Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.432exploits catalogados
34.424CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.493GitHub PoC 13.618VulnCheck XDB 8.198Nuclei 4.217Metasploit 3.463✓ só verificadosrecentespopularesrisco
13.618 exploits
GitHub PoC★ 8
NULLTRACE0X/CVE-2025-31324
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISCO
abrir ↗GitHub PoC★ 1
1Altruist/CVE-2025-46271-Reverse-Shell-PoC
Planet Technology Network Products OS Command Injection
48RISCO
abrir ↗GitHub PoC
Vite WASM Import Path Traversal 🛡️
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
90RISCO
abrir ↗GitHub PoC
abrewer251/CVE-2024-38475_SonicBoom_Apache_URL_Traversal_PoC
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
100RISCO
abrir ↗GitHub PoC★ 1
Commvault Remote Code Execution (CVE-2025-34028) NSE
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RISCO
abrir ↗GitHub PoC★ 2
Proof-of-Concept (PoC) for CVE-2025-34028, a Remote Code Execution vulnerability in Commvault Command Center. This Python script scans single or multiple targets, executes commands, and reports vulnerable hosts.
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RISCO
abrir ↗GitHub PoC★ 1
PoC for CVE-2025-2011 - SQLi in Depicter plugin <= 3.6.1
Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection via 's' Parameter
68RISCO
abrir ↗GitHub PoC
abrewer251/CVE-2025-1974_IngressNightmare_PoC
ingress-nginx admission controller RCE escalation
85RISCO
abrir ↗GitHub PoC★ 1
Next.js Auth Bypass PoC Edge Runtime Env Leak via Middleware Bug
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 5
Research Purposes only
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISCO
abrir ↗GitHub PoC
Hirainsingadia/CVE-2002-2154
Directory traversal vulnerability in Monkey HTTP Daemon 0.1.4 allows remote attackers to read arbitrary files via .. (do
23RISCO
abrir ↗GitHub PoC
NGINX DNS Overflow Vulnerability Check - CVE-2021-23017 PoC
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t
35RISCO
abrir ↗GitHub PoC★ 1
ductink98lhp/analyze-Exploit-CVE-2023-22518-Confluence
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authoriz
100RISCO
abrir ↗GitHub PoC★ 1
Scanner and exploit for CVE-2025-3248
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir ↗GitHub PoC★ 1
CVE-2025-4524 - Unauthenticated madara-core Wordpress theme LFI
Madara – Responsive and modern WordPress theme for manga sites <= 2.2.2 - Unauthenticated Local File Inclusion
63RISCO
abrir ↗GitHub PoC★ 2
Artemir7/CVE-2025-24893-EXP
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir ↗GitHub PoC★ 5
This Python exploit script targets a vulnerable Laravel Filemanager created by UniSharp, which allows authenticated users to bypass file restrictions and upload malicious files. This can lead to Remote Code Execution (RCE) when the uploaded payload is triggered.
Versions of the package unisharp/laravel-filemanager before 2.9.1 are vulnerable to Remote Code Execution (RCE) through
48RISCO
abrir ↗GitHub PoC
Shellshock Vulnerability Scanner
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗GitHub PoC
CCIEVoice2009/CVE-2023-46604
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISCO
abrir ↗GitHub PoC
Bridg3Ops/SOC335-CVE-2024-49138-Exploitation-Detected
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir ↗GitHub PoC
This CVE - PoC about information on the CVEs I found.
Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.
33RISCO
abrir ↗GitHub PoC
CVE-2024-10914 Shell Exploit
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir ↗GitHub PoC★ 3
This repository includes everything needed to run a PoC exploit for CVE-2025-32375 in a Docker environment. It runs the latest vulnerable version of BentoML (1.4.7).
Insecure Deserialization leads to RCE in BentoML's runner server
75RISCO
abrir ↗GitHub PoC
A critical flaw has been discovered in Erlang/OTP's SSH server allows unauthenticated attackers to gain remote code execution. One malformed SSH handshake bypasses authentication and exploits improper handling of SSH protocol messages.
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir ↗GitHub PoC
Vite Development Server's @fs endpoint (CVE-2025-31125) to access sensitive files like /etc/passwd and /etc/hosts via crafted URLs.
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
90RISCO
abrir ↗GitHub PoC★ 1
olimpiofreitas/CVE-2025-29927-scanner
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 1
ByteMe1001/CVE-2020-13151-POC-Aerospike-Server-Host-Command-Execution-RCE-
Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs)
60RISCO
abrir ↗GitHub PoC
toothbrushsoapflannelbiscuits/cve-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir ↗GitHub PoC★ 1
CVE-2025-32433 – Erlang/OTP SSH vulnerability allowing pre-auth RCE
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir ↗GitHub PoC
Simple PoC of wpstorecart before 2.5.30 plugin exploit (CVE-2012-3576) written in bash.
Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows re
28RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.