Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 20.003GitHub PoC 13.307VulnCheck XDB 8.182Nuclei 4.217Metasploit 3.462✓ só verificadosrecentespopularesrisco
13.282 exploits
GitHub PoC
CVE-2025-54782
@nestjs/devtools-integration's CSRF to Sandbox Escape Allows for RCE against JS Developers
75RISCO
abrir ↗GitHub PoC★ 8
CVE-2025-53690 POC
Sitecore Products ViewState Deserialization Vulnerability
90RISCO
abrir ↗GitHub PoC
Billing CTF Machine_CVE-2023-30258_Remote Code Execution
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISCO
abrir ↗GitHub PoC
A Dockerized setup for running a vulnerable CrushFTP 10 server instance (CVE-2024-4040).
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISCO
abrir ↗GitHub PoC★ 1
RestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT
RestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT
63RISCO
abrir ↗GitHub PoC★ 10
Breaking down CVE-2025-54253 — an Adobe AEM-Forms exploit path from XXE to full remote code execution and its real-world impact.
Adobe Experience Manager | Incorrect Authorization (CWE-863)
100RISCO
abrir ↗GitHub PoC★ 4
CVE-2025-11953 demonstration: Critical RCE vulnerability in React Native CLI (CVSS 9.8). Educational security research with proof-of-concept exploits and mitigation strategies.
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
90RISCO
abrir ↗GitHub PoC
PoC for CVE-2024-5932.
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RISCO
abrir ↗GitHub PoC★ 8
A vulnerability in fiberhome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-shared key) to be predicted from the SSID
A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-s
48RISCO
abrir ↗GitHub PoC★ 1
XWiki Unauthenticated RCE Exploit for Reverse Shell
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir ↗GitHub PoC★ 1
Exploit for CVE-2025-2011
Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection via 's' Parameter
68RISCO
abrir ↗GitHub PoC★ 1
This is a customized script to help solve the lab on remote code execution under the CVE-2015-3306 lab.
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISCO
abrir ↗GitHub PoC★ 1
My view on IngressNightmare vulnerability (CVE-2025-1974)
ingress-nginx admission controller RCE escalation
85RISCO
abrir ↗GitHub PoC
Exploit for CVE-2021-3560 Polkit Local Privilege Escalation Vulnerability
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISCO
abrir ↗GitHub PoC
CVE-2024-9047
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
85RISCO
abrir ↗GitHub PoC★ 1
A Proof of Concept (PoC) exploit for CVE-2015-1328
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISCO
abrir ↗GitHub PoC
Fast, socket-level scanner for detecting CVE-2022-22536 in SAP ICM or Web Dispatcher instances. Performs request smuggling tests with a crafted MPI-desync payload. Supports batch scanning IP:PORT targets via plain text files.
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RISCO
abrir ↗GitHub PoC★ 25
Proof-of-concept for CVE-2025-49844
Redis Lua Use-After-Free may lead to remote code execution
85RISCO
abrir ↗GitHub PoC
A XXE payload generator
WordPress Authenticated XXE attack when installation is running PHP 8
63RISCO
abrir ↗GitHub PoC★ 1
shiro 路径穿越
Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the
35RISCO
abrir ↗GitHub PoC
Mahfujurjust/CVE-2021-41773
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗GitHub PoC★ 1
adrianmafandy/CVE-2021-41773
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗GitHub PoC★ 1
WooCommerce Designer Pro 1.9.26 - Arbitrary File Upload
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISCO
abrir ↗GitHub PoC★ 2
A combined POC for CVE-2021-31955, CVE-2015-4077, and CVE-2015-5736
Windows Kernel Information Disclosure Vulnerability
85RISCO
abrir ↗GitHub PoC
TranDongA3/Simulation_CVE-2024-46256
A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add
48RISCO
abrir ↗GitHub PoC★ 2
A combined POC for CVE-2021-31955, CVE-2015-4077, and CVE-2015-5736
The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient b
23RISCO
abrir ↗GitHub PoC
Demo of CVE-2021-44228 Log4Shell.
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗GitHub PoC★ 1
Exploit for Remote Code Execution in ColdFusion 2021 (CVE-2023-26360)
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RISCO
abrir ↗GitHub PoC
A powerful and reliable exploit tool for Apache HTTP Server vulnerabilities CVE-2021-41773 and CVE-2021-42013. This tool provides remote code execution capabilities on vulnerable Apache 2.4.49 and 2.4.50 servers.
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.