Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.445exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
13.627 exploits
GitHub PoC
Yami0x777/Belsen_Group-et-exploitation-de-la-CVE-2022-40684
CVE-2022-40684CRITICALsob ataqueransomware10 fev 2025
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir
GitHub PoC1
cve-2019-5420 POC simple ruby script
CVE-2019-542010 fev 2025
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISCO
abrir
GitHub PoC
RogelioPumajulca/CVE-2022-0847
CVE-2022-0847HIGHsob ataque09 fev 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC
skrkcb2/CVE-2024-5452
CVE-2024-5452CRITICAL09 fev 2025
RCE via Property/Class Pollution in lightning-ai/pytorch-lightning
53RISCO
abrir
GitHub PoC
0x7556/CVE-2024-55591
CVE-2024-55591CRITICALsob ataqueransomware09 fev 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISCO
abrir
GitHub PoC1
SSHEnum es una herramienta de enumeración de usuarios SSH basada en CVE-2018-15473. Permite detectar usuarios válidos aprovechando respuestas diferenciadas del servidor. Es rápida, compatible con Python 3.12 y soporta wordlists. Uso exclusivo para auditoría y pruebas de seguridad autorizadas.
CVE-2018-15473MEDIUM09 fev 2025
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC
pz-frontend-manager < 1.0.6 - CSRF Profile Picture Exploit
CVE-2024-6244HIGH08 fev 2025
pz-frontend-manager < 1.0.6 - CSRF change user profile picture
41RISCO
abrir
GitHub PoC
This repository contains a Proof-of-Concept (PoC) exploit for the Baron Samedit vulnerability (CVE-2021-3156). The exploit demonstrates privilege escalation on Ubuntu 20.04 with sudo version 1.8.31 and glibc version 2.31. It includes an assembly-based exploit, a shared object payload, and a Makefile for automated compilation.
CVE-2021-3156HIGHsob ataque08 fev 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC3
Snizi/Moodle-CVE-2024-43425-Exploit
CVE-2024-43425HIGH07 fev 2025
Moodle: remote code execution via calculated question types
78RISCO
abrir
GitHub PoC4
Cityworks deserialization of untrusted data vulnerability Detection
CVE-2025-0994HIGHsob ataque07 fev 2025
Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to
83RISCO
abrir
GitHub PoC
PoC of CVE-2022-30190
CVE-2022-30190HIGHsob ataqueransomware07 fev 2025
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC4
Python script for CVE-2024-0012 / CVE-2024-9474 exploit
CVE-2024-0012CRITICALsob ataqueransomware06 fev 2025
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISCO
abrir
GitHub PoC1
This is a Python script that exploits the CVE-2024-6624 vulnerability in the JSON API User <= 3.9.3 plugin for WordPress.
CVE-2024-6624CRITICAL06 fev 2025
JSON API User <= 3.9.3 - Unauthenticated Privilege Escalation
48RISCO
abrir
GitHub PoC
Directory Traversal Exploit written in Bash for NVMS-1000 (CVE-2019-20085).
CVE-2019-20085HIGHsob ataque06 fev 2025
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RISCO
abrir
GitHub PoC
KGorbakon/CVE-2023-41425
CVE-2023-41425MEDIUM05 fev 2025
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISCO
abrir
GitHub PoC
cy3erdr4g0n/CVE-2024-10924
CVE-2024-10924CRITICAL05 fev 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir
GitHub PoC
Arthikw3b/RCE-CVE-2024-7954
CVE-2024-7954CRITICAL05 fev 2025
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISCO
abrir
GitHub PoC1
SOC287 - Arbitrary File Read on Checkpoint Security Gateway [CVE-2024-24919]
CVE-2024-24919HIGHsob ataqueransomware05 fev 2025
Information disclosure
100RISCO
abrir
GitHub PoC
daikinitanda/-CVE-2024-47875-
CVE-2024-47875CRITICAL05 fev 2025
DOMPurify nesting-based mXSS
48RISCO
abrir
GitHub PoC1
qw3rtyou/CVE-2021-44228_dockernize
CVE-2021-44228CRITICALsob ataqueransomware04 fev 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC5
CVE-2019-2215 poc for Huawei hardened kernel
CVE-2019-2215HIGHsob ataque04 fev 2025
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISCO
abrir
GitHub PoC1
This script checks for devices vulnerable to the EternalBlue exploit (CVE-2017-0144) in a network using SMB.
CVE-2017-0144HIGHsob ataqueransomware03 fev 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
GitHub PoC
Code to decrypt Huawei passwords CVE-2012-4960
CVE-2012-496003 fev 2025
The Huawei NE5000E, MA5200G, NE40E, NE80E, ATN, NE40, NE80, NE20E-X6, NE20, ME60, CX600, CX200, CX300, ACU, WLAN AC 6605
23RISCO
abrir
GitHub PoC
In this challenge, I analyzed the Spring4Shell (CVE-2022-22965) vulnerability, investigated security bypasses, and wrote an Incident Postmortem Report detailing the detection, impact, and resolution of the attack. I also implemented a firewall rule in Python to block malicious requests and prevent future exploitation.
CVE-2022-22965CRITICALsob ataque03 fev 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC
rehan6658/CVE-2023-40028
CVE-2023-40028MEDIUM02 fev 2025
Arbitrary file read via symlinks in Ghost
45RISCO
abrir
GitHub PoC
dorattias/CVE-2025-26319
CVE-2025-26319CRITICAL02 fev 2025
FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.
75RISCO
abrir
GitHub PoC
This repository contains a Proof-of-Concept for the CVE-2021-41773. This CVE contains a LFI and RCE vulnerablity.
CVE-2021-41773HIGHsob ataqueransomware02 fev 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
This code is taken from "Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Add Admin User)" and was converted to Python 3 to suit the exercise in Academy for Module "Attacking Commoon Applications" and section "Attacking Drupal".
CVE-2014-370402 fev 2025
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISCO
abrir
GitHub PoC
CVE-2017-8869 - MediaCoder 0.8.48.5888 - Local Buffer Overflow (SEH)
CVE-2017-886902 fev 2025
Buffer overflow in MediaCoder 0.8.48.5888 allows remote attackers to execute arbitrary code via a crafted .m3u file.
43RISCO
abrir
GitHub PoC1
hashdr1ft/SOC274-Palo-Alto-Networks-PAN-OS-Command-Injection-Vulnerability-Exploitation-CVE-2024-3400
CVE-2024-3400CRITICALsob ataqueransomware02 fev 2025
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISCO
abrir
anteriorpágina 179 / 455próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.