Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.184exploits catalogados
37.029CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.521GitHub PoC 15.321VulnCheck XDB 8.970Nuclei 4.394Metasploit 3.502✓ só verificadosrecentespopularesrisco
15.321 exploits
GitHub PoC★ 4
Academic proof-of-concept demonstrating CVE-2025-14847 for authorized security research.
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir ↗GitHub PoC
Reproducible Docker lab for CVE-2018-15133 (Laravel Framework token unserialize RCE)
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISCO
abrir ↗GitHub PoC
cv-sai-kamesh/n8n-CVE-2025-68613
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISCO
abrir ↗GitHub PoC★ 2
AntonieSoga/Erlang-OTP-PoC_CVE-2025-32433
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir ↗GitHub PoC★ 13
Exploit lab, docker and code scanner for mongobleed Vulnerability CVE-2025-14847 plus Phoenix Security Sync tools
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir ↗GitHub PoC
Detect exposed MongoDB instances and CVE-2025-14847 "MongoBleed" risks — Zero-Trust Python scanner
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir ↗GitHub PoC
amirali-ramezani/react2shell-CVE-2025-55182-
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗GitHub PoC
CVE-2025-14611 CentreStack and Triofox full Poc/Exploit
Gladinet CentreStack and TrioFox Hard Coded AES Keys
98RISCO
abrir ↗GitHub PoC★ 1
aexdyhaxor/CVE-2025-32463
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗GitHub PoC
bodoinon/CVE-2024-10924
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir ↗GitHub PoC
hariskhalil555000-sketch/What-utility-does-CVE-2024-3094-refer-to-
Xz: malicious code in distributed source
70RISCO
abrir ↗GitHub PoC
The script focuses on safe artifact acquisition first, followed by optional on-host analysis, and produces a portable, hashed forensic archive suitable for offline investigation on a forensic workstation.
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir ↗GitHub PoC
n8n CVE-2025-68613
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISCO
abrir ↗GitHub PoC★ 3
Explot, Lab, Scanner - external and docker container, for SMongobleed-CVE-2025-14847 plus phoenix security uploader
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir ↗GitHub PoC★ 2
Proof of Concept for CVE-2025-24893 demonstrating unauthenticated remote command execution in XWiki through unsafe server-side template evaluation.
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir ↗GitHub PoC
CVE-2025-20393
Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability
83RISCO
abrir ↗GitHub PoC★ 3
A testing framework to identify and demonstrate deserialization vulnerabilities in LangChain Core (<0.3.81). Educational use only
LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
60RISCO
abrir ↗GitHub PoC
This is a standalone Python implementation for CVE-2024-46506. I created this script because I could only find the Metasploit module and needed a lightweight, portable version that doesn't require the full Metasploit Framework.
NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because fun
75RISCO
abrir ↗GitHub PoC
webmin/usermin 2.100
A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid
48RISCO
abrir ↗GitHub PoC★ 3
PoC para determinar si Fortinet es vulnerable a CVE-2025-59718 / CVE-2025-59719
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0
90RISCO
abrir ↗GitHub PoC★ 36
MongoDB CVE-2025-14847 Heap Memory Leak Scanner | OP_COMPRESSED zlib Vulnerability | Bug Bounty & Red Team Tool
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir ↗GitHub PoC
saereya/CVE-2025-14847---MongoBleed
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir ↗GitHub PoC★ 2
golang test tool for mongobleed (cve-2025-14847)
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir ↗GitHub PoC★ 1
flame-11/CVE-2018-9206-jquery-file-upload
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISCO
abrir ↗GitHub PoC★ 1
PoC For CVE-2024-30167 (Atlona OME Authenticated Command Injection)
/cgi-bin/time.cgi in Atlona AT-OME-MS42 Matrix Switcher 1.1.2 allow remote authenticated users to execute arbitrary comm
33RISCO
abrir ↗GitHub PoC
KingHacker353/CVE-2025-14847_Expolit
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir ↗GitHub PoC★ 31
a critical memory disclosure vulnerability in MongoDB's zlib compression handling. This tool allows security researchers to extract sensitive data from vulnerable MongoDB instances.
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir ↗GitHub PoC★ 1
CVE-2023-5360 PoC: Unauthenticated arbitrary file upload leading to RCE in Royal Elementor Addons (≤ 1.3.78), written in pure Python.
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RISCO
abrir ↗GitHub PoC
KingHacker353/R2C-CVE-2025-55182-66478
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗GitHub PoC★ 1
Mass Bot Exploit
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.