Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.409exploits catalogados
37.196CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.478Referência 23.664GitHub PoC 15.347VulnCheck XDB 9.003Nuclei 4.415Metasploit 3.502✓ só verificadosrecentespopularesrisco
80.409 exploits
GitHub PoC
PoC exploit for CVE-2024-46987 — Camaleon CMS arbitrary path traversal (file read)
Arbitrary path traversal in Camaleon CMS
61RISCO
abrir ↗GitHub PoC
iOxsec/CVE-2025-6018-CVE-2025-6019-Privilege-Escalation-Exploit
Pam-config: lpe from unprivileged to allow_active in pam
41RISCO
abrir ↗GitHub PoC
The flaw allows an attacker to execute arbitrary system commands on the server hosting the Pterodactyl Panel without any prior authentication.
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISCO
abrir ↗GitHub PoC
its970/CVE-2025-68645
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1
98RISCO
abrir ↗VulnCheck XDB
initial-access
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1
98RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
Active Directory Domain Services Elevation of Privilege Vulnerability
100RISCO
abrir ↗GitHub PoC★ 1
Exploitation de CVE-2022-26923
Active Directory Domain Services Elevation of Privilege Vulnerability
100RISCO
abrir ↗VulnCheck XDB
initial-access
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
Slider Future <= 1.0.5 - Unauthenticated Arbitrary File Upload
63RISCO
abrir ↗VulnCheck XDB
initial-access
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir ↗GitHub PoC
C reimplementation of chwoot PoC
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗GitHub PoC
Path traversal vulnerability in Python's tarfile.
Arbitrary writes via tarfile realpath overflow
48RISCO
abrir ↗GitHub PoC
CVE-2022-37969 poc
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir ↗GitHub PoC
A practical lab demonstrating the exploitation of a critical Remote Code Execution (RCE) vulnerability in Apache Struts2 (CVE-2017-5638) using Vulhub Docker environments. Includes setup instructions and commands to run the vulnerable container.
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir ↗VulnCheck XDB
local
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir ↗GitHub PoC
A proof of concept for CVE-2025-31161, using mangled HTTP header to perform unauthenticated impersonation of any user in Crush FTP server.
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISCO
abrir ↗GitHub PoC
theemperorspath/CVE-2026-2441-PoC
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside
76RISCO
abrir ↗VulnCheck XDB
initial-access
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
SPIP Saisies Plugin < 5.11.1 Remote Code Execution
63RISCO
abrir ↗GitHub PoC★ 1
这是基于cve-2016-4437简单的漏洞复现代码
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RISCO
abrir ↗VulnCheck XDB
client-side
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside
76RISCO
abrir ↗VulnCheck XDB
initial-access
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
100RISCO
abrir ↗VulnCheck XDB
initial-access
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
100RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir ↗GitHub PoC★ 4
CVE-2025-71243 - SPIP Saisies Plugin RCE (Unauthenticated PHP Code Injection)
SPIP Saisies Plugin < 5.11.1 Remote Code Execution
63RISCO
abrir ↗GitHub PoC
CVE-2014-6271 Exploit | by infrar3d
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗VulnCheck XDB
local
Windows Common Log File System Driver Elevation of Privilege Vulnerability
71RISCO
abrir ↗GitHub PoC★ 2
Unauthenticated remote code execution vulnerability in Wing FTP Server <= 7.4.3.
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir ↗GitHub PoC
CVE-2022-24521 poc
Windows Common Log File System Driver Elevation of Privilege Vulnerability
71RISCO
abrir ↗Metasploit600
MajorDoMo Supply Chain RCE via Update Poisoning
MajorDoMo Supply Chain Remote Code Execution via Update URL Poisoning
43RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.