Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.445exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.497GitHub PoC 13.627VulnCheck XDB 8.198Nuclei 4.217Metasploit 3.463✓ só verificadosrecentespopularesrisco
13.622 exploits
GitHub PoC★ 1
build-script for CVE-2024-46507 and CVE-2024-46508
A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti befor
56RISCO
abrir ↗GitHub PoC
Exploitation for CVE-2022-26923
Active Directory Domain Services Elevation of Privilege Vulnerability
100RISCO
abrir ↗GitHub PoC
GazettEl/CVE-2020-17519
Apache Flink directory traversal attack: reading remote files through the REST API
100RISCO
abrir ↗GitHub PoC★ 3
Python script to exploit CVE-2020-35391 on Tenda F3 V3/V4 routers, enabling unauthorized download of configuration, flash, and syslog files.
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_pas
60RISCO
abrir ↗GitHub PoC
Project on CVE-2022-30190 exploitation and mitigation strategies
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC★ 129
Deterministic kernel exploit based on CVE-2023-32434.
An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11
83RISCO
abrir ↗GitHub PoC
CVE-2019-18935: Remote Code Execution
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISCO
abrir ↗GitHub PoC★ 1
overgrowncarrot1/CVE-2019-1003030
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/
100RISCO
abrir ↗GitHub PoC★ 4
Mautic < 5.2.3 Authenticated RCE
Remote Code Execution & File Deletion in Asset Uploads
48RISCO
abrir ↗GitHub PoC★ 233
POC exploit for CVE-2025-21333 heap-based buffer overflow. It leverages WNF state data and I/O ring IOP_MC_BUFFER_ENTRY
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RISCO
abrir ↗GitHub PoC★ 1
skrkcb2/CVE-2023-46604
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISCO
abrir ↗GitHub PoC
cojoben/CVE-2018-13382
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti
100RISCO
abrir ↗GitHub PoC★ 6
CVE-2025-26263 - GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less, is vulnerable to credentials disclosure due to improper memory handling in the ASManagerService.exe process.
GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to cred
33RISCO
abrir ↗GitHub PoC★ 7
CVE-2025-26264 - GeoVision GV-ASWeb with the version 6.1.2.0 or less, contains a Remote Code Execution (RCE) vulnerability within its Notification Settings feature. An authenticated attacker with "System Settings" privileges in ASWeb can exploit this flaw to execute arbitrary commands on the server, leading to a full system compromise.
GeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), contains a Remote Code Execution (RCE) vulnerabili
46RISCO
abrir ↗GitHub PoC
monjheta/CVE-2020-0796
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir ↗GitHub PoC
Automation script to exploit the Shellshock vulnerability.
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗GitHub PoC★ 3
WP Load Gallery <= 2.1.6 - Authenticated (Author+) Arbitrary File Upload
WordPress WP Load Gallery Plugin <= 2.1.6 - Arbitrary File Upload vulnerability
48RISCO
abrir ↗GitHub PoC★ 21
JSONPath-plus Remote Code Execution
Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input
68RISCO
abrir ↗GitHub PoC
A Rust exploit for CVE-2024-23346 that functions as a "terminal" (tested on chemistry.htb)
pymatgen arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
48RISCO
abrir ↗GitHub PoC★ 10
XWiki SolrSearchMacros 远程代码执行漏洞PoC(CVE-2025-24893)
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir ↗GitHub PoC★ 3
shishirghimir/CVE-2024-53677-Exploit
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir ↗GitHub PoC★ 1
Copy of the POC for CVE-2023-1545
SQL Injection in nilsteampassnet/teampass
41RISCO
abrir ↗GitHub PoC
Code to exploit CVE-2021-4034
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir ↗GitHub PoC★ 4
numanturle/CVE-2025-25279
Arbitrary file read in Mattermost Boards via import & export board archive
53RISCO
abrir ↗GitHub PoC
vivigotnotime/CVE-2023-22515-Exploit-Script
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISCO
abrir ↗GitHub PoC★ 1
WordPress CVE-2024-10924 Exploit for Really Simple Security plugin
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir ↗GitHub PoC★ 2
cesarbtakeda/7-Zip-CVE-2025-0411-POC
7-Zip Mark-of-the-Web Bypass Vulnerability
83RISCO
abrir ↗GitHub PoC
WinVerifyTrust Signature Validation CVE-2013-3900 Mitigation (EnableCertPaddingCheck)
WinVerifyTrust Signature Validation Vulnerability
75RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.