Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 20.003GitHub PoC 13.307VulnCheck XDB 8.182Nuclei 4.217Metasploit 3.462✓ só verificadosrecentespopularesrisco
13.307 exploits
GitHub PoC★ 1
Esse script explora a vulnerabilidade CVE-2025-20124 — uma falha de Java Deserialization no Cisco ISE (Identity Services Engine) que permite Remote Code Execution (RCE).
Cisco Identity Services Engine Java Deserialization Vulnerability
53RISCO
abrir ↗GitHub PoC★ 46
WinRAR 0day CVE-2025-8088 PoC RAR Archive
Path traversal vulnerability in WinRAR
93RISCO
abrir ↗GitHub PoC
These PoC python scripts test the Kemp LoadMaster for remote code execution.
Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection
75RISCO
abrir ↗GitHub PoC★ 4
Python exploit for vsftpd 2.3.4 - Backdoor Command Execution
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir ↗GitHub PoC
Update the old POC of CVE-2025-5777 Citrix NetScaler Memory leak
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir ↗GitHub PoC
alexander47777/CVE-2016-10033
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir ↗GitHub PoC
Bash POC script for RCE vulnerability in Apache 2.4.49
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗GitHub PoC★ 3
CVE-2024-47533: Cobbler Authentication Bypass & Code Execution
Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes
63RISCO
abrir ↗GitHub PoC★ 1
Este script explora a vulnerabilidade CVE-2025-24813 em versões específicas do Apache Tomcat, permitindo execução remota de código (RCE) através de um vetor de desserialização Java e abuso do método HTTP PUT para gravação arbitrária de arquivos de sessão.
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗GitHub PoC
kylew1004/cve-2017-5941-poc-docker-lab
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RISCO
abrir ↗GitHub PoC★ 10
Python tool for safe archive handling, path traversal awareness, and secure extraction. Inspired by CVE-2025-8088.
Path traversal vulnerability in WinRAR
93RISCO
abrir ↗GitHub PoC
BiiTts/POC-IngressNightmare-CVE-2025-1974
ingress-nginx admission controller RCE escalation
85RISCO
abrir ↗GitHub PoC
TryHackMe CTF writeup — WordPress RCE via CVE-2024-25600, crypto miner forensics, and LockBit ransomware group identification
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir ↗GitHub PoC★ 6
POC for CVE-2025-4404
Freeipa: idm: privilege escalation from host to domain admin in freeipa
48RISCO
abrir ↗GitHub PoC
RAJMadhusankha/Shellshock-CVE-2014-6271-Exploitation-and-Analysis
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗GitHub PoC★ 4
POC exploit for CVE-2025-24893
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir ↗GitHub PoC
A POC for CVE-2025-24893 written in python
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir ↗GitHub PoC★ 6
This vulnerability could allow a malicious user to execute remote code by sending appropriately crafted requests to the default search engine SolrSearch
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir ↗GitHub PoC
XWiki 15.10.11, 16.4.1 and 16.5.0RC1 Unauthenticated Remote code execution POC
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir ↗GitHub PoC★ 2
Exploit demonstrating an authentication bypass vulnerability in the web interface of Belkin F9K1009 and F9K1010 routers.
Belkin F9K1009/F9K1010 Web Interface hard-coded credentials
48RISCO
abrir ↗GitHub PoC
This repository contains a completely original and self-developed Proof-of-Concept (PoC) for CVE-2018-7600, also known as Drupalgeddon 2 — a critical remote code execution vulnerability affecting Drupal 7 and 8 core versions.
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir ↗GitHub PoC
一个由AI生成的漏洞验证应用
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir ↗GitHub PoC★ 13
This CVE addresses a vulnerability in sudo versions 1.9.14 to 1.9.17, enabling unauthorized local privilege escalation to root access.
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗GitHub PoC★ 4
soltanali0/CVE-2025-5777-Exploit
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir ↗GitHub PoC
Scouserr/cve-2022-0847-poc-dockerimage
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir ↗GitHub PoC★ 5
Shenzhen Aitemi M300 Wi-Fi Repeater Unauthenticated RCE (CVE-2025-34152)
Shenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via Time Parameter
75RISCO
abrir ↗GitHub PoC★ 1
PoC to inject a command via the DEVICE_PING endpoint
Improper Neutralization of Special Elements used in a Command ('Command Injection') in Tigo Energy Cloud Connect Advanced
46RISCO
abrir ↗GitHub PoC★ 1
CVE-2025-24893 is a critical unauthenticated remote code execution (RCE) vulnerability in XWiki, a popular open-source enterprise wiki platform.
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.