Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
76.107exploits catalogados
34.679CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.692GitHub PoC 13.812VulnCheck XDB 8.460Nuclei 4.233Metasploit 3.467✓ só verificadosrecentespopularesrisco
75.951 exploits
GitHub PoC★ 2
sandsoncosta/CVE-2025-26633
Microsoft Management Console Security Feature Bypass Vulnerability
83RISCO
abrir ↗VulnCheck XDB
initial-access
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISCO
abrir ↗Exploit-DB
jQuery 3.3.1 - Prototype Pollution & XSS Exploit
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and re
23RISCO
abrir ↗VulnCheck XDB
denial-of-service
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7
100RISCO
abrir ↗VulnCheck XDB
initial-access
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗Exploit-DB
Nagios Xi 5.6.6 - Authenticated Remote Code Execution (RCE)
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios
100RISCO
abrir ↗VulnCheck XDB
denial-of-service
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7
100RISCO
abrir ↗Exploit-DB
GeoVision GV-ASManager 6.1.0.0 - Information Disclosure
Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which
46RISCO
abrir ↗VulnCheck XDB
client-side
The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18
71RISCO
abrir ↗GitHub PoC
DFG register allocation bug in JavaScriptCore
The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18
71RISCO
abrir ↗VulnCheck XDB
infoleak
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir ↗GitHub PoC
vances25/CVE-2024-44871
An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute a
46RISCO
abrir ↗GitHub PoC★ 3
mouadk/parquet-rce-poc-CVE-2025-30065
Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
60RISCO
abrir ↗GitHub PoC
Hello researchers, I have a checker for the recent vulnerability CVE-2025-24813-checker.
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗GitHub PoC
WHS 3기 장대혁 취약한(CVE) Docker 환경 구성 과제입니다.
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir ↗Exploit-DB
Apache Tomcat 11.0.3 - Remote Code Execution
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗GitHub PoC
Heimd411/CVE-2025-24813-noPoC
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗Exploit-DB
XWiki Platform 15.10.10 - Remote Code Execution
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir ↗Exploit-DB
YesWiki 4.5.1 - Unauthenticated Path Traversal
Path Traversal allowing arbitrary read of files in Yeswiki
56RISCO
abrir ↗GitHub PoC
Demonstration of CVE-2023-23397 Outlook Privellege Escalation vulnerability
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir ↗GitHub PoC★ 32
Simulated PoC for CVE-2025-2783 — a sandbox escape vulnerability in Chrome's Mojo IPC. Includes phishing delivery, memory fuzzing, IPC simulation, and logging. Safe for red team demos, detection engineering, and educational use.
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
71RISCO
abrir ↗GitHub PoC
A POC lab environment for CVE-2024-56145 CraftCMS RCE.
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
100RISCO
abrir ↗GitHub PoC★ 8
Next.js Middleware Bypass Scanne
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 1
cybermads/CVE-2011-2523
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.