Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.184exploits catalogados
37.029CVEs com exploração pública
24.695testados em laboratório
15.321 exploits
GitHub PoC1
RestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT
CVE-2025-9209CRITICAL05 nov 2025
RestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT
63RISCO
abrir
GitHub PoC
Billing CTF Machine_CVE-2023-30258_Remote Code Execution
CVE-2023-30258CRITICAL05 nov 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISCO
abrir
GitHub PoC
PoC for CVE-2024-5932.
CVE-2024-5932CRITICAL04 nov 2025
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RISCO
abrir
GitHub PoC10
Breaking down CVE-2025-54253 — an Adobe AEM-Forms exploit path from XXE to full remote code execution and its real-world impact.
CVE-2025-54253CRITICALsob ataque04 nov 2025
Adobe Experience Manager | Incorrect Authorization (CWE-863)
100RISCO
abrir
GitHub PoC8
A vulnerability in fiberhome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-shared key) to be predicted from the SSID
CVE-2025-63353CRITICAL04 nov 2025
A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-s
48RISCO
abrir
GitHub PoC4
CVE-2025-11953 demonstration: Critical RCE vulnerability in React Native CLI (CVSS 9.8). Educational security research with proof-of-concept exploits and mitigation strategies.
CVE-2025-11953CRITICALsob ataque04 nov 2025
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
100RISCO
abrir
GitHub PoC1
XWiki Unauthenticated RCE Exploit for Reverse Shell
CVE-2025-24893CRITICALsob ataque03 nov 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC1
exploit
CVE-2025-32463CRITICALsob ataque03 nov 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC
zimshk/CVE-2025-59528.yaml
CVE-2025-59528CRITICAL02 nov 2025
Flowise has Remote Code Execution vulnerability
85RISCO
abrir
GitHub PoC1
Exploit for CVE-2025-2011
CVE-2025-2011HIGH02 nov 2025
Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection via 's' Parameter
68RISCO
abrir
GitHub PoC1
This is a customized script to help solve the lab on remote code execution under the CVE-2015-3306 lab.
CVE-2015-330602 nov 2025
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISCO
abrir
GitHub PoC1
My view on IngressNightmare vulnerability (CVE-2025-1974)
CVE-2025-1974CRITICAL02 nov 2025
ingress-nginx admission controller RCE escalation
85RISCO
abrir
GitHub PoC1
A Proof of Concept (PoC) exploit for CVE-2015-1328
CVE-2015-132801 nov 2025
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISCO
abrir
GitHub PoC
CVE-2024-9047
CVE-2024-9047CRITICAL01 nov 2025
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
85RISCO
abrir
GitHub PoC
Exploit for CVE-2021-3560 Polkit Local Privilege Escalation Vulnerability
CVE-2021-3560HIGHsob ataque01 nov 2025
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISCO
abrir
GitHub PoC
Unauthorized access to all user names and passwords entered in the Address Book feature found in Kyocera printers.
CVE-2025-63579HIGH31 out 2025
Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The secu
41RISCO
abrir
GitHub PoC1
shiro 路径穿越
CVE-2010-386331 out 2025
Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the
35RISCO
abrir
GitHub PoC
Fast, socket-level scanner for detecting CVE-2022-22536 in SAP ICM or Web Dispatcher instances. Performs request smuggling tests with a crafted MPI-desync payload. Supports batch scanning IP:PORT targets via plain text files.
CVE-2022-22536CRITICALsob ataque31 out 2025
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RISCO
abrir
GitHub PoC1
adrianmafandy/CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware31 out 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC25
Proof-of-concept for CVE-2025-49844
CVE-2025-49844CRITICAL31 out 2025
Redis Lua Use-After-Free may lead to remote code execution
85RISCO
abrir
GitHub PoC
Mahfujurjust/CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware31 out 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
A XXE payload generator
CVE-2021-29447HIGH31 out 2025
WordPress Authenticated XXE attack when installation is running PHP 8
63RISCO
abrir
GitHub PoC
Y2F05p2w/CVE-2025-24893
CVE-2025-24893CRITICALsob ataque31 out 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC1
WooCommerce Designer Pro 1.9.26 - Arbitrary File Upload
CVE-2025-6440CRITICAL30 out 2025
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISCO
abrir
GitHub PoC
Technical examination of CVE-2025-32463 by Muhammed Kaya.
CVE-2025-32463CRITICALsob ataque30 out 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC2
A combined POC for CVE-2021-31955, CVE-2015-4077, and CVE-2015-5736
CVE-2015-407729 out 2025
The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient b
23RISCO
abrir
GitHub PoC
TranDongA3/Simulation_CVE-2024-46256
CVE-2024-46256CRITICAL29 out 2025
A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add
48RISCO
abrir
GitHub PoC2
A combined POC for CVE-2021-31955, CVE-2015-4077, and CVE-2015-5736
CVE-2021-31955MEDIUMsob ataque29 out 2025
Windows Kernel Information Disclosure Vulnerability
85RISCO
abrir
GitHub PoC
Zohaibkhan1472/cve-2023-6019
CVE-2023-6019CRITICAL28 out 2025
Ray Command Injection in cpu_profile Parameter
85RISCO
abrir
GitHub PoC
ict519 assignment
CVE-2023-38831HIGHsob ataqueransomware28 out 2025
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
anteriorpágina 168 / 511próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.