Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.324exploits catalogados
37.130CVEs com exploração pública
24.695testados em laboratório
15.330 exploits
GitHub PoC
tranphuc2005/CVE-2017-9822
CVE-2017-9822HIGHsob ataqueransomware15 set 2025
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code e
100RISCO
abrir
GitHub PoC
Authentication bypass vulnerability in versions of the CrushFTP server.
CVE-2025-31161CRITICALsob ataqueransomware15 set 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISCO
abrir
GitHub PoC
0xDTC/js2py-Sandbox-Escape-CVE-2024-28397-RCE
CVE-2024-28397MEDIUM15 set 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISCO
abrir
GitHub PoC3
Langflow Remote Code Execution
CVE-2025-3248CRITICALsob ataqueransomware15 set 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
GitHub PoC
tcetin704/CVE-2017-12611
CVE-2017-1261115 set 2025
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag in
60RISCO
abrir
GitHub PoC1
Safe, read-only SQL Injection checker for FreePBX (CVE-2025-57819), using error/boolean/time-based techniques with per-parameter verdicts and JSON reporting.
CVE-2025-57819CRITICALsob ataque14 set 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir
GitHub PoC
CVE-2025-26264 - GeoVision GV-ASWeb with the version 6.1.2.0 or less, contains a Remote Code Execution (RCE) vulnerability within its Notification Settings feature. An authenticated attacker with "System Settings" privileges in ASWeb can exploit this flaw to execute arbitrary commands on the server, leading to a full system compromise.
CVE-2025-26264HIGH14 set 2025
GeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), contains a Remote Code Execution (RCE) vulnerabili
46RISCO
abrir
GitHub PoC
Documented CVE-2021-41773 (Apache HTTP Server path traversal, CVSS 9.8) — produced CVSS breakdown, impact assessment, and a mitigation plan (patch to 2.4.51+, CGI disable, firewall) and published the analysis on GitHub.
CVE-2021-41773HIGHsob ataqueransomware14 set 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
shoucheng3/apache__dolphinscheduler_CVE-2023-49109_3_2_1_fixed
CVE-2023-49109CRITICAL14 set 2025
Remote Code Execution in Apache Dolphinscheduler
48RISCO
abrir
GitHub PoC
A proof-of-concept exploit for WinRAR vulnerability (CVE-2025-8088) affecting versions 7.12 and lower. This tool creates a malicious RAR archive that embeds payloads in Alternate Data Streams (ADS) with path traversal, potentially leading to arbitrary code execution.
CVE-2025-8088HIGHsob ataqueransomware14 set 2025
Path traversal vulnerability in WinRAR
93RISCO
abrir
GitHub PoC
Shubhankargupta691/CVE-2024-42009
CVE-2024-42009CRITICALsob ataque14 set 2025
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RISCO
abrir
GitHub PoC7
Python PoC script for pgAdmin4 Query Tool RCE (CVE-2025-2945)
CVE-2025-2945CRITICAL13 set 2025
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
75RISCO
abrir
GitHub PoC
Grafana SQL Expressions → DuckDB LFI (CVE-2024-9264)
CVE-2024-9264CRITICAL13 set 2025
Grafana SQL Expressions allow for remote code execution
85RISCO
abrir
GitHub PoC
chin-tech/CrushFTP_CVE-2025-54309
CVE-2025-54309CRITICALsob ataque13 set 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RISCO
abrir
GitHub PoC
CVE-2025-48384-submodule
CVE-2025-48384HIGHsob ataque13 set 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC1
Hands-on pentest project using Kali Linux vs Metasploitable2. Includes full workflow: Nmap scanning, enumeration, Metasploit exploitation (Samba CVE-2007-2447), post-exploitation validation, and mitigation steps. Repo contains commands, outputs, and report showing both offensive techniques and defensive recommendations.
CVE-2007-244713 set 2025
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir
GitHub PoC
GIT vulnerability | Carriage Return and RCE on cloning
CVE-2025-48384HIGHsob ataque12 set 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC
Grafana CVE-2025-4123-POC
CVE-2025-4123HIGH12 set 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISCO
abrir
GitHub PoC7
FreePBX versions 15, 16, and 17 contain a Remote Code Execution (RCE) vulnerability caused by insufficient sanitization of user-supplied data in endpoints.
CVE-2025-57819CRITICALsob ataque12 set 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir
GitHub PoC4
Ash1996x/CVE-2025-54914-PoC
CVE-2025-54914CRITICAL12 set 2025
Azure Networking Elevation of Privilege Vulnerability
48RISCO
abrir
GitHub PoC2
CVE-2024-3094 exposed a backdoor in the XZ compression library, allowing remote SSH access by bypassing authentication. It’s a major supply chain attack affecting Linux systems, highlighting risks in trusted open-source components.
CVE-2024-3094CRITICAL12 set 2025
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC1
JinhyukKo/CVE-2024-4701-POC
CVE-2024-4701CRITICAL12 set 2025
Path Traversal vulnerability via File Uploads in Genie
53RISCO
abrir
GitHub PoC
A hands-on simulation of CVE-2017-5638 (Apache Struts2 RCE), showcasing exploit reproduction, OS-level command execution, and mitigations such as input sanitization and endpoint monitoring. Built in Python/Flask with Jupyter notebook demos
CVE-2017-5638CRITICALsob ataqueransomware11 set 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC
Detection for CVE-2025-42944
CVE-2025-42944CRITICAL11 set 2025
Insecure Deserialization vulnerability in SAP Netweaver (RMI-P4)
48RISCO
abrir
GitHub PoC
exploit of CVE-2022-0847 which directly remove password of the root account
CVE-2022-0847HIGHsob ataque11 set 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC1
For CTF's and Safe Environments.... CVE-2021-4034 Local PrivEsc.
CVE-2021-4034HIGHsob ataqueransomware11 set 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
This repository contains **research and analysis** related to CVE-2025-29927. It demonstrates safe, controlled testing approaches for a path traversal/middleware misconfiguration vulnerability in web applications.
CVE-2025-29927CRITICAL11 set 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC1
In-depth study of CVE-2019-18935 affecting Telerik UI for ASP.NET AJAX. Covers .NET deserialization vulnerability, RadAsyncUpload handler, gadget chains, mixed-mode assembly exploitation, and mitigation strategies.
CVE-2019-18935CRITICALsob ataqueransomware11 set 2025
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISCO
abrir
GitHub PoC
Nexus Repository 3 Path Traversal (CVE-2024-4956)
CVE-2024-4956HIGH10 set 2025
Nexus Repository 3 - Path Traversal
61RISCO
abrir
GitHub PoC1
Advanced network penetration testing toolkit with SSH vulnerability assessment, CVE-2018-15473 exploitation, stealth brute force capabilities, and fail2ban evasion techniques. Professional-grade security testing framework for authorized penetration testing engagements.
CVE-2018-15473MEDIUM10 set 2025
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
anteriorpágina 176 / 511próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.