Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.095exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
15.312 exploits
GitHub PoC
hook repo for cve-2024-32002
CVE-2024-32002CRITICAL12 mar 2026
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
GitHub PoC1
A simple Docker lab and Exploit setup for CVE-2021-3156 - "Baron Samedit".
CVE-2021-3156HIGHsob ataque11 mar 2026
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC1
CVE-2023-6329 – Authentication bypass PoC for Control iD iDSecure ≤ 4.7.43.0
CVE-2023-6329CRITICAL11 mar 2026
Control iD iDSecure passwordCustom Authentication Bypass
75RISCO
abrir
GitHub PoC
Scripts en Python para la explotación de CVE-2024-51482 (SQLi en ZoneMinder) — HTB CCTV
CVE-2024-51482CRITICAL11 mar 2026
Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64
75RISCO
abrir
GitHub PoC
michalAshurov/writeup-CVE-2024-3094
CVE-2024-3094CRITICAL11 mar 2026
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC
Advanced SMB Honeypot: CVE-2025-33073 Research & Implementation
CVE-2025-33073HIGHsob ataque11 mar 2026
Windows SMB Client Elevation of Privilege Vulnerability
93RISCO
abrir
GitHub PoC
Proof of concept exploit for CVE-2019-10068.
CVE-2019-10068CRITICALsob ataque11 mar 2026
An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions
100RISCO
abrir
GitHub PoC7
MistyFir/CVE-2024-21338-Exploit
CVE-2024-21338HIGHsob ataqueransomware11 mar 2026
Windows Kernel Elevation of Privilege Vulnerability
83RISCO
abrir
GitHub PoC2
CVE-2025-66398 — Signal K Server ≤ 2.18.0 RCE PoC
CVE-2025-66398CRITICAL10 mar 2026
Signal K Server has Unauthenticated State Pollution leading to Remote Code Execution (RCE)
53RISCO
abrir
GitHub PoC
engranaabubakar/CVE-2022-42889
CVE-2022-4288910 mar 2026
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC5
Comprehensive deobfuscated research of the Coruna iOS exploit kit targeting CVE-2024-23222. Analysis of WebKit Type Confusion, PAC Bypass, and Sandbox Escape
CVE-2024-23222HIGHsob ataque10 mar 2026
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.
76RISCO
abrir
GitHub PoC
Writeup of the Optimum machine from Hack The Box. This walkthrough covers the exploitation of Rejetto HttpFileServer 2.3 (CVE-2014-6287) to gain initial access, followed by privilege escalation on a Windows host using enumeration techniques and post-exploitation tools.
CVE-2014-6287CRITICALsob ataque10 mar 2026
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir
GitHub PoC2
CVE-2026-6508 LiderAhenk Merkezi Yönetim Sistemi mimarisinde, uç birimler (agents) arası tüm istemcilerin birbirleri üzerinde 'root' yetkisiyle kod çalıştırılmasına (unauthorized rce & lateral movement) olanak tanıyan kritik güvenlik zafiyeti.
CVE-2026-6508CRITICAL10 mar 2026
RCE in TUBITAK BILGEM's Liderahenk
48RISCO
abrir
GitHub PoC
CVE-2025-49844
CVE-2025-49844CRITICAL09 mar 2026
Redis Lua Use-After-Free may lead to remote code execution
85RISCO
abrir
GitHub PoC
OpenSSH regreSSHion (CVE-2024-6387) Lab
CVE-2024-6387HIGH09 mar 2026
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir
GitHub PoC
swoon69/CVE-2025-59287-Exercise-Use
CVE-2025-59287CRITICALsob ataque09 mar 2026
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC3
cupntlm
CVE-2025-33073HIGHsob ataque09 mar 2026
Windows SMB Client Elevation of Privilege Vulnerability
93RISCO
abrir
GitHub PoC
libssh Authentication Bypass (CVE-2018-10933) Lab
CVE-2018-10933CRITICAL09 mar 2026
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC
OpenSSH User Enumeration (CVE-2018-15473) Lab
CVE-2018-15473MEDIUM09 mar 2026
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC
demo application showing off SQL Injection exploit in django 5.2.7
CVE-2025-64459CRITICAL09 mar 2026
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RISCO
abrir
GitHub PoC
gregk4sec/cve-2025-31651
CVE-2025-31651CRITICAL09 mar 2026
Apache Tomcat: Bypass of rules in Rewrite Valve
48RISCO
abrir
GitHub PoC1
Buffer overflow in FreeFloat FTP Server 1.0 illustrating how a single unsafe handler can generate multiple CVE entries across different commands.
CVE-2025-5548MEDIUM09 mar 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISCO
abrir
GitHub PoC
learning github
CVE-2021-2476209 mar 2026
Perfect Survey < 1.5.2 - Unauthenticated SQL Injection
60RISCO
abrir
GitHub PoC1
PoC for CVE-2024-22393: Pixel Flood DoS in Apache Answer ≤1.2.1. Upload crafted 5KB image with fake 64Kx64K dimensions. Server allocates memory for 4B+ pixels and crashes. Find targets via "Powered by Apache Answer." Check bounty program rules before testing—DoS testing is often prohibited.
CVE-2024-22393CRITICAL09 mar 2026
Apache Answer: Pixel Flood Attack by uploading the large pixel file
48RISCO
abrir
GitHub PoC1
ApacheHunter detects CVE-2024-22393 in Apache Answer servers. Like Wappalyzer but CLI-based. Scans headers, page content, meta tags, and paths to identify Apache versions and vulnerable installations (≤1.2.1). No output files—just real-time results.
CVE-2024-22393CRITICAL09 mar 2026
Apache Answer: Pixel Flood Attack by uploading the large pixel file
48RISCO
abrir
GitHub PoC
VX Search Enterprise v10.1.12 Remote Buffer Overflow
CVE-2017-1522009 mar 2026
Flexense VX Search Enterprise 10.1.12 is vulnerable to a buffer overflow via an empty POST request to a long URI beginni
23RISCO
abrir
GitHub PoC1
SOC investigation of CVE-2024-49138 exploitation alert involving PowerShell, EDRFreeze execution, and defense evasion behavior in a simulated environment.
CVE-2024-49138HIGHsob ataque09 mar 2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC1
CVE-2026-24061
CVE-2026-24061CRITICALsob ataque09 mar 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
gustavorobertux/cisco-cve-2023-20198-checker
CVE-2023-20198CRITICALsob ataque08 mar 2026
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISCO
abrir
GitHub PoC824
CVE-2026-24061 exploit PoC
CVE-2026-24061CRITICALsob ataque08 mar 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
anteriorpágina 123 / 511próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.