Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.444exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
13.618 exploits
GitHub PoC16
CVE-2025-24813利用工具
CVE-2025-24813CRITICALsob ataque16 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC2
One-Click-Root program based on CVE-2016-5195, that works on the old 'PlayStation Certified' android devices
CVE-2016-5195HIGHsob ataque15 mar 2025
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC2
CVE-2024-51788 - WordPress The Novel Design Store Directory plugin <= 4.3.0 - Unauthenticated Arbitrary File Upload Vulnerability
CVE-2024-51788CRITICAL15 mar 2025
WordPress The Novel Design Store Directory plugin <= 4.3.0 - Arbitrary File Upload vulnerability
48RISCO
abrir
GitHub PoC
ishwardeepp/CVE-2025-22604-Cacti-RCE
CVE-2025-22604CRITICAL15 mar 2025
Cacti has Authenticated RCE via multi-line SNMP responses
48RISCO
abrir
GitHub PoC47
一個測試CVE-2024-4577和CVE-2024-8926的安全滲透工具
CVE-2024-4577CRITICALsob ataqueransomware15 mar 2025
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC2
PoC - OpenSSL NPN Buffer Overread
CVE-2024-5535CRITICAL15 mar 2025
SSL_select_next_proto buffer overread
48RISCO
abrir
GitHub PoC
redpack-kr/CVE-2025-26319
CVE-2025-26319CRITICAL14 mar 2025
FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.
75RISCO
abrir
GitHub PoC1
User name enumeration against SSH daemons affected by CVE-2016-6210.
CVE-2016-6210MEDIUM14 mar 2025
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RISCO
abrir
GitHub PoC
Webmin 1.580 /file/show.cgi Remote Code Execution
CVE-2012-298214 mar 2025
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISCO
abrir
GitHub PoC
Pei4AN/CVE-2025-28915
CVE-2025-28915CRITICAL14 mar 2025
WordPress ThemeEgg ToolKit plugin <= 1.2.9 - Arbitrary File Upload vulnerability
48RISCO
abrir
GitHub PoC3
CVE-2025-24813_POC
CVE-2025-24813CRITICALsob ataque14 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC1
Security Researcher
CVE-2025-24813CRITICALsob ataque14 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC196
his repository contains an automated Proof of Concept (PoC) script for exploiting **CVE-2025-24813**, a Remote Code Execution (RCE) vulnerability in Apache Tomcat. The vulnerability allows an attacker to upload a malicious serialized payload to the server, leading to arbitrary code execution via deserialization when specific conditions are met.
CVE-2025-24813CRITICALsob ataque14 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC
DeividasTerechovas/SOC335-CVE-2024-49138-Exploitation-Detected
CVE-2024-49138HIGHsob ataque14 mar 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC11
cve-2025-24813验证脚本
CVE-2025-24813CRITICALsob ataque14 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC98
Apache Tomcat 远程代码执行漏洞批量检测脚本(CVE-2025-24813)
CVE-2025-24813CRITICALsob ataque13 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC1
HUSKY – Products Filter Professional for WooCommerce < 1.3.6.6 - Local File Inclusion PoC
CVE-2025-1661CRITICAL13 mar 2025
HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion
75RISCO
abrir
GitHub PoC43
This lab guides you through setting up an environment to explore CVE-2019-2215, a critical Android kernel vulnerability in the binder subsystem.
CVE-2019-2215HIGHsob ataque13 mar 2025
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISCO
abrir
GitHub PoC
PoC Exploit for CVE-2015-0009 (SMB Signing)
CVE-2015-000912 mar 2025
The Group Policy Security Configuration policy implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, W
23RISCO
abrir
GitHub PoC
CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware12 mar 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC7
tinashelorenzi/CVE-2023-30258-magnus-billing-v7-exploit
CVE-2023-30258CRITICAL12 mar 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISCO
abrir
GitHub PoC1
WordPress ThemeEgg ToolKit plugin <= 1.2.9 - Arbitrary File Upload vulnerability
CVE-2025-28915CRITICAL12 mar 2025
WordPress ThemeEgg ToolKit plugin <= 1.2.9 - Arbitrary File Upload vulnerability
48RISCO
abrir
GitHub PoC1
POC for CVE-2025-26240
CVE-2025-26240HIGH12 mar 2025
In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of t
41RISCO
abrir
GitHub PoC1
MS17-010 (CVE-2017-0143) - Python3 Script
CVE-2017-0143HIGHsob ataqueransomware12 mar 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
GitHub PoC
CVE-2017-11882 Preventer for .docx files
CVE-2017-11882HIGHsob ataqueransomware11 mar 2025
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISCO
abrir
GitHub PoC
In this project, I documented a detailed penetration testing process targeting Apache HTTP Server vulnerabilities, specifically CVE-2021-41773 and CVE-2021-42013, which involve Path Traversal and Remote Code Execution (RCE).
CVE-2021-41773HIGHsob ataqueransomware11 mar 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
CVE-2024-8289 https://www.cve.org/CVERecord?id=CVE-2024-8289, Vendor wcmp Product MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution
CVE-2024-8289CRITICAL11 mar 2025
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.0 - Missing Authorization to Limited Vendor Privilege Escalation/Account Takeover
48RISCO
abrir
GitHub PoC
CVE-2024-54383, https://www.cve.org/CVERecord?id=CVE-2024-54383
CVE-2024-54383CRITICAL11 mar 2025
WordPress WooCommerce - PDF Vouchers plugin < 4.9.9 - Broken Authentication vulnerability
48RISCO
abrir
GitHub PoC
KQL para deteccion de CVE-2025-21333 en Sentinel
CVE-2025-21333HIGHsob ataque11 mar 2025
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RISCO
abrir
GitHub PoC
Remote code execution running on w3 total cache cve 2013-2010
CVE-2013-201011 mar 2025
WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability
60RISCO
abrir
anteriorpágina 174 / 454próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.