Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

72.018exploits catalogados
32.219CVEs com exploração pública
1.932testados em laboratório
13.334 exploits
GitHub PoC6
Proof-of-concept to CVE-2025-49113
CVE-2025-49113CRITICALsob ataque10 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
GitHub PoC
CVE-2025-24071
CVE-2025-24071MEDIUM10 jun 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
GitHub PoC1
CVE-2024-10914 is a critical command injection vulnerability affecting several legacy D-Link Network Attached Storage (NAS) devices.
CVE-2024-10914CRITICAL09 jun 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir
GitHub PoC
CVE-2025-32756: NSE Scanning for RCE in vulnerable FortiVoice, FortiMail, FortiNDR, FortiRecorder and FortiCamera nodes
CVE-2025-32756CRITICALsob ataque09 jun 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RISCO
abrir
GitHub PoC
PoC malware that uses exploit CVE-2021-36934 (improper ACLs on shadow copies) using a fileless red team method on Windows 10/11 with LOLBins, extracting SYSTEM and SAM hives for local NTLM hashes.
CVE-2021-36934HIGHsob ataque09 jun 2025
Windows Elevation of Privilege Vulnerability
98RISCO
abrir
GitHub PoC2
This script exploits CVE-2025-49619 in Skyvern to execute a reverse shell command.
CVE-2025-49619HIGH09 jun 2025
Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks suc
61RISCO
abrir
GitHub PoC
alm6no5/CVE-2025-32756-POC
CVE-2025-32756CRITICALsob ataque09 jun 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RISCO
abrir
GitHub PoC3
Security Vulnerability Report: CVE-2025-24071 - Windows File Explorer Spoofing Vulnerability
CVE-2025-24071MEDIUM09 jun 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
GitHub PoC
Arshit01/CVE-2023-20198
CVE-2023-20198CRITICALsob ataque09 jun 2025
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISCO
abrir
GitHub PoC1
CVE-2025-29927 - Critical Security Vulnerability in Next.js
CVE-2025-29972CRITICAL09 jun 2025
Azure Storage Resource Provider Spoofing Vulnerability
48RISCO
abrir
GitHub PoC
Atlassian's Confluence Server and Data Center editions (Vulnerable Version > 7.18.1)
CVE-2022-26134CRITICALsob ataqueransomware09 jun 2025
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC
CVE-2021-3156-Exploit-Demo
CVE-2021-3156HIGHsob ataque09 jun 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC
CVE-2025-0282
CVE-2025-0282CRITICALsob ataqueransomware08 jun 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RISCO
abrir
GitHub PoC
CVE-2024-40453 - Squirrelly v9.0.0 RCE. Poc
CVE-2024-40453CRITICAL08 jun 2025
squirrellyjs squirrelly v9.0.0 and fixed in v.9.0.1 was discovered to contain a code injection vulnerability via the com
48RISCO
abrir
GitHub PoC
CyberBibs/SOC274---Palo-Alto-Networks-PAN-OS-Command-Injection-Vulnerability-Exploitation-CVE-2024-3400-
CVE-2024-3400CRITICALsob ataqueransomware08 jun 2025
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISCO
abrir
GitHub PoC
CyberBibs/Event-ID-263-Arbitrary-File-Read-on-Checkpoint-Security-Gateway-CVE-2024-24919-
CVE-2024-24919HIGHsob ataqueransomware08 jun 2025
Information disclosure
100RISCO
abrir
GitHub PoC1
CVE-2017-5638 Exploit Rewritten In Python By haxerr9
CVE-2017-5638CRITICALsob ataqueransomware07 jun 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC
CVE-2025-31161
CVE-2025-31161CRITICALsob ataqueransomware07 jun 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISCO
abrir
GitHub PoC
CVE-2025-31131
CVE-2025-31131HIGH07 jun 2025
Path Traversal allowing arbitrary read of files in Yeswiki
56RISCO
abrir
GitHub PoC
CVE-2024-51482 ZoneMinder v1.37.* <= 1.37.64 poc
CVE-2024-51482CRITICAL07 jun 2025
Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64
75RISCO
abrir
GitHub PoC90
Proof of Concept demonstrating Remote Code Execution through insecure deserialization in Roundcube (CVE-2025-49113).
CVE-2025-49113CRITICALsob ataque06 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
GitHub PoC
This is a little Python script to detect the "EvilSun" vulnerability (CVE-2020-14871) on Solaris systems. The vulnerability is a buffer overflow in the Pluggable Authentication Module (PAM) `pam_unix_auth` when handling keyboard-interactive authentication in SSH.
CVE-2020-14871CRITICALsob ataque06 jun 2025
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported ve
100RISCO
abrir
GitHub PoC18
mbanyamer/CVE-2025-24076
CVE-2025-24076HIGH06 jun 2025
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC
POC
CVE-2025-30208MEDIUM06 jun 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir
GitHub PoC2
CVE-2025-49113 exploit
CVE-2025-49113CRITICALsob ataque06 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
GitHub PoC
🚨 Exploit CVE-2025-55182 to demonstrate RCE in React Server Functions, highlighting risks from insecure prototype references in Next.js applications.
CVE-2025-55182CRITICALsob ataqueransomware06 jun 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
PoC for CVE-2024-42049
CVE-2024-42049CRITICAL05 jun 2025
TightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pipe via a network connection.
48RISCO
abrir
GitHub PoC1
CyberQuestor-infosec/CVE-2022-46604-Responsive-File-Manager
CVE-2022-46604HIGH05 jun 2025
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanis
41RISCO
abrir
GitHub PoC1
Repositorio de investigación de seguridad que contiene una Prueba de Concepto (PoC) para la vulnerabilidad CVE-2021-4034 (PwnKit) y utilidades de scripting para la demostración de escalada de privilegios y ejecución remota en entornos Linux.
CVE-2021-4034HIGHsob ataque05 jun 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC3
rasool13x/exploit-CVE-2025-49113
CVE-2025-49113CRITICALsob ataque05 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
anteriorpágina 145 / 445próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.