Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
76.313exploits catalogados
34.834CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.797GitHub PoC 13.885VulnCheck XDB 8.484Nuclei 4.237Metasploit 3.467✓ só verificadosrecentespopularesrisco
76.008 exploits
GitHub PoC★ 9
POC for CVE-2024-42327: Zabbix Privilege Escalation -> RCE
SQL injection in user.get API
70RISCO
abrir ↗GitHub PoC
This repository contains a Python script to exploit two vulnerabilities: CVE-2019-18818 and CVE-2019-19609.
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISCO
abrir ↗GitHub PoC
Explore CVE-2023-33580 (XSS) & CVE-2023-33584 (SQLI) discovered by me. Dive into vulnerabilities and exploits for insights.
Phpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" f
23RISCO
abrir ↗GitHub PoC★ 1
Browser exploitation framework for Chakra (Edge). Written as part of OSEE preparation. Demo bug: CVE-2019-0567
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RISCO
abrir ↗GitHub PoC
hopsypopsy8/CVE-2020-1938-Exploitation
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir ↗GitHub PoC★ 2
A Proof-of-Concept (PoC) exploit for CVE-2024-10924, a vulnerability in the Really Simple SSL WordPress plugin that allows bypassing two-factor authentication (2FA). Includes mitigation techniques to secure affected WordPress sites.
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir ↗VulnCheck XDB
initial-access
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir ↗VulnCheck XDB
initial-access
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir ↗GitHub PoC★ 8
PoC exploit for CVE-2025-0108 - PAN-OS Authentication Bypass
PAN-OS: Authentication Bypass in the Management Web Interface
100RISCO
abrir ↗GitHub PoC
CVE-2016-6914-UniFiVideo-LPE
Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local u
23RISCO
abrir ↗GitHub PoC★ 32
Palo Alto Networks PAN-OS 身份验证绕过漏洞批量检测脚本(CVE-2025-0108)
PAN-OS: Authentication Bypass in the Management Web Interface
100RISCO
abrir ↗VulnCheck XDB
initial-access
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2
100RISCO
abrir ↗VulnCheck XDB
initial-access
PAN-OS: Authentication Bypass in the Management Web Interface
100RISCO
abrir ↗VulnCheck XDB
client-side
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RISCO
abrir ↗GitHub PoC
CMS Made Simple < 2.2.10 - SQL Injection python3
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir ↗GitHub PoC★ 1
This Proof of Concept (PoC) demonstrates an exploit for CVE-2024-42009, leveraging a cross-site scripting (XSS) vulnerability to extract emails from a target webmail application. The attack injects a malicious payload that exfiltrates email content to an attacker-controlled listener.
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RISCO
abrir ↗GitHub PoC
Apache Struts CVE-2024-53677 Exploitation
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir ↗GitHub PoC
luke0x90/CVE-2021-21551
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RISCO
abrir ↗GitHub PoC★ 2
POC for Roundcube vulnerabilities CVE-2024-42008 and CVE-2024-42010
A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7
60RISCO
abrir ↗GitHub PoC★ 4
huseyinstif/CVE-2025-24016-Nuclei-Template
Remote code execution in Wazuh server
100RISCO
abrir ↗VulnCheck XDB
initial-access
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir ↗Metasploit300
mySCADA myPRO Manager Credential Harvester (CVE-2025-24865 and CVE-2025-22896)
mySCADA myPRO Manager Missing Authentication for Critical Function
43RISCO
abrir ↗Metasploit300
mySCADA myPRO Manager Credential Harvester (CVE-2025-24865 and CVE-2025-22896)
mySCADA myPRO Manager Cleartext Storage of Sensitive Information
43RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.