Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 20.003GitHub PoC 13.307VulnCheck XDB 8.182Nuclei 4.217Metasploit 3.462✓ só verificadosrecentespopularesrisco
13.307 exploits
GitHub PoC★ 6
Detects vulnerable FreePBX versions affected by CVE-2025-57819.
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir ↗GitHub PoC
CrushFTP AS2 Authentication Bypass
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RISCO
abrir ↗GitHub PoC
This is repository contains a script to check for current IOCs listed in the freepbx forum topic of the CVE-2025-57819
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir ↗GitHub PoC
arun1033/CVE-2025-48384
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir ↗GitHub PoC★ 2
致远OA存在文件上传导致RCE(CVE-2025-34040)
Seeyon Zhiyuan OA System Path Traversal File Upload
68RISCO
abrir ↗GitHub PoC
Python Script for CVE-2025-49113. Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir ↗GitHub PoC
Mdusmandasthaheer/CVE-2025-32433
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir ↗GitHub PoC★ 4
swabird/CVE-2025-7775-PoC
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service
83RISCO
abrir ↗GitHub PoC★ 1
soltanali0/CVE-2024-12877-Exploit
GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection
48RISCO
abrir ↗GitHub PoC
PoC for CVE-2025-48384
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir ↗GitHub PoC
jacobholtz/CVE-2025-48384-submodule
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir ↗GitHub PoC
Naved124/CVE-2024-28397-js2py-Sandbox-Escape
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISCO
abrir ↗GitHub PoC
Built to call on CVE-2025-48384-PoC-Part2 for RCE
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir ↗GitHub PoC★ 1
Detection for CVE-2025-57819
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir ↗GitHub PoC
PoC | NextJS Middleware 15.2.2 - Authorization Bypass
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 11
IOS audio buffer overflow CVE-2025-31200 POC
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4
83RISCO
abrir ↗GitHub PoC★ 5
yukinime/CVE-2025-6934
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RISCO
abrir ↗GitHub PoC★ 3
用于CVE-2025-32463 sudo_chwoot的权限提升POC,适配了有gcc编译环境和无gcc编译环境的两种情况,下载运行即可一把梭哈
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗GitHub PoC
hacieda/CVE-2025-32463
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗GitHub PoC★ 8
A high-performance, memory-safe implementation of the WinRAR CVE-2025-8088 exploit tool, rewritten in Rust for better reliability and performance.
Path traversal vulnerability in WinRAR
93RISCO
abrir ↗GitHub PoC
A standalone Rust implementation of the CVE-2007-2447 exploit targeting Samba smbd 3.0.20-Debian.
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir ↗GitHub PoC★ 10
Winrar CVE exploitation before 7.13 using multiple ADS streams on a single file (Custom PDF implementation)
Path traversal vulnerability in WinRAR
93RISCO
abrir ↗GitHub PoC
te0rwx/CVE-2025-32433-Detection
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir ↗GitHub PoC
An exploitation framework for CVE-2018-19323 - GIGABYTE GDrv privilege escalation vulnerability with multi-architecture support and framework integration
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
78RISCO
abrir ↗GitHub PoC★ 2
Unauth RCE PoC for XWiki SolrSearch (CVE-2025-24893). Command exec + reverse shell.
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir ↗GitHub PoC
A critical remote code execution (RCE) vulnerability (CVE‑2025‑24893) exists in the XWiki Platform, specifically in the SolrSearch RSS feed endpoint.
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir ↗GitHub PoC★ 1
Real4XoR/CVE-2019-6693
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacke
63RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.