Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
13.307 exploits
GitHub PoC1
Shinkirou789/Cve-2025-8088-WinRar-vulnerability
CVE-2025-8088HIGHsob ataque17 set 2025
Path traversal vulnerability in WinRAR
93RISCO
abrir
GitHub PoC
CVE-2019-3396 confluence SSTI RCE
CVE-2019-3396CRITICALsob ataqueransomware16 set 2025
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISCO
abrir
GitHub PoC2
Example PoC for CVE-2025-24813 (Tomcat RCE)
CVE-2025-24813CRITICALsob ataque16 set 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC
PoC for CVE-2025-20265 Cisco Secure FMC Software RADIUS Remote Code Execution Vulnerability
CVE-2025-20265CRITICAL16 set 2025
Cisco Secure Firewall Management Center Software Radius Remote Code Execution Vulnerability
53RISCO
abrir
GitHub PoC
A Rust implementation of the CVE-2014-6287 exploit targeting Rejetto HTTP File Server (HFS) versions 2.3x before 2.3c.
CVE-2014-6287CRITICALsob ataque16 set 2025
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir
GitHub PoC2
RedArrow3.2 是一款用于渗透测试ThinkPHP 5.0.23 远程命令执行漏洞(CVE-2018-20062)的图形化工具。
CVE-2018-20062CRITICALsob ataque16 set 2025
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RISCO
abrir
GitHub PoC
2 web apps vulnerable to CVE-2025-27210
CVE-2025-27210HIGH16 set 2025
An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CO
41RISCO
abrir
GitHub PoC
tranphuc2005/CVE-2017-9822
CVE-2017-9822HIGHsob ataqueransomware15 set 2025
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code e
100RISCO
abrir
GitHub PoC
0xDTC/js2py-Sandbox-Escape-CVE-2024-28397-RCE
CVE-2024-28397MEDIUM15 set 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISCO
abrir
GitHub PoC1
Langflow Remote Code Execution
CVE-2025-3248CRITICALsob ataqueransomware15 set 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
GitHub PoC
tcetin704/CVE-2017-12611
CVE-2017-1261115 set 2025
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag in
60RISCO
abrir
GitHub PoC
Authentication bypass vulnerability in versions of the CrushFTP server.
CVE-2025-31161CRITICALsob ataqueransomware15 set 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISCO
abrir
GitHub PoC
shoucheng3/apache__dolphinscheduler_CVE-2023-49109_3_2_1_fixed
CVE-2023-49109CRITICAL14 set 2025
Remote Code Execution in Apache Dolphinscheduler
48RISCO
abrir
GitHub PoC1
Safe, read-only SQL Injection checker for FreePBX (CVE-2025-57819), using error/boolean/time-based techniques with per-parameter verdicts and JSON reporting.
CVE-2025-57819CRITICALsob ataque14 set 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir
GitHub PoC
A proof-of-concept exploit for WinRAR vulnerability (CVE-2025-8088) affecting versions 7.12 and lower. This tool creates a malicious RAR archive that embeds payloads in Alternate Data Streams (ADS) with path traversal, potentially leading to arbitrary code execution.
CVE-2025-8088HIGHsob ataque14 set 2025
Path traversal vulnerability in WinRAR
93RISCO
abrir
GitHub PoC
Shubhankargupta691/CVE-2024-42009
CVE-2024-42009CRITICALsob ataque14 set 2025
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RISCO
abrir
GitHub PoC
Documented CVE-2021-41773 (Apache HTTP Server path traversal, CVSS 9.8) — produced CVSS breakdown, impact assessment, and a mitigation plan (patch to 2.4.51+, CGI disable, firewall) and published the analysis on GitHub.
CVE-2021-41773HIGHsob ataqueransomware14 set 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
CVE-2025-48384-submodule
CVE-2025-48384HIGHsob ataque13 set 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC1
Hands-on pentest project using Kali Linux vs Metasploitable2. Includes full workflow: Nmap scanning, enumeration, Metasploit exploitation (Samba CVE-2007-2447), post-exploitation validation, and mitigation steps. Repo contains commands, outputs, and report showing both offensive techniques and defensive recommendations.
CVE-2007-244713 set 2025
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir
GitHub PoC7
Python PoC script for pgAdmin4 Query Tool RCE (CVE-2025-2945)
CVE-2025-2945CRITICAL13 set 2025
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
75RISCO
abrir
GitHub PoC
chin-tech/CrushFTP_CVE-2025-54309
CVE-2025-54309CRITICALsob ataque13 set 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RISCO
abrir
GitHub PoC
Grafana SQL Expressions → DuckDB LFI (CVE-2024-9264)
CVE-2024-9264CRITICAL13 set 2025
Grafana SQL Expressions allow for remote code execution
85RISCO
abrir
GitHub PoC2
CVE-2024-3094 exposed a backdoor in the XZ compression library, allowing remote SSH access by bypassing authentication. It’s a major supply chain attack affecting Linux systems, highlighting risks in trusted open-source components.
CVE-2024-3094CRITICAL12 set 2025
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC
Grafana CVE-2025-4123-POC
CVE-2025-4123HIGH12 set 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISCO
abrir
GitHub PoC6
FreePBX versions 15, 16, and 17 contain a Remote Code Execution (RCE) vulnerability caused by insufficient sanitization of user-supplied data in endpoints.
CVE-2025-57819CRITICALsob ataque12 set 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir
GitHub PoC
GIT vulnerability | Carriage Return and RCE on cloning
CVE-2025-48384HIGHsob ataque12 set 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC4
Ash1996x/CVE-2025-54914-PoC
CVE-2025-54914CRITICAL12 set 2025
Azure Networking Elevation of Privilege Vulnerability
48RISCO
abrir
GitHub PoC1
JinhyukKo/CVE-2024-4701-POC
CVE-2024-4701CRITICAL12 set 2025
Path Traversal vulnerability via File Uploads in Genie
53RISCO
abrir
GitHub PoC1
For CTF's and Safe Environments.... CVE-2021-4034 Local PrivEsc.
CVE-2021-4034HIGHsob ataque11 set 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
A hands-on simulation of CVE-2017-5638 (Apache Struts2 RCE), showcasing exploit reproduction, OS-level command execution, and mitigations such as input sanitization and endpoint monitoring. Built in Python/Flask with Jupyter notebook demos
CVE-2017-5638CRITICALsob ataqueransomware11 set 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
anteriorpágina 118 / 444próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.