Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.432exploits catalogados
34.424CVEs com exploração pública
24.695testados em laboratório
13.618 exploits
GitHub PoC1
CVE-2025-32433 is a vuln of ssh
CVE-2025-32433CRITICALsob ataque28 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
GitHub PoC
Next js middlewareauth Bypass
CVE-2025-29927CRITICAL28 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC6
Proof-of-Concept for CVE-2025-31324: Unauthenticated upload in SAP NetWeaver Visual Composer Metadata Uploader
CVE-2025-31324CRITICALsob ataqueransomware28 abr 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISCO
abrir
GitHub PoC
Updated exploit script for the CVE-2021-43798
CVE-2021-43798HIGHsob ataque27 abr 2025
Grafana path traversal
100RISCO
abrir
GitHub PoC
shun1403/CVE-2017-8291
CVE-2017-8291HIGHsob ataque27 abr 2025
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion
100RISCO
abrir
GitHub PoC
Dowonkwon/drupal-cve-2018-7600-poc
CVE-2018-7600CRITICALsob ataqueransomware27 abr 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC
shun1403/PIL-CVE-2017-8291-study
CVE-2017-8291HIGHsob ataque27 abr 2025
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion
100RISCO
abrir
GitHub PoC
WHS3기 가상화 취약한(CVE) Docker 환경 구성 과제
CVE-2025-1974CRITICAL27 abr 2025
ingress-nginx admission controller RCE escalation
85RISCO
abrir
GitHub PoC
airtiels 5650 CVE-2015-2797 PoC
CVE-2015-279727 abr 2025
Stack-based buffer overflow in AirTies Air 6372, 5760, 5750, 5650TT, 5453, 5444TT, 5443, 5442, 5343, 5342, 5341, and 502
60RISCO
abrir
GitHub PoC12
Onapsis/Onapsis_CVE-2025-31324_Scanner_Tools
CVE-2025-31324CRITICALsob ataqueransomware27 abr 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISCO
abrir
GitHub PoC24
CVE-2025-31324, SAP Exploit
CVE-2025-31324CRITICALsob ataqueransomware27 abr 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISCO
abrir
GitHub PoC
Attacks a vulnerable WordPress site with the wp-automatic plugin. Inserts a new user called eviladmin directly into the database (INSERT INTO wp_users). Searches for the ID of the newly created user (cyclic SELECT). Promotes eviladmin to Administrator (INSERT INTO wp_usermeta).
CVE-2024-27956CRITICAL27 abr 2025
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISCO
abrir
GitHub PoC2
CVE-2022-3552 RCE with detailed exploitation steps
CVE-2022-3552HIGH27 abr 2025
Unrestricted Upload of File with Dangerous Type in boxbilling/boxbilling
53RISCO
abrir
GitHub PoC
CVE-2025-32433 Summary and Attack Overview
CVE-2025-32433CRITICALsob ataque27 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
GitHub PoC27
This repository contains a proof-of-concept exploit script for CVE-2025-32432, a pre-authentication Remote Code Execution (RCE) vulnerability affecting CraftCMS versions 4.x and 5.x. The vulnerability exists in the asset transform generation feature of CraftCMS.
CVE-2025-32432CRITICALsob ataque27 abr 2025
Craft CMS Allows Remote Code Execution
100RISCO
abrir
GitHub PoC1
yeahhbean/Laravel-CVE-2018-15133
CVE-2018-15133HIGHsob ataque27 abr 2025
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISCO
abrir
GitHub PoC
Proof of Concept (PoC) script for CVE-2025-24813, vulnerability in Apache Tomcat.
CVE-2025-24813CRITICALsob ataque27 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC
romanedutov/CVE-2025-2294
CVE-2025-2294CRITICAL26 abr 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISCO
abrir
GitHub PoC1
chhhd/CVE-2025-1974
CVE-2025-1974CRITICAL26 abr 2025
ingress-nginx admission controller RCE escalation
85RISCO
abrir
GitHub PoC10
CraftCMS RCE Checker (CVE-2025-32432)
CVE-2025-32432CRITICALsob ataque26 abr 2025
Craft CMS Allows Remote Code Execution
100RISCO
abrir
GitHub PoC2
CVE-2021-42287/CVE-2021-42278/OTHER Scanner & Exploiter.
CVE-2021-42287HIGHsob ataqueransomware26 abr 2025
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISCO
abrir
GitHub PoC
ChoDeokCheol/CVE-2023-39361
CVE-2023-39361CRITICAL26 abr 2025
Unauthenticated SQL Injection in graph_view.php in Cacti
85RISCO
abrir
GitHub PoC
CyprianAtsyor/CVE-2024-24919-Incident-Report.md
CVE-2024-24919HIGHsob ataqueransomware25 abr 2025
Information disclosure
100RISCO
abrir
GitHub PoC2
Next.js middleware bypass exploit
CVE-2025-29927CRITICAL25 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC4
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
CVE-2025-31324CRITICALsob ataqueransomware25 abr 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISCO
abrir
GitHub PoC
Python Proof of Concept for CVE-2023-1545 (SQL Injection for Teampass versions prior to 3.0.0.23).
CVE-2023-1545HIGH25 abr 2025
SQL Injection in nilsteampassnet/teampass
41RISCO
abrir
GitHub PoC
WonderCMS v3.4.2 NSE Discovery Script
CVE-2023-41425MEDIUM25 abr 2025
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISCO
abrir
GitHub PoC1
Erlang OTP SSH NSE Discovery Script
CVE-2025-32433CRITICALsob ataque25 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
GitHub PoC
K4Der11000/k4_cve-2023-41064
CVE-2023-41064HIGHsob ataque25 abr 2025
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1
76RISCO
abrir
GitHub PoC3
CVE-2025-32433 Erlang/OTP SSH RCE Exploit SSH远程代码执行漏洞EXP
CVE-2025-32433CRITICALsob ataque25 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
anteriorpágina 161 / 454próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.