Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.432exploits catalogados
34.424CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.493GitHub PoC 13.618VulnCheck XDB 8.198Nuclei 4.217Metasploit 3.463✓ só verificadosrecentespopularesrisco
13.618 exploits
GitHub PoC★ 9
WordPress Front End Users Plugin <= 3.2.32 is vulnerable to Arbitrary File Upload
Front-End-Only-Users <= 3.2.32 - Unauthenticated Arbitrary File Upload
53RISCO
abrir ↗GitHub PoC★ 2
Detection of malicious VHD files for CVE-2025-24985
Windows Fast FAT File System Driver Remote Code Execution Vulnerability
71RISCO
abrir ↗GitHub PoC
DeividasTerechovas/SOC227-Microsoft-SharePoint-Server-Elevation-of-Privilege-Possible-CVE-2023-29357-Exploitation
Microsoft SharePoint Server Elevation of Privilege Vulnerability
100RISCO
abrir ↗GitHub PoC★ 6
Vite 任意文件读取漏洞POC
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
90RISCO
abrir ↗GitHub PoC
congdong007/CVE-2024-50623-poc
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file up
100RISCO
abrir ↗GitHub PoC★ 1
SAPGateBreaker is a PoC exploit for CVE-2022-22536, a critical HTTP Request Smuggling vulnerability in SAP NetWeaver. It demonstrates how to bypass ACLs by desynchronizing request parsing between ICM and backend services using crafted Content-Length-based payloads.
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RISCO
abrir ↗GitHub PoC
Authorization Bypass in Next.js Middleware
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 1
Next.js Middleware Bypass Vulnerability
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC
Next.js CVE-2025-29927 güvenlik açığı hakkında
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC★ 5
Documentation and PoC for CVE-2023-21554 MSMQ Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
85RISCO
abrir ↗GitHub PoC
Unauthenticated SQL injection exploit for CVE-2019-9053 in CMS Made Simple <= 2.2.9. Extracts admin creds with time-based SQLi.
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir ↗GitHub PoC
Script to make changes on registry to fix CVE-2013-3900. It comes with an option to undo in case it breaks something on your environment.
WinVerifyTrust Signature Validation Vulnerability
75RISCO
abrir ↗GitHub PoC★ 7
针对CVE-2025-30208和CVE-2025-31125的漏洞利用
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗GitHub PoC
B1gN0Se/Tomcat-CVE-2025-24813
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗GitHub PoC
mrrivaldo/CVE-2025-2294
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISCO
abrir ↗GitHub PoC
backdoor.mirai.helloworld cve2018-20561, cve-2018-10562 해킹
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RISCO
abrir ↗GitHub PoC★ 13
Unauthenticated RCE exploit for CVE-2024-25600 in WordPress Bricks Builder <= 1.9.6. Executes arbitrary code remotely.
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir ↗GitHub PoC★ 9
IngressNightmare-PoC: (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, CVE-2025-1974) PoC ,One-click script 。 一键脚本
ingress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
68RISCO
abrir ↗GitHub PoC
Next.js Auth Bypass Lab ‐ CVE-2025-29927
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC
cyberdesu/Elastix-2.2.0-CVE-2012-4869
The callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attacke
60RISCO
abrir ↗GitHub PoC★ 1
This repository contains a shell script based POC on Apache Tomcat CVE-2025-24813. It allow you to easily test the vulnerability on any version of Apache Tomcat
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗GitHub PoC
cve-2022-26134 atlassia Confluence Data Center2016 server OGNL %[...}
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir ↗GitHub PoC
CVE-2009-1151, phpMyAdmin의 set.up
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remo
100RISCO
abrir ↗GitHub PoC★ 1
Sets up a local Tapo C200 using CVE-2021-4045
TP-LINK Tapo C200 remote code execution vulnerability
70RISCO
abrir ↗GitHub PoC
thunww/CVE-2024-50379
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RISCO
abrir ↗GitHub PoC★ 1
A script that exploits SaltStack CVE-2020-11651 and CVE-2020-11652 to add new users to a vulnerable Salt master by injecting entries into /etc/passwd and /etc/shadow. POC
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISCO
abrir ↗GitHub PoC★ 1
Kamal-418/Vulnerable-Lab-NextJS-CVE-2025-29927
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC
Sornphut/CVE-2023-7028-GitLab
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.