Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8.176Nuclei 4.202Metasploit 3.462✓ só verificadosrecentespopularesrisco
71.886 exploits
GitHub PoC★ 1
PoC for Mirth Connect Remote Code Execution (RCE)
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISCO
abrir ↗GitHub PoC★ 3
CVE-2023-43208: Mirth Connect Pre-Auth RCE PoC
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISCO
abrir ↗VulnCheck XDB
local
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RISCO
abrir ↗VulnCheck XDB
initial-access
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗VulnCheck XDB
initial-access
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISCO
abrir ↗VulnCheck XDB
initial-access
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISCO
abrir ↗GitHub PoC
Stored Cross-Site Scripting in "usememos" via SVG
The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a us
48RISCO
abrir ↗VulnCheck XDB
initial-access
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir ↗GitHub PoC
danilo1992-sys/CVE-2025-32463
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗GitHub PoC
its970/CVE-2025-68645
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1
98RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
Active Directory Domain Services Elevation of Privilege Vulnerability
100RISCO
abrir ↗VulnCheck XDB
initial-access
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISCO
abrir ↗GitHub PoC
The flaw allows an attacker to execute arbitrary system commands on the server hosting the Pterodactyl Panel without any prior authentication.
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISCO
abrir ↗GitHub PoC★ 1
Exploitation de CVE-2022-26923
Active Directory Domain Services Elevation of Privilege Vulnerability
100RISCO
abrir ↗VulnCheck XDB
initial-access
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1
98RISCO
abrir ↗GitHub PoC
A practical lab demonstrating the exploitation of a critical Remote Code Execution (RCE) vulnerability in Apache Struts2 (CVE-2017-5638) using Vulhub Docker environments. Includes setup instructions and commands to run the vulnerable container.
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir ↗GitHub PoC
C reimplementation of chwoot PoC
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗GitHub PoC
Path traversal vulnerability in Python's tarfile.
Arbitrary writes via tarfile realpath overflow
48RISCO
abrir ↗GitHub PoC
CVE-2022-37969 poc
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir ↗VulnCheck XDB
initial-access
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir ↗VulnCheck XDB
local
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
Slider Future <= 1.0.5 - Unauthenticated Arbitrary File Upload
63RISCO
abrir ↗GitHub PoC
A proof of concept for CVE-2025-31161, using mangled HTTP header to perform unauthenticated impersonation of any user in Crush FTP server.
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISCO
abrir ↗VulnCheck XDB
initial-access
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
100RISCO
abrir ↗VulnCheck XDB
initial-access
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗VulnCheck XDB
local
Windows Common Log File System Driver Elevation of Privilege Vulnerability
71RISCO
abrir ↗VulnCheck XDB
initial-access
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
100RISCO
abrir ↗GitHub PoC
CVE-2014-6271 Exploit | by infrar3d
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗GitHub PoC★ 1
Unauthenticated remote code execution vulnerability in Wing FTP Server <= 7.4.3.
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
SPIP Saisies Plugin < 5.11.1 Remote Code Execution
63RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.