Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

72.041exploits catalogados
32.227CVEs com exploração pública
1.932testados em laboratório
13.352 exploits
GitHub PoC4
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
CVE-2025-31324CRITICALsob ataqueransomware25 abr 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISCO
abrir
GitHub PoC3
CVE-2025-32433 Erlang/OTP SSH RCE Exploit SSH远程代码执行漏洞EXP
CVE-2025-32433CRITICALsob ataque25 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
GitHub PoC1
Erlang OTP SSH NSE Discovery Script
CVE-2025-32433CRITICALsob ataque25 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
GitHub PoC
A PoC of CVE-2018-0114 I made for PentesterLab
CVE-2018-011425 abr 2025
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISCO
abrir
GitHub PoC
K4Der11000/k4_cve-2023-41064
CVE-2023-41064HIGHsob ataque25 abr 2025
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1
76RISCO
abrir
GitHub PoC
Python Proof of Concept for CVE-2023-1545 (SQL Injection for Teampass versions prior to 3.0.0.23).
CVE-2023-1545HIGH25 abr 2025
SQL Injection in nilsteampassnet/teampass
41RISCO
abrir
GitHub PoC
A PoC of CVE-2016-10033 I made for PentesterLab
CVE-2016-10033CRITICALsob ataque25 abr 2025
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir
GitHub PoC2
Next.js middleware bypass exploit
CVE-2025-29927CRITICAL25 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
CyprianAtsyor/CVE-2024-24919-Incident-Report.md
CVE-2024-24919HIGHsob ataqueransomware25 abr 2025
Information disclosure
100RISCO
abrir
GitHub PoC1
tar-fs file write/overwrite vulnerability
CVE-2024-12905HIGH24 abr 2025
An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted
41RISCO
abrir
GitHub PoC3
Analysis of the Reproduction of CVE-2025-30208 Series Vulnerabilities
CVE-2025-30208MEDIUM24 abr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir
GitHub PoC
Commvault CVE-2025-34028 endpoint scanner using Nmap NSE. For ethical testing and configuration validation.
CVE-2025-34028CRITICALsob ataque24 abr 2025
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RISCO
abrir
GitHub PoC
CVE-2025-31161 python exploit
CVE-2025-31161CRITICALsob ataqueransomware24 abr 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISCO
abrir
GitHub PoC1
Official Nuclei template for CVE-2025-31161 (formerly CVE-2025-2825)
CVE-2025-31161CRITICALsob ataqueransomware24 abr 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISCO
abrir
GitHub PoC
Jasurbek-Masimov/CVE-2018-15745
CVE-2018-1574524 abr 2025
Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F
60RISCO
abrir
GitHub PoC
unzip-stream file write/overwrite vulnerability
CVE-2024-42471HIGH24 abr 2025
Arbitrary File Write via artifact extraction in actions/artifact
41RISCO
abrir
GitHub PoC
Optimized exploit for CVE-2021-43857 affecting Gerapy < 0.9.8
CVE-2021-43857CRITICAL24 abr 2025
Gerapy may contain remote code execution vulnerability
60RISCO
abrir
GitHub PoC12
Exploit for CVE-2025-30406
CVE-2025-30406CRITICALsob ataque24 abr 2025
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
100RISCO
abrir
GitHub PoC
CVE lab to accompany CVE course for CVE-2025-32433
CVE-2025-32433CRITICALsob ataque24 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
GitHub PoC3
CVE-2023-25157 exp
CVE-2023-25157CRITICAL24 abr 2025
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RISCO
abrir
GitHub PoC
JIYUN02/cve-2021-41773
CVE-2021-41773HIGHsob ataqueransomware24 abr 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
Hands-on SOC investigation of CVE-2024-49138 using LetsDefend, VirusTotal, Hybrid Analysis, TrueFort, and ChatGPT.
CVE-2024-49138HIGHsob ataque23 abr 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC12
F5-Labs/parquet-canary-exploit-rce-poc-CVE-2025-30065
CVE-2025-30065CRITICAL23 abr 2025
Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
60RISCO
abrir
GitHub PoC2
CVE-2025-29927: Next.js Middleware Bypass Vulnerability
CVE-2025-29927CRITICAL23 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC1
Tool designed to scan a list of websites for a known vulnerability in the PHPUnit framework, specifically the CVE-2017-9841 vulnerability.
CVE-2017-9841CRITICALsob ataque22 abr 2025
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISCO
abrir
GitHub PoC1
Demo for detection and mitigation of HTTP/2 Rapid Reset vulnerability (CVE-2023-44487)
CVE-2023-44487HIGHsob ataque22 abr 2025
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISCO
abrir
GitHub PoC1
inok009/FOXCMS-CVE-2025-29306-POC
CVE-2025-29306CRITICAL22 abr 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISCO
abrir
GitHub PoC20
Proof of Concept for the NTLM Hash Leak via .library-ms CVE-2025-24054 / CVE-2025-24071
CVE-2025-24054MEDIUMsob ataque22 abr 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RISCO
abrir
GitHub PoC
pswalia2u/CVE-2025-24071_POC
CVE-2025-24071MEDIUM21 abr 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
GitHub PoC1
CVE-2025-30208 vite file read nuclei template
CVE-2025-30208MEDIUM21 abr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir
anteriorpágina 154 / 446próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.