Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
76.008exploits catalogados
34.638CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.662GitHub PoC 13.743VulnCheck XDB 8.460Nuclei 4.233Metasploit 3.467✓ só verificadosrecentespopularesrisco
75.902 exploits
GitHub PoC
This CVE - PoC about information on the CVEs I found.
Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.
33RISCO
abrir ↗GitHub PoC★ 1
olimpiofreitas/CVE-2025-29927-scanner
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 3
This repository includes everything needed to run a PoC exploit for CVE-2025-32375 in a Docker environment. It runs the latest vulnerable version of BentoML (1.4.7).
Insecure Deserialization leads to RCE in BentoML's runner server
75RISCO
abrir ↗GitHub PoC
Vite Development Server's @fs endpoint (CVE-2025-31125) to access sensitive files like /etc/passwd and /etc/hosts via crafted URLs.
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
90RISCO
abrir ↗GitHub PoC
A critical flaw has been discovered in Erlang/OTP's SSH server allows unauthenticated attackers to gain remote code execution. One malformed SSH handshake bypasses authentication and exploits improper handling of SSH protocol messages.
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir ↗VulnCheck XDB
infoleak
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
90RISCO
abrir ↗GitHub PoC
CVE-2024-10914 Shell Exploit
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir ↗GitHub PoC★ 1
ByteMe1001/CVE-2020-13151-POC-Aerospike-Server-Host-Command-Execution-RCE-
Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs)
60RISCO
abrir ↗GitHub PoC★ 1
CVE-2025-32433 – Erlang/OTP SSH vulnerability allowing pre-auth RCE
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir ↗GitHub PoC
sattarbug/Analysis-of-TomcatKiller---CVE-2025-31650-Exploit-Tool
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
53RISCO
abrir ↗GitHub PoC★ 1
CVE-2016-5195 linux kernel exploit
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir ↗GitHub PoC
This python scripts searches a client list to see if their FortiGate device is vulnerable to this CVE.
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RISCO
abrir ↗VulnCheck XDB
denial-of-service
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RISCO
abrir ↗VulnCheck XDB
local
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir ↗GitHub PoC
Simple PoC of wpstorecart before 2.5.30 plugin exploit (CVE-2012-3576) written in bash.
Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows re
28RISCO
abrir ↗GitHub PoC
katseyres2/CVE-2022-44268-pilgrimage
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISCO
abrir ↗GitHub PoC
toothbrushsoapflannelbiscuits/cve-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir ↗Exploit-DB
Microsoft - NTLM Hash Disclosure Spoofing (library-ms)
NTLM Hash Disclosure Spoofing Vulnerability
75RISCO
abrir ↗GitHub PoC★ 9
CVE-2025-31324 & CVE-2025-42999 vulnerability and compromise assessment tool
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISCO
abrir ↗GitHub PoC★ 1
CVE-2024-27956 - WP Automatic SQL Injection Exploit Tool
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISCO
abrir ↗VulnCheck XDB
initial-access
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISCO
abrir ↗VulnCheck XDB
initial-access
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISCO
abrir ↗GitHub PoC★ 2
CVE-2025-31650 PoC
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
53RISCO
abrir ↗GitHub PoC★ 20
A tool designed to detect the vulnerability **CVE-2025-31650** in Apache Tomcat (versions 10.1.10 to 10.1.39)
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
53RISCO
abrir ↗VulnCheck XDB
initial-access
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.