Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.095exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
15.312 exploits
GitHub PoC
beginner friendly write-up for the TryHackMe easy level module- polkit:CVE-2021-3560
CVE-2021-3560HIGHsob ataque14 jan 2026
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISCO
abrir
GitHub PoC
**Log4Shell PoC is a high-fidelity exploitation environment designed to replicate the CVE-2021-44228 vulnerability.** It provides a containerized sandbox to demonstrate JNDI injection, LDAP/RMI referral redirection, and remote code execution (RCE) via the Log4j 2 library.
CVE-2021-44228CRITICALsob ataqueransomware14 jan 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Asset-wide detection tool for identifying jsPDF usage related to CVE-2025-68428 Detection only — no exploitation
CVE-2025-68428CRITICAL14 jan 2026
jsPDF has Local File Inclusion/Path Traversal vulnerability
48RISCO
abrir
GitHub PoC
🔍 Scan for MongoDB vulnerabilities with MongoBleed, a high-performance tool for detecting CVE-2025-14847 across large networks quickly and efficiently.
CVE-2025-14847HIGHsob ataque14 jan 2026
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir
GitHub PoC
🛡️ Detect vulnerable MongoDB instances with the high-performance MongoBleed scanner for CVE-2025-14847, ensuring network security and data protection.
CVE-2025-14847HIGHsob ataque14 jan 2026
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir
GitHub PoC
encikayelwhitehat-glitch/CVE-2024-3094
CVE-2024-3094CRITICAL14 jan 2026
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC
CVE-2025-64459-hunter
CVE-2025-64459CRITICAL14 jan 2026
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RISCO
abrir
GitHub PoC
A comprehensive Security Operations Centre (SOC) incident response simulation demonstrating threat detection, triage, analysis, and mitigation of the Spring4Shell vulnerability (CVE-2022-22965).
CVE-2022-22965CRITICALsob ataque14 jan 2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC
Implementation of the CVE-2023-22809
CVE-2023-22809HIGH14 jan 2026
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISCO
abrir
GitHub PoC
Remote code execution for React Server Components 19.0.0 - 19.2.0
CVE-2025-55182CRITICALsob ataqueransomware13 jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Unauthenticated file upload for Chamilo 1.11.24 and lower
CVE-2023-4220HIGH13 jan 2026
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir
GitHub PoC1
Local Priviledge Escalation for Druva
CVE-2020-575213 jan 2026
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitra
38RISCO
abrir
GitHub PoC
POC for the CVE-2025-32462 and CVE-2025-32463 vulnerabilities
CVE-2025-32462LOW13 jan 2026
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RISCO
abrir
GitHub PoC100
Analysis of CVE-2025-43529 (WebKit UAF) + CVE-2025-14174 (ANGLE OOB) exploit chain - iOS Safari
CVE-2025-43529HIGHsob ataque13 jan 2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
71RISCO
abrir
GitHub PoC
0x13-ByteZer0/CVE-2024-21762
CVE-2024-21762CRITICALsob ataqueransomware13 jan 2026
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISCO
abrir
GitHub PoC10
A simple PoC demonstrating the vulnerability in the ThrottleStop.sys driver, showcasing arbitrary physical memory read and write capabilities, as well as virtual-to-physical address translation using Superfetch.
CVE-2025-7771HIGH13 jan 2026
Code Execution / Escalation of Privileges in ThrottleStop
41RISCO
abrir
GitHub PoC2
alexcyberx/CVE-2025-14847_Expolit
CVE-2025-14847HIGHsob ataque13 jan 2026
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir
GitHub PoC
posix sh poc for CVE-2009-2265 (deps: curl,msfvenom,uuidgen,tr)
CVE-2009-226512 jan 2026
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RISCO
abrir
GitHub PoC2
CVE-2025-14847 | MongoBleed vulnerability proof of concept project
CVE-2025-14847HIGHsob ataque12 jan 2026
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir
GitHub PoC3
CVE-2025-52694 Critical SQL Injection in Advantech IoTSuite/SaaS-Composer
CVE-2025-52694CRITICAL12 jan 2026
Execution of arbitrary SQL commands
75RISCO
abrir
GitHub PoC1
CVE-2026-22241 Exploit for GUnet Open eClass Unrestricted File Upload Leads to Remote Code Execution (RCE)
CVE-2026-22241HIGH12 jan 2026
Open eClass has Unrestricted File Upload that Leads to Remote Code Execution (RCE)
41RISCO
abrir
GitHub PoC3
Proof-of-Concept 0day for SAP NetWeaver created by ShinyHunters
CVE-2025-31324CRITICALsob ataqueransomware12 jan 2026
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISCO
abrir
GitHub PoC
Mr-In4inci3le/CVE-2025-11953-POC-
CVE-2025-11953CRITICALsob ataque12 jan 2026
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
100RISCO
abrir
GitHub PoC
An exploit for CVE-2015-1538-1 - Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution
CVE-2015-153812 jan 2026
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RISCO
abrir
GitHub PoC
React2Shell is a high-performance vulnerability scanner written in Go, specifically designed to detect Server-Side Remote Code Execution (RCE) vulnerabilities in Next.js applications (CVE-2025-55182 & CVE-2025-66478).
CVE-2025-55182CRITICALsob ataqueransomware12 jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Technical analysis and reproduction lab for the Apache HTTP Server 2.4.49 Path Traversal and RCE vulnerability.
CVE-2021-41773HIGHsob ataqueransomware12 jan 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC2
CVE-2025-55182漏洞检测工具
CVE-2025-55182CRITICALsob ataqueransomware11 jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
js2py <= 0.74 sandbox escape (CVE-2024-28397)
CVE-2024-28397MEDIUM11 jan 2026
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISCO
abrir
GitHub PoC3
rimbadirgantara/CVE-2025-52691-poc
CVE-2025-52691CRITICALsob ataqueransomware11 jan 2026
Upload Arbitrary Files
100RISCO
abrir
GitHub PoC
sahar042/CVE-2025-14847
CVE-2025-14847HIGHsob ataque11 jan 2026
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir
anteriorpágina 139 / 511próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.