Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.051exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.442GitHub PoC 15.268VulnCheck XDB 8.970Nuclei 4.393Metasploit 3.502✓ só verificadosrecentespopularesrisco
15.273 exploits
GitHub PoC
a PoC for the Nagios CVE-2019-15949 rce in python
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios
100RISCO
abrir ↗GitHub PoC
Proof-of-concept for CVE-2025-55182 (React2Shell): unauthenticated RCE in React Server Components / Next.js via Flight protocol deserialization.
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗GitHub PoC
Security research and reproduction of CVE-2025-5548: A stack-based buffer overflow in FreeFloat FTP Server 1.0. Includes binary analysis, crash replication, and environment setup for vulnerability research.
FreeFloat FTP Server NOOP Command buffer overflow
38RISCO
abrir ↗GitHub PoC★ 1
uname1able/CVE-2025-29824
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir ↗GitHub PoC
REC Exploit is a Python-based security testing tool that automates detection of potential RCE conditions in web applications under authorized environments. It sends crafted POST requests to targets, analyzes server responses for execution indicators, and supports batch scanning with custom input, structured payload handling, and clear CLI output.
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗GitHub PoC
Authenticated RCE in pgAdmin 4 (8.10–9.1) via eval() injection in the Query Tool. This is an updated PoC with compatibility fixes for pgAdmin 9.x auth changes
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
75RISCO
abrir ↗GitHub PoC
Binary exploitation laboratory: Environment setup and step-by-step walkthrough for exploiting CVE-2025-5548 using Ghidra, Immunity Debugger, and Python.
FreeFloat FTP Server NOOP Command buffer overflow
38RISCO
abrir ↗GitHub PoC
CVE-2020-5902
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir ↗GitHub PoC
12-test-12/CVE-2025-3248
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir ↗GitHub PoC
CVE-2022-42889 취약점 분석보고서
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir ↗GitHub PoC
jgs-developer/CVE-2025-5548
FreeFloat FTP Server NOOP Command buffer overflow
38RISCO
abrir ↗GitHub PoC
The script performs a full Telnet negotiation mirroring the exact byte sequence of a real telnet -a client session.
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir ↗GitHub PoC
Proof-of-Concept exploit for Apache Struts S2-052 (CVE-2017-9805) XML Deserialization Remote Code Execution. Created while solving the INE eWPTX Practice Range lab. Includes custom payloads, reverse shell exploit script, and step-by-step exploitation examples.
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISCO
abrir ↗GitHub PoC
Vulnerable Docker lab and exploit for Apache HTTP Server 2.4.49 path traversal vulnerability (CVE‑2021‑41773)
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗GitHub PoC
luisyapura/Analisis-y-Explotacion-de-CVE-2025-5548
FreeFloat FTP Server NOOP Command buffer overflow
38RISCO
abrir ↗GitHub PoC★ 2
Security research and technical analysis of CVE-2025-5548, a buffer overflow vulnerability affecting FreeFloat FTP Server 1.0. This repository documents vulnerability behavior, attack surface, controlled proof of concept testing, and defensive insights within a structured research environment for cybersecurity learning and analysis.
FreeFloat FTP Server NOOP Command buffer overflow
38RISCO
abrir ↗GitHub PoC
exploit para a CVE-2021-41773:Path Traversal cgi-bin
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗GitHub PoC
Apache ActiveMQ OpenWire 역직렬화 RCE 취약점 기술 분석
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISCO
abrir ↗GitHub PoC
POC for log4shll Vulnerablity (CVE-2021-44228)
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗GitHub PoC
Laboratorio de análisis y explotación de la vulnerabilidad CVE-2025-5548 en FreeFloat FTP Server 1.0
FreeFloat FTP Server NOOP Command buffer overflow
38RISCO
abrir ↗GitHub PoC
sumaiyafathima-code/CVE-2023-27524
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISCO
abrir ↗GitHub PoC
Heap Buffer Overflow in CVE-2025-5548
FreeFloat FTP Server NOOP Command buffer overflow
38RISCO
abrir ↗GitHub PoC
Script and node.proto for exploit CVE-2025-68926
RustFS has a gRPC Hardcoded Token Authentication Bypass
60RISCO
abrir ↗GitHub PoC
Análisis técnico, preparación de entorno de laboratorio y desarrollo de exploit (RCE) para la vulnerabilidad CVE-2025-5548 en FreeFloat FTP Server.
FreeFloat FTP Server NOOP Command buffer overflow
38RISCO
abrir ↗GitHub PoC
LorenzoPorrasDuque/CVE-2025-5548-POC
FreeFloat FTP Server NOOP Command buffer overflow
38RISCO
abrir ↗GitHub PoC
MotionEye v0.43.1b4 OS Command Injection
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name
61RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.