Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.324exploits catalogados
37.130CVEs com exploração pública
24.695testados em laboratório
15.330 exploits
GitHub PoC
CVE-2025-57174 Unauthenticated Remote Command Execution
CVE-2025-57174CRITICAL24 set 2025
An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and p
48RISCO
abrir
GitHub PoC
Demonstration on exploitation on Drupal 7.57 (CVE-2018-7600) with and without WAF(Web Application Firewall)
CVE-2018-7600CRITICALsob ataqueransomware24 set 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC2
the task from C*****k
CVE-2025-32433CRITICALsob ataque24 set 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
GitHub PoC
CVE-2025-57176 - Siklu EtherHaul Series - Unauthenticated Arbitrary File Upload
CVE-2025-57176MEDIUM24 set 2025
On Ceragon Networks / Siklu Communication EtherHaul and MultiHaul Series microwave antennas before 2026-03-10, the rfpip
33RISCO
abrir
GitHub PoC
Proof of Concept for CVE-2024-32002: Git submodule path injection vulnerability.
CVE-2024-32002CRITICAL24 set 2025
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISCO
abrir
GitHub PoC2
An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter.
CVE-2025-56819CRITICAL24 set 2025
An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter.
63RISCO
abrir
GitHub PoC
iteride/CVE-2025-2294
CVE-2025-2294CRITICAL24 set 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISCO
abrir
GitHub PoC
This repository contains a Proof of Concept (PoC) for CVE-2025-32463, a vulnerability in sudo allowing a chroot escape to achieve local privilege escalation.
CVE-2025-32463CRITICALsob ataque24 set 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC
Proof-of-concept script for CVE-2020-3452 — Cisco ASA/FTD Path Traversal vulnerability. Supports automated extraction of known file targets with a hard limit on successful downloads for safety. Intended for authorized security testing and research purposes only.
CVE-2020-3452HIGHsob ataque23 set 2025
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
GitHub PoC
dadosneurais/cve-2023-3824
CVE-2023-3824CRITICAL23 set 2025
Buffer overflow and overread in phar_dir_read()
53RISCO
abrir
GitHub PoC2
Detection for CVE-2025-26399
CVE-2025-26399CRITICALsob ataqueransomware23 set 2025
SolarWinds Web Help Desk Deserialization of Untrusted Data Privilege Escalation Vulnerability
100RISCO
abrir
GitHub PoC
iteride/CVE-2025-1974
CVE-2025-1974CRITICAL23 set 2025
ingress-nginx admission controller RCE escalation
85RISCO
abrir
GitHub PoC
yass2400012/Email-exploit-Moniker-Link-CVE-2024-21413-
CVE-2024-21413CRITICALsob ataque23 set 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC1
CVE-2025-29927
CVE-2025-29927CRITICAL23 set 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC2
AI修复生成的CVE-2025-32432的poc
CVE-2025-32432CRITICALsob ataque23 set 2025
Craft CMS Allows Remote Code Execution
100RISCO
abrir
GitHub PoC
Next.js middleware auth-bypass lab (CVE-2025-29927 simulation)
CVE-2025-29927CRITICAL23 set 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
Michaael01/LetsDefend--SOC-342-CVE-2025-53770-SharePoint-Exploit-ToolShell
CVE-2025-53770CRITICALsob ataqueransomware23 set 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC1
Playing with CVE-2010-2883
CVE-2010-2883HIGHsob ataque22 set 2025
Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows
100RISCO
abrir
GitHub PoC10
Take first steps in CodeQL for Python by writing a query to find CVE-2024-32022
CVE-2024-32022CRITICAL22 set 2025
Kohya_ss is vulnerable to a command injection in basic_caption_gui.py (GHSL-2024-019)
48RISCO
abrir
GitHub PoC1
PoC and exploit scripts for CVE-2023-20048 - Remote Code Execution vulnerability affecting Cisco RV series routers. Includes a vulnerability checker (PoC) and a working exploit for gaining remote shell access. For educational and research purposes only.
CVE-2023-20048CRITICAL22 set 2025
A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authent
53RISCO
abrir
GitHub PoC1
Complete analysis of CVE-2025-21298, a double free vulnerability related to ole32 library in windows.
CVE-2025-21298CRITICAL22 set 2025
Windows OLE Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC
ay 09 — CVE-2025-27520 (BentoML-style insecure deserialization) — Local Docker lab
CVE-2025-27520CRITICAL22 set 2025
BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
75RISCO
abrir
GitHub PoC1
Summar Employee Portal Prior to 3.98.0 Authenticated SQL Injection - CVE-2025-40677
CVE-2025-40677HIGH22 set 2025
SQL injection vulnerability in Summar Software´s Portal del Empleado
41RISCO
abrir
GitHub PoC
CVE-2018-13379 - Fortinet SSL VPN Vulnerability
CVE-2018-13379CRITICALsob ataqueransomware21 set 2025
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISCO
abrir
GitHub PoC1
iteride/CVE-2025-29927
CVE-2025-29927CRITICAL21 set 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC2
CVE-2020-0796 (SMBGhost) is a critical RCE vulnerability in Windows 10 SMBv3 protocol. It allows attackers to execute code remotely via crafted SMB packets, making it wormable. Affects Windows 10 v1903/v1909 and Server 2019. Exploit targets srv2.sys via buffer overflow
CVE-2020-0796CRITICALsob ataqueransomware21 set 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC2
Shenzhen Aitemi M300 Wi-Fi Repeater Unauthenticated RCE (CVE-2025-34152)
CVE-2025-34152CRITICAL21 set 2025
Shenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via Time Parameter
75RISCO
abrir
GitHub PoC
A Rust implementation of the CVE-2018-7600 exploit targeting vulnerable Drupal 7 installations (<= 7.57)
CVE-2018-7600CRITICALsob ataqueransomware21 set 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC1
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
CVE-2025-10035CRITICALsob ataqueransomware21 set 2025
Deserialization Vulnerability in GoAnywhere MFT's License Servlet
100RISCO
abrir
GitHub PoC1
A working (at least for me :] ) exploit for CVE-2025-25257
CVE-2025-25257CRITICALsob ataque21 set 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISCO
abrir
anteriorpágina 174 / 511próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.