Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.760exploits catalogados
32.083CVEs com exploração pública
1.932testados em laboratório
13.235 exploits
GitHub PoC
Diego57709/CVE-2025-5548
CVE-2025-5548MEDIUM16 mar 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISCO
abrir
GitHub PoC
luisyapura/Analisis-y-Explotacion-de-CVE-2025-5548
CVE-2025-5548MEDIUM16 mar 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISCO
abrir
GitHub PoC
Authenticated RCE in pgAdmin 4 (8.10–9.1) via eval() injection in the Query Tool. This is an updated PoC with compatibility fixes for pgAdmin 9.x auth changes
CVE-2025-2945CRITICAL16 mar 2026
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
75RISCO
abrir
GitHub PoC
Binary exploitation laboratory: Environment setup and step-by-step walkthrough for exploiting CVE-2025-5548 using Ghidra, Immunity Debugger, and Python.
CVE-2025-5548MEDIUM16 mar 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISCO
abrir
GitHub PoC
CVE-2022-42889 취약점 분석보고서
CVE-2022-4288916 mar 2026
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC
Proof-of-Concept exploit for Apache Struts S2-052 (CVE-2017-9805) XML Deserialization Remote Code Execution. Created while solving the INE eWPTX Practice Range lab. Includes custom payloads, reverse shell exploit script, and step-by-step exploitation examples.
CVE-2017-9805HIGHsob ataque16 mar 2026
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISCO
abrir
GitHub PoC
Vulnerable Docker lab and exploit for Apache HTTP Server 2.4.49 path traversal vulnerability (CVE‑2021‑41773)
CVE-2021-41773HIGHsob ataqueransomware16 mar 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
12-test-12/CVE-2025-3248
CVE-2025-3248CRITICALsob ataqueransomware16 mar 2026
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
GitHub PoC
CVE-2020-5902
CVE-2020-5902CRITICALsob ataqueransomware16 mar 2026
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
GitHub PoC
exploit para a CVE-2021-41773:Path Traversal cgi-bin
CVE-2021-41773HIGHsob ataqueransomware15 mar 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
sumaiyafathima-code/CVE-2023-27524
CVE-2023-27524HIGHsob ataque15 mar 2026
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISCO
abrir
GitHub PoC
POC for log4shll Vulnerablity (CVE-2021-44228)
CVE-2021-44228CRITICALsob ataqueransomware15 mar 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Victor875/CVE-2025-5548
CVE-2025-5548MEDIUM15 mar 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISCO
abrir
GitHub PoC
Laboratorio de análisis y explotación de la vulnerabilidad CVE-2025-5548 en FreeFloat FTP Server 1.0
CVE-2025-5548MEDIUM15 mar 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISCO
abrir
GitHub PoC
Apache ActiveMQ OpenWire 역직렬화 RCE 취약점 기술 분석
CVE-2023-46604CRITICALsob ataqueransomware15 mar 2026
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISCO
abrir
GitHub PoC2
Security research and technical analysis of CVE-2025-5548, a buffer overflow vulnerability affecting FreeFloat FTP Server 1.0. This repository documents vulnerability behavior, attack surface, controlled proof of concept testing, and defensive insights within a structured research environment for cybersecurity learning and analysis.
CVE-2025-5548MEDIUM15 mar 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISCO
abrir
GitHub PoC
Heap Buffer Overflow in CVE-2025-5548
CVE-2025-5548MEDIUM14 mar 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISCO
abrir
GitHub PoC
Análisis técnico, preparación de entorno de laboratorio y desarrollo de exploit (RCE) para la vulnerabilidad CVE-2025-5548 en FreeFloat FTP Server.
CVE-2025-5548MEDIUM14 mar 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISCO
abrir
GitHub PoC
Explotación de la vulnerabilidad CVE-2025-5548, paso a paso
CVE-2025-5548MEDIUM14 mar 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISCO
abrir
GitHub PoC
LorenzoPorrasDuque/CVE-2025-5548-POC
CVE-2025-5548MEDIUM14 mar 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISCO
abrir
GitHub PoC
CVE-2018-6606
CVE-2018-660614 mar 2026
An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows
23RISCO
abrir
GitHub PoC
anasrami12/CVE-2025-5548
CVE-2025-5548MEDIUM14 mar 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISCO
abrir
GitHub PoC
Script and node.proto for exploit CVE-2025-68926
CVE-2025-68926CRITICAL14 mar 2026
RustFS has a gRPC Hardcoded Token Authentication Bypass
53RISCO
abrir
GitHub PoC
MotionEye v0.43.1b4 OS Command Injection
CVE-2025-60787HIGH14 mar 2026
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name
61RISCO
abrir
GitHub PoC
charlyrr/CVE-2025-5548
CVE-2025-5548MEDIUM13 mar 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISCO
abrir
GitHub PoC
Research of CVE-2024-3094 vulnerability.
CVE-2024-3094CRITICAL13 mar 2026
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC1
Proof‑of‑concept Python script demonstrating CVE‑2023‑43208 in Mirth Connect, allowing version checks and command execution on vulnerable instances.
CVE-2023-43208CRITICALsob ataqueransomware13 mar 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISCO
abrir
GitHub PoC1
CVE-2025-49844
CVE-2025-49844CRITICAL13 mar 2026
Redis Lua Use-After-Free may lead to remote code execution
85RISCO
abrir
GitHub PoC10
Adaptation of Cassowary CVE-2024-23222 for Linux x86_64
CVE-2024-23222HIGHsob ataque13 mar 2026
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.
76RISCO
abrir
GitHub PoC
0xTerror/CVE-2025-6934
CVE-2025-6934CRITICAL13 mar 2026
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RISCO
abrir
anteriorpágina 67 / 442próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.