Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8.176Nuclei 4.202Metasploit 3.462✓ só verificadosrecentespopularesrisco
13.282 exploits
GitHub PoC
CVE-2025-12762
Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)
53RISCO
abrir ↗GitHub PoC★ 1
A easy poc for CVE-2024-12084.
Rsync: heap buffer overflow in rsync due to improper checksum length handling
70RISCO
abrir ↗GitHub PoC
Juniper JunOS J-Web PHP external variable modification (CVE-2023-36845) exploit.
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISCO
abrir ↗GitHub PoC
CVE-2012-2122 MySQL Authentication Bypass Home Lab
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x befor
60RISCO
abrir ↗GitHub PoC
IS8123/CVE-2025-54381
BentoML is Vulnerable to an SSRF Attack Through File Upload Processing
53RISCO
abrir ↗GitHub PoC★ 1
This repository contains a full blue-team malware analysis of a real malicious DOCX exploiting CVE-2017-0199. The lab includes sandbox execution, network forensics, IOC extraction, MITRE ATT&CK mapping, dropped files review, and detection rules. Evidence screenshots are included inside the evidence folder for professional documentation.
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISCO
abrir ↗GitHub PoC★ 2
Windows File Explorer Zero Click NTLMv2-SSP Hash Disclosure
NTLM Hash Disclosure Spoofing Vulnerability
75RISCO
abrir ↗GitHub PoC
rashedhasan090/CVE-2025-5777
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir ↗GitHub PoC
CVE-2025-11833 Checker
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Log Disclosure
75RISCO
abrir ↗GitHub PoC★ 1
CVE-2025-10230 PoC - Samba WINS Hook Command Injection
Samba: command injection in wins server hook script
60RISCO
abrir ↗GitHub PoC★ 4
CVE-2025-26633 (CVSS 7.8) – Zero-day MMC .msc EvilTwin LPE actively exploited by Water Gamayun APT. PoC creates local admin via malicious MSC file on unpatched Windows 10/11/Server. Patched March 2025. Authorized testing only.
Microsoft Management Console Security Feature Bypass Vulnerability
83RISCO
abrir ↗GitHub PoC
ranasen-rat/CVE-2025-11001
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RISCO
abrir ↗GitHub PoC★ 7
CVE-2025-11001 (CVSS 7.0) – 7-Zip < 25.00 Directory Traversal → RCE via crafted ZIP with symlink. Allows arbitrary file write when extracted as Administrator. Fixed in 7-Zip 25.00 (July 2025).
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RISCO
abrir ↗GitHub PoC
Custom Docker Image
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISCO
abrir ↗GitHub PoC
POC
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir ↗GitHub PoC★ 1
Security research tool for detecting and testing CVE-2025-64446 (FortiWeb Path Traversal RCE vulnerability)
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISCO
abrir ↗GitHub PoC★ 1
Reproducible incident micro-postmortem for on-prem Microsoft SharePoint “ToolShell” (CVE-2025-53770): ATT&CK snapshot, “logs that matter” table, three hunts (KQL/SPL/Sigma), first-4-hours comms, sample data, and figures. Built for fast triage; no org data; SharePoint Online out of scope.
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC★ 4
Oracle Identity Manager 远程代码执行漏洞CVE-2025-61757
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported vers
100RISCO
abrir ↗GitHub PoC
Hands-on security lab demonstrating CVE-2023-22515 — Atlassian Confluence Authentication Bypass using a simulated vulnerable environment.
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISCO
abrir ↗GitHub PoC★ 2
A self-contained testbed for Django CVE-2025-64459. Demonstrates QuerySet.filter() parameter injection via dictionary expansion using Docker.
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RISCO
abrir ↗GitHub PoC★ 1
SAP RCE auto-chain (CVE-2024-22127 + DIAG)
Code Injection vulnerability in SAP NetWeaver AS Java (Administrator Log Viewer plug-in)
48RISCO
abrir ↗GitHub PoC★ 1
Adel-kaka-dz/cve-2025-59287
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC★ 1
Proof‑of‑concept description for CVE‑2025‑47916, a Remote Code Execution vulnerability affecting Invision Community 5.0.0–5.0.6 via unsafe template processing in the "customCss()" method.
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The
85RISCO
abrir ↗GitHub PoC★ 1
Proof‑of‑concept for CVE‑2024‑58258, a SugarCRM (<13.0.4 / <14.0.1) flaw where user input is parsed as LESS in /css/preview, allowing unauthenticated SSRF or local file access.
SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can
46RISCO
abrir ↗GitHub PoC
Security research tool for detecting and testing CVE-2025-12735 (expr-eval RCE vulnerability)
CVE-2025-12735
48RISCO
abrir ↗GitHub PoC★ 1
Fully automated Confluence RCE exploit (CVE-2023-22527 + OGNL injection) 100% from scratch • Python • 2025
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RISCO
abrir ↗GitHub PoC
Sorumluluk Reddi Kendi sorumluluğunuzda kullanın, size ait olmayan veya tarama izninizin olmadığı altyapılarda gerçekleştireceğiniz yasa dışı faaliyetlerden sorumlu olmayacağım.
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integratio
100RISCO
abrir ↗GitHub PoC
Security research tool for detecting and testing CVE-2025-12735 (expr-eval RCE vulnerability)
CVE-2025-12735
48RISCO
abrir ↗GitHub PoC
lastvocher/7zip-CVE-2025-11001
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.