Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

72.018exploits catalogados
32.219CVEs com exploração pública
1.932testados em laboratório
13.320 exploits
GitHub PoC
rpc.py 0.6.0 - Remote Code Execution (RCE)
CVE-2022-3541116 jul 2025
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header i
35RISCO
abrir
GitHub PoC5
An in-depth analysis of CVE 2023 38408, a critical OpenSSH vulnerability, including technical background, exploitation in controlled environments, and mitigation strategies.
CVE-2023-38408CRITICAL16 jul 2025
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISCO
abrir
GitHub PoC
CVE-2025-53833
CVE-2025-53833CRITICAL16 jul 2025
LaRecipe is vulnerable to Server-Side Template Injection attacks
63RISCO
abrir
GitHub PoC
Exploit for php-cgi
CVE-2024-4577CRITICALsob ataqueransomware16 jul 2025
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
nguyentranbaotran/cve-2025-48384-poc
CVE-2025-48384HIGHsob ataque16 jul 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC
Detection for CVE-2025-47812
CVE-2025-47812CRITICALsob ataque16 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir
GitHub PoC1
PoC for CVE-2025-25257, a critical unauthenticated SQL injection in FortiWeb. Exploits SQLi via the Authorization header to write a webshell and gain RCE. No login required. Fully automated.
CVE-2025-25257CRITICALsob ataque15 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISCO
abrir
GitHub PoC
ECHO6789/CVE-2025-48384-submodule
CVE-2025-48384HIGHsob ataque15 jul 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC
CVE-2025-5777 (CitrixBleed 2) - [Citrix NetScaler ADC] [Citrix Gateway]
CVE-2025-5777CRITICALsob ataqueransomware15 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
GitHub PoC2
An advanced, powerful, and easy-to-use tool designed to detect and exploit CVE-2025-5777 (CitrixBleed 2). This script not only identifies the vulnerability but also helps in demonstrating its impact by parsing human-readable information from the memory leak.
CVE-2025-5777CRITICALsob ataqueransomware15 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
GitHub PoC7
HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 - Unauthenticated Arbitrary File Upload
CVE-2025-7340CRITICAL14 jul 2025
HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 - Unauthenticated Arbitrary File Upload
48RISCO
abrir
GitHub PoC
CVE-2025-29927 PoC | Auth Bypass Exploit | Python Tool using httpx | Middleware Vulnerability | Ethical Hacking Toolkit
CVE-2025-29927CRITICAL14 jul 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
Armand2002/Exploit-CVE-2025-1974-Lab
CVE-2025-1974CRITICAL14 jul 2025
ingress-nginx admission controller RCE escalation
85RISCO
abrir
GitHub PoC48
Privilege escalation to root using sudo chroot, NO NEED for gcc installed.
CVE-2025-32463CRITICALsob ataque14 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC
mheranco/CVE-2025-44136
CVE-2025-44136CRITICAL14 jul 2025
MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an e
63RISCO
abrir
GitHub PoC2
This repository includes the code and files needed to test and execute a PoC for CVE-2025-41656
CVE-2025-41656CRITICAL14 jul 2025
Pilz: Missing Authentication in Node-RED integration
53RISCO
abrir
GitHub PoC1
This repository contains a proof-of-concept exploit for CVE-2025-48827, a critical authentication bypass vulnerability affecting vBulletin 5.0.0–5.7.5 and 6.0.0–6.0.3 when running on PHP 8.1 or later. The vulnerability allows unauthenticated attackers to invoke protected API methods remotely.
CVE-2025-48827CRITICAL14 jul 2025
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
85RISCO
abrir
GitHub PoC2
Royal Elementor Addons - Unauthenticated Remote Code Execution
CVE-2023-536014 jul 2025
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RISCO
abrir
GitHub PoC14
A detailed walkthrough of TryHackMe's Billing room exploiting CVE-2023-30258 and escalating via fail2ban misconfig
CVE-2023-30258CRITICAL13 jul 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISCO
abrir
GitHub PoC8
Wazuh 8.4 CVE-2025-24016
CVE-2025-24016CRITICALsob ataque13 jul 2025
Remote code execution in Wazuh server
100RISCO
abrir
GitHub PoC
This is a security assessment report regarding the EthernalBlue vulnerability (CVE-2017-0143).
CVE-2017-0143HIGHsob ataqueransomware13 jul 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
GitHub PoC2
🚀 Exploit for Moodle 4.4.0 Authenticated RCE (CVE-2024-43425) — run commands remotely ⚡
CVE-2024-43425HIGH13 jul 2025
Moodle: remote code execution via calculated question types
78RISCO
abrir
GitHub PoC
Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected. This vulnerability is fixed in 6.2.4, 6.1.3, 6.0.13, 5.4.16, and 4.5.11.
CVE-2025-31125MEDIUMsob ataque13 jul 2025
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
90RISCO
abrir
GitHub PoC
CVE-2020-35848 impacts Cockpit-CMS v1.7 due to unsafe handling of user inputs in authentication mechanisms, leading to remote code execution. This lab is built for CTF players and bug bounty learners to simulate real-world exploitation workflows including token extraction, password reset, and flag capture.
CVE-2020-3584813 jul 2025
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.
60RISCO
abrir
GitHub PoC
CVE-2025-32023
CVE-2025-32023HIGH13 jul 2025
Redis allows out of bounds writes in hyperloglog commands leading to RCE
41RISCO
abrir
GitHub PoC
JayVillain/Scan-CVE-2025-6058
CVE-2025-6058CRITICAL13 jul 2025
WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload
63RISCO
abrir
GitHub PoC
Proof of Concept for CVE-2025-24813, a Remote Code Execution vulnerability in Apache Tomcat. This PoC exploits unsafe deserialization via crafted session files uploaded through HTTP PUT requests, allowing attackers to execute arbitrary code remotely on vulnerable Tomcat servers.
CVE-2025-24813CRITICALsob ataque12 jul 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC
MacUchegit/Detecting-and-Analyzing-CVE-2024-24919-Exploitation
CVE-2024-24919HIGHsob ataqueransomware12 jul 2025
Information disclosure
100RISCO
abrir
GitHub PoC
WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload
CVE-2025-6058CRITICAL12 jul 2025
WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload
63RISCO
abrir
GitHub PoC
r0otk3r/CVE-2022-1388
CVE-2022-1388CRITICALsob ataqueransomware12 jul 2025
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir
anteriorpágina 135 / 444próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.