Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.095exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.442GitHub PoC 15.312VulnCheck XDB 8.970Nuclei 4.393Metasploit 3.502✓ só verificadosrecentespopularesrisco
15.312 exploits
GitHub PoC★ 12
UAF and AOP coprocessor panic in IOHIDEventServiceFastPathUserClient. No entitlements, reachable from app sandbox.
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7
33RISCO
abrir ↗GitHub PoC★ 2
Herramienta avanzada de explotación transversal de ruta de WinRAR para CVE-2025-8088
Path traversal vulnerability in WinRAR
93RISCO
abrir ↗GitHub PoC
A lightweight Docker lab for experimenting with Telnet protocol negotiation, explained in the CVE-2026-24061 exploit, which contains automatic username injection using the NEW-ENVIRON option.
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir ↗GitHub PoC
nik123-py/CVE-2025-49132_HTB_SEASON10
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISCO
abrir ↗GitHub PoC★ 49
The PoC for CVE-2025-70795 / CVE-2026-0828 and updated driver
STProcessMonitor 11.11.4.0, part of the Safetica Application suite, allows an admin-privileged user to send crafted IOCT
33RISCO
abrir ↗GitHub PoC★ 5
A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to execute arbitrary code via injecting crafted Freemarker template syntax into the SQL script field.
A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows aut
48RISCO
abrir ↗GitHub PoC
mbanyamer/CVE-2026-26335-Calero-VeraSMART-RCE
Calero VeraSMART < 2022 R1 Static IIS Machine Keys Enable ViewState RCE
48RISCO
abrir ↗GitHub PoC
Домашняя работа по Pyton № 10 CVE-2020-11022 Краткое описание CVE-2020-11022 — уязвимость типа Reflected XSS (межсайтовый скриптинг), связанная с некорректной обработкой пользовательского ввода, который отражается в HTML-ответе без экранирования. Атакующий может внедрить JavaScript-код, который выполнится в браузере пользователя.
jQuery has a potential XSS vulnerability
55RISCO
abrir ↗GitHub PoC★ 12
UAF and AOP coprocessor panic in IOHIDEventServiceFastPathUserClient. No entitlements, reachable from app sandbox.
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7
33RISCO
abrir ↗GitHub PoC
CVE-2024-37383 Proof of Concept
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
85RISCO
abrir ↗GitHub PoC★ 50
The PoC for CVE-2025-70795 / CVE-2026-0828 and updated driver
Kernel driver vulnerability in Safetica Endpoint Client
41RISCO
abrir ↗GitHub PoC
Privilege escalation exploit chain (CVE-2025-6018 + CVE-2025-6019) for openSUSE Leap 15.6
Pam-config: lpe from unprivileged to allow_active in pam
41RISCO
abrir ↗GitHub PoC
Samba 3.0.20 CVE-2007-2447 Exploit
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir ↗GitHub PoC★ 1
针对 Next.js 原型污染漏洞 (CVE-2025-55182) 的高效批量检测工具。
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗GitHub PoC★ 1
Vulnerability chaining leads to privilege escalation
Pam-config: lpe from unprivileged to allow_active in pam
41RISCO
abrir ↗GitHub PoC
BIG02-bot/React2Shell-CVE-2025-55182-An-lise-T-cnica
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗GitHub PoC★ 4
watchtowrlabs/watchTowr-vs-SolarWinds-WebHelpDesk-CVE-2025-40552-CVE-2025-40553
SolarWinds Web Help Desk Authentication Bypass Vulnerability
75RISCO
abrir ↗GitHub PoC★ 1
CVE-2024-34102 exploit for python3
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir ↗GitHub PoC★ 3
CVE-2025-49132_PHP_PEAR_METHOD
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISCO
abrir ↗GitHub PoC
scroollocker/CVE-2025-49132
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISCO
abrir ↗GitHub PoC★ 5
CVE-2025-6018 CVE-2025-6019 PoC Exploit - Local Privilege Escalation in openSUSE/SUSE Linux Enterprise 15 - PAM bypass + udisks2 XFS race condition LPE to root
Pam-config: lpe from unprivileged to allow_active in pam
41RISCO
abrir ↗GitHub PoC★ 2
React2Shell (CVE-2025-55182) POC
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗GitHub PoC
Sn0wBaall/CVE-2023-4220-PoC
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir ↗GitHub PoC★ 1
Exploit CVE-2025-49132 Pterodactyl Panel RCE
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISCO
abrir ↗GitHub PoC
Real-world information security risk assessment based on the Oracle E-Business Suite zero-day (CVE-2025-61882). Analyses attacker methods, enterprise risks, and mitigation strategies using ISO 27001, NIST CSF, Cyber Essentials and COBIT.
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integratio
100RISCO
abrir ↗GitHub PoC
mbanyamer/CVE-2026-26235-JUNG-Smart-Visu-Server-Unauthenticated-Reboot-Shutdown
JUNG Smart Visu Server 1.1.1050 - 'JUNG Smart Visu Server' Missing Authentication
41RISCO
abrir ↗GitHub PoC★ 1
Ni8mare, n8n RCE
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RISCO
abrir ↗GitHub PoC★ 4
This program Prompts you for the Local File Inclusion information and will automatically search the /etc/passwd and using the users names found will search for and download any SSH key or variation of keys to the local computer. This program also performs the CVE-2021-41773_ apache2.4.49 and 50 traversal path exploit. In addtion to other LFI Vuln
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗GitHub PoC
A POC chain exploit using the recent Cisco SMP exploit (CVE-2017-6736) to chain into Spectre (CVE-2017-5753 and CVE-2017-5715)
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabiliti
93RISCO
abrir ↗GitHub PoC
ISabbiI/PoC-Apache-CVE-2021-41773-Infrastructure-LAB
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.