Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
13.282 exploits
GitHub PoC
CVE-2025-54782
CVE-2025-54782CRITICAL06 nov 2025
@nestjs/devtools-integration's CSRF to Sandbox Escape Allows for RCE against JS Developers
75RISCO
abrir
GitHub PoC8
CVE-2025-53690 POC
CVE-2025-53690CRITICALsob ataque05 nov 2025
Sitecore Products ViewState Deserialization Vulnerability
90RISCO
abrir
GitHub PoC
Billing CTF Machine_CVE-2023-30258_Remote Code Execution
CVE-2023-30258CRITICAL05 nov 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISCO
abrir
GitHub PoC
A Dockerized setup for running a vulnerable CrushFTP 10 server instance (CVE-2024-4040).
CVE-2024-4040CRITICALsob ataque05 nov 2025
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISCO
abrir
GitHub PoC1
RestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT
CVE-2025-9209CRITICAL05 nov 2025
RestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT
63RISCO
abrir
GitHub PoC10
Breaking down CVE-2025-54253 — an Adobe AEM-Forms exploit path from XXE to full remote code execution and its real-world impact.
CVE-2025-54253CRITICALsob ataque04 nov 2025
Adobe Experience Manager | Incorrect Authorization (CWE-863)
100RISCO
abrir
GitHub PoC4
CVE-2025-11953 demonstration: Critical RCE vulnerability in React Native CLI (CVSS 9.8). Educational security research with proof-of-concept exploits and mitigation strategies.
CVE-2025-11953CRITICALsob ataque04 nov 2025
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
90RISCO
abrir
GitHub PoC
PoC for CVE-2024-5932.
CVE-2024-5932CRITICAL04 nov 2025
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RISCO
abrir
GitHub PoC8
A vulnerability in fiberhome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-shared key) to be predicted from the SSID
CVE-2025-63353CRITICAL04 nov 2025
A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-s
48RISCO
abrir
GitHub PoC1
XWiki Unauthenticated RCE Exploit for Reverse Shell
CVE-2025-24893CRITICALsob ataque03 nov 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC1
Exploit for CVE-2025-2011
CVE-2025-2011HIGH02 nov 2025
Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection via 's' Parameter
68RISCO
abrir
GitHub PoC1
This is a customized script to help solve the lab on remote code execution under the CVE-2015-3306 lab.
CVE-2015-330602 nov 2025
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISCO
abrir
GitHub PoC1
My view on IngressNightmare vulnerability (CVE-2025-1974)
CVE-2025-1974CRITICAL02 nov 2025
ingress-nginx admission controller RCE escalation
85RISCO
abrir
GitHub PoC
Exploit for CVE-2021-3560 Polkit Local Privilege Escalation Vulnerability
CVE-2021-3560HIGHsob ataque01 nov 2025
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISCO
abrir
GitHub PoC
CVE-2024-9047
CVE-2024-9047CRITICAL01 nov 2025
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
85RISCO
abrir
GitHub PoC1
A Proof of Concept (PoC) exploit for CVE-2015-1328
CVE-2015-132801 nov 2025
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISCO
abrir
GitHub PoC
Fast, socket-level scanner for detecting CVE-2022-22536 in SAP ICM or Web Dispatcher instances. Performs request smuggling tests with a crafted MPI-desync payload. Supports batch scanning IP:PORT targets via plain text files.
CVE-2022-22536CRITICALsob ataque31 out 2025
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RISCO
abrir
GitHub PoC25
Proof-of-concept for CVE-2025-49844
CVE-2025-49844CRITICAL31 out 2025
Redis Lua Use-After-Free may lead to remote code execution
85RISCO
abrir
GitHub PoC
A XXE payload generator
CVE-2021-29447HIGH31 out 2025
WordPress Authenticated XXE attack when installation is running PHP 8
63RISCO
abrir
GitHub PoC1
shiro 路径穿越
CVE-2010-386331 out 2025
Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the
35RISCO
abrir
GitHub PoC
Mahfujurjust/CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware31 out 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC1
adrianmafandy/CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware31 out 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC1
WooCommerce Designer Pro 1.9.26 - Arbitrary File Upload
CVE-2025-6440CRITICAL30 out 2025
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISCO
abrir
GitHub PoC2
A combined POC for CVE-2021-31955, CVE-2015-4077, and CVE-2015-5736
CVE-2021-31955MEDIUMsob ataque29 out 2025
Windows Kernel Information Disclosure Vulnerability
85RISCO
abrir
GitHub PoC
TranDongA3/Simulation_CVE-2024-46256
CVE-2024-46256CRITICAL29 out 2025
A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add
48RISCO
abrir
GitHub PoC2
A combined POC for CVE-2021-31955, CVE-2015-4077, and CVE-2015-5736
CVE-2015-407729 out 2025
The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient b
23RISCO
abrir
GitHub PoC
Zohaibkhan1472/cve-2023-6019
CVE-2023-6019CRITICAL28 out 2025
Ray Command Injection in cpu_profile Parameter
85RISCO
abrir
GitHub PoC
Demo of CVE-2021-44228 Log4Shell.
CVE-2021-44228CRITICALsob ataqueransomware28 out 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
Exploit for Remote Code Execution in ColdFusion 2021 (CVE-2023-26360)
CVE-2023-26360HIGHsob ataque28 out 2025
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RISCO
abrir
GitHub PoC
A powerful and reliable exploit tool for Apache HTTP Server vulnerabilities CVE-2021-41773 and CVE-2021-42013. This tool provides remote code execution capabilities on vulnerable Apache 2.4.49 and 2.4.50 servers.
CVE-2021-42013CRITICALsob ataqueransomware28 out 2025
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
anteriorpágina 111 / 443próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.