Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.324exploits catalogados
37.130CVEs com exploração pública
24.695testados em laboratório
15.330 exploits
GitHub PoC
Python Script for CVE-2025-49113. Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
CVE-2025-49113CRITICALsob ataque29 ago 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
GitHub PoC2
致远OA存在文件上传导致RCE(CVE-2025-34040)
CVE-2025-34040CRITICAL29 ago 2025
Seeyon Zhiyuan OA System Path Traversal File Upload
68RISCO
abrir
GitHub PoC
Built to call on CVE-2025-48384-PoC-Part2 for RCE
CVE-2025-48384HIGHsob ataque28 ago 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC
PoC for CVE-2025-48384
CVE-2025-48384HIGHsob ataque28 ago 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC
Mdusmandasthaheer/CVE-2025-32433
CVE-2025-32433CRITICALsob ataque28 ago 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
GitHub PoC
jacobholtz/CVE-2025-48384-submodule
CVE-2025-48384HIGHsob ataque28 ago 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC4
swabird/CVE-2025-7775-PoC
CVE-2025-7775CRITICALsob ataque28 ago 2025
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service
83RISCO
abrir
GitHub PoC
PoC | NextJS Middleware 15.2.2 - Authorization Bypass
CVE-2025-29927CRITICAL28 ago 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
RCE hook
CVE-2025-48384HIGHsob ataque28 ago 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC
Naved124/CVE-2024-28397-js2py-Sandbox-Escape
CVE-2024-28397MEDIUM28 ago 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISCO
abrir
GitHub PoC1
soltanali0/CVE-2024-12877-Exploit
CVE-2024-12877CRITICAL28 ago 2025
GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection
48RISCO
abrir
GitHub PoC11
IOS audio buffer overflow CVE-2025-31200 POC
CVE-2025-31200CRITICALsob ataque28 ago 2025
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4
83RISCO
abrir
GitHub PoC1
Detection for CVE-2025-57819
CVE-2025-57819CRITICALsob ataque28 ago 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir
GitHub PoC
An exploitation framework for CVE-2018-19323 - GIGABYTE GDrv privilege escalation vulnerability with multi-architecture support and framework integration
CVE-2018-19323CRITICALsob ataqueransomware27 ago 2025
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
78RISCO
abrir
GitHub PoC
A standalone Rust implementation of the CVE-2007-2447 exploit targeting Samba smbd 3.0.20-Debian.
CVE-2007-244727 ago 2025
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir
GitHub PoC3
用于CVE-2025-32463 sudo_chwoot的权限提升POC,适配了有gcc编译环境和无gcc编译环境的两种情况,下载运行即可一把梭哈
CVE-2025-32463CRITICALsob ataque27 ago 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC
hacieda/CVE-2025-32463
CVE-2025-32463CRITICALsob ataque27 ago 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC8
A high-performance, memory-safe implementation of the WinRAR CVE-2025-8088 exploit tool, rewritten in Rust for better reliability and performance.
CVE-2025-8088HIGHsob ataqueransomware27 ago 2025
Path traversal vulnerability in WinRAR
93RISCO
abrir
GitHub PoC10
Winrar CVE exploitation before 7.13 using multiple ADS streams on a single file (Custom PDF implementation)
CVE-2025-8088HIGHsob ataqueransomware27 ago 2025
Path traversal vulnerability in WinRAR
93RISCO
abrir
GitHub PoC5
yukinime/CVE-2025-6934
CVE-2025-6934CRITICAL27 ago 2025
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RISCO
abrir
GitHub PoC
te0rwx/CVE-2025-32433-Detection
CVE-2025-32433CRITICALsob ataque27 ago 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
GitHub PoC5
walidpyh/CVE-2025-8088
CVE-2025-8088HIGHsob ataqueransomware27 ago 2025
Path traversal vulnerability in WinRAR
93RISCO
abrir
GitHub PoC1
DeepBlue-dot/CVE-2025-8088-WinRAR-Startup-PoC
CVE-2025-8088HIGHsob ataqueransomware26 ago 2025
Path traversal vulnerability in WinRAR
93RISCO
abrir
GitHub PoC12
An engaging walkthrough on uncovering, patching, and securing the WinRAR CVE-2025-8088 with a hands-on hacker’s twist.
CVE-2025-8088HIGHsob ataqueransomware26 ago 2025
Path traversal vulnerability in WinRAR
93RISCO
abrir
GitHub PoC1
POWERSHEL script to check if your device is affected or no
CVE-2025-8088HIGHsob ataqueransomware26 ago 2025
Path traversal vulnerability in WinRAR
93RISCO
abrir
GitHub PoC2
Unauth RCE PoC for XWiki SolrSearch (CVE-2025-24893). Command exec + reverse shell.
CVE-2025-24893CRITICALsob ataque26 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC
a1ex-var1amov/ctf-cve-2019-11043
CVE-2019-11043HIGHsob ataqueransomware26 ago 2025
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC
A critical remote code execution (RCE) vulnerability (CVE‑2025‑24893) exists in the XWiki Platform, specifically in the SolrSearch RSS feed endpoint.
CVE-2025-24893CRITICALsob ataque26 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC
PoC for CVE-2025-34030 sar2html 'plot' parameter RCE
CVE-2025-34030CRITICAL26 ago 2025
sar2html OS Command Injection
75RISCO
abrir
GitHub PoC1
Real4XoR/CVE-2019-6693
CVE-2019-6693MEDIUMsob ataqueransomware26 ago 2025
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacke
63RISCO
abrir
anteriorpágina 180 / 511próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.