Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
71.886 exploits
GitHub PoC1
SOC investigation of CVE-2024-49138 exploitation alert involving PowerShell, EDRFreeze execution, and defense evasion behavior in a simulated environment.
CVE-2024-49138HIGHsob ataque09 mar 2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC
OpenSSH regreSSHion (CVE-2024-6387) Lab
CVE-2024-6387HIGH09 mar 2026
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir
GitHub PoC
swoon69/CVE-2025-59287-Exercise-Use
CVE-2025-59287CRITICALsob ataque09 mar 2026
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
OpenSSH User Enumeration (CVE-2018-15473) Lab
CVE-2018-15473MEDIUM09 mar 2026
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC3
cupntlm
CVE-2025-33073HIGHsob ataque09 mar 2026
Windows SMB Client Elevation of Privilege Vulnerability
93RISCO
abrir
GitHub PoC
gregk4sec/cve-2025-31651
CVE-2025-31651CRITICAL09 mar 2026
Apache Tomcat: Bypass of rules in Rewrite Valve
48RISCO
abrir
GitHub PoC
demo application showing off SQL Injection exploit in django 5.2.7
CVE-2025-64459CRITICAL09 mar 2026
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-33073HIGHsob ataque09 mar 2026
Windows SMB Client Elevation of Privilege Vulnerability
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-20198CRITICALsob ataque08 mar 2026
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISCO
abrir
GitHub PoC
gustavorobertux/cisco-cve-2023-20198-checker
CVE-2023-20198CRITICALsob ataque08 mar 2026
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISCO
abrir
GitHub PoC10
PoC for CVE-2025-60787 - Authenticated RCE in motionEye for all versions up to 0.43.1b4 (included)
CVE-2025-60787HIGH08 mar 2026
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name
61RISCO
abrir
GitHub PoC
Dockerized vulnerable lab demonstrating CVE-2024-2083 in ZenML, a path traversal vulnerability in the step logs API allowing arbitrary file read.
CVE-2024-2083CRITICAL08 mar 2026
Directory Traversal in zenml-io/zenml
60RISCO
abrir
GitHub PoC202
CVE-2026-24061 exploit PoC
CVE-2026-24061CRITICALsob ataque08 mar 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC2
lil0xplorer/CVE-2025-60787_PoC
CVE-2025-60787HIGH08 mar 2026
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name
61RISCO
abrir
GitHub PoC3
CVE-2023-38831 is a Zero-day WinRAR vulnerability that lets attackers disguise malicious files in archives, tricking users into executing harmful content.
CVE-2023-38831HIGHsob ataqueransomware08 mar 2026
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC
Penetration testing lab demonstrating CVE-2024-21413 moniker link exploitation for NTLM credential theft, including attack execution, hash cracking, and defensive countermeasures
CVE-2024-21413CRITICALsob ataque08 mar 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
0axz-tools/CVE-2025-6440
CVE-2025-6440CRITICAL08 mar 2026
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-6440CRITICAL08 mar 2026
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISCO
abrir
GitHub PoC
ZoneMinder Time-Based SQL Injection (CVE-2024-51482) Exploit POC
CVE-2024-51482CRITICAL08 mar 2026
Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64
75RISCO
abrir
GitHub PoC
A demo and explanation of CVE-2026-31431
CVE-2026-31431HIGHsob ataque08 mar 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC8
ZenoMinder Blind SQL Injection PoC
CVE-2024-51482CRITICAL08 mar 2026
Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64
75RISCO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHsob ataque08 mar 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC
An automated, high-precision zero-shot evaluation pipeline for OpenAI's CLIP model on CIFAR-10. Features 88.80% accuracy, Safetensors security mitigation (CVE-2025-32434), and AI Native (Trae) workflow.
CVE-2025-32434CRITICAL08 mar 2026
PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
48RISCO
abrir
GitHub PoC14
Authenticated time-based blind SQL injection PoC for ZoneMinder CVE-2024-51482 (v1.37.* <= 1.37.64)
CVE-2024-51482CRITICAL07 mar 2026
Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-20122MEDIUMsob ataque07 mar 2026
Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite Vulnerability
63RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2020-1350CRITICALsob ataque07 mar 2026
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISCO
abrir
GitHub PoC1
Professional PoC for CVE-2025-60787: Remote Code Execution in MotionEye (<= 0.43.1b4). This exploit demonstrates an OS Command Injection vulnerability through client-side validation bypass, allowing attackers to execute arbitrary commands via configuration files.
CVE-2025-60787HIGH07 mar 2026
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name
61RISCO
abrir
GitHub PoC
Exploit for CVE-2023-27372 with interactiev shell
CVE-2023-27372CRITICAL07 mar 2026
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-27372CRITICAL07 mar 2026
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALsob ataque07 mar 2026
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
anteriorpágina 107 / 2.397próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.