC★ 3
An advanced, powerful, and easy-to-use tool designed to detect and exploit CVE-2025-5777 (CitrixBleed 2). This script not only identifies the vulnerability but also helps in demonstrating its impact by parsing human-readable information from the memory leak.
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir ↗GitHub PoC
CVE-2025-5777 (CitrixBleed 2) - [Citrix NetScaler ADC] [Citrix Gateway]
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.