Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.432exploits catalogados
34.424CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.493GitHub PoC 13.618VulnCheck XDB 8.198Nuclei 4.217Metasploit 3.463✓ só verificadosrecentespopularesrisco
13.618 exploits
GitHub PoC★ 1
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISCO
abrir ↗GitHub PoC
MandipJoshi/CVE-2021-3560
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISCO
abrir ↗GitHub PoC★ 2
CVE-2025-3248: A critical flaw has been discovered in Langflow that allows malicious actors to execute arbitrary Python code on the target system. This can lead to full remote code execution without authentication, potentially giving attackers control over the server.
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir ↗GitHub PoC★ 1
eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Deletion
eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Deletion
48RISCO
abrir ↗GitHub PoC
laishouchao/Apache-RocketMQ-RCE-CVE-2023-37582-poc
Apache RocketMQ: Possible remote code execution when using the update configuration function
85RISCO
abrir ↗GitHub PoC★ 3
rebelle3/cve-2017-7117
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud befor
28RISCO
abrir ↗GitHub PoC
shishirpandey18/CVE-2021-3156
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir ↗GitHub PoC★ 55
WHW0x455/CVE-2023-41992
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macO
71RISCO
abrir ↗GitHub PoC★ 1
PolarisXSec/CVE-2024-21413
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC★ 1
fatkz/CVE-2025-24813
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗GitHub PoC★ 1
Windows & linux support
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir ↗GitHub PoC
CVE-2025-0411 7-Zip Mark-of-the-Web Bypass
7-Zip Mark-of-the-Web Bypass Vulnerability
83RISCO
abrir ↗GitHub PoC
SAP NetWeaver Visual Composer Metadata Uploader <= 7.50 CVE-2025-31324 PoC
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISCO
abrir ↗GitHub PoC★ 2
WordPress PDF 2 Post Plugin <= 2.4.0 is vulnerable to Remote Code Execution (RCE) +Subscriber
WordPress PDF 2 Post Plugin <= 2.4.0 - Remote Code Execution (RCE) vulnerability
53RISCO
abrir ↗GitHub PoC
Remote Code Execution (RCE) vulnerability in Apache Tomcat.
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗GitHub PoC★ 3
Drag and Drop Multiple File Upload for WooCommerce <= 1.1.6 - Unauthenticated Arbitrary File Upload via upload Function
Drag and Drop Multiple File Upload for WooCommerce <= 1.1.6 - Unauthenticated Arbitrary File Upload via upload Function
48RISCO
abrir ↗GitHub PoC
PoC for CVE-2017-5487 - WordPress User Enumeration via REST
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RISCO
abrir ↗GitHub PoC
congdong007/CVE-2025-29306_poc
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISCO
abrir ↗GitHub PoC★ 1
Apache CXF SSRF CVE-2024-28752
Apache CXF SSRF Vulnerability using the Aegis databinding
63RISCO
abrir ↗GitHub PoC
This is an exercise built around CVE-2021-3560
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISCO
abrir ↗GitHub PoC★ 8
exploit for CVE-2025-27533, a Denial of Service (DoS) vulnerability in Apache ActiveMQ
Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation
33RISCO
abrir ↗GitHub PoC
CVE-2024-38475 Scanner using FFUF + Seclists
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
100RISCO
abrir ↗GitHub PoC★ 2
WordPress Frontend Login and Registration Blocks Plugin <= 1.0.7 is vulnerable to Privilege Escalation
Frontend Login and Registration Blocks <= 1.1.1 - Unauthenticated Privilege Escalation via Account Takeover
63RISCO
abrir ↗GitHub PoC
Tools for scan CVE-2024-25600 - WordPress Bricks Builder Remote Code Execution (RCE)
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir ↗GitHub PoC
The Web Is Vulnerable to CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗GitHub PoC★ 1
sap-netweaver-cve-2025-31324-check
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISCO
abrir ↗GitHub PoC
x-middleware exploit for next.js CVE-2023–46298 cache poisoning and CVE-2025-29927 bypass
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 2
exploiting CVE-2025-27007, a critical unauthenticated privilege escalation vulnerability in the OttoKit (formerly SureTriggers) WordPress plugin
WordPress SureTriggers <= 1.0.82 - Privilege Escalation Vulnerability
75RISCO
abrir ↗GitHub PoC★ 1
1Altruist/CVE-2025-46271-Reverse-Shell-PoC
Planet Technology Network Products OS Command Injection
48RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.