Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.324exploits catalogados
37.130CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.614GitHub PoC 15.330VulnCheck XDB 9.001Nuclei 4.401Metasploit 3.502✓ só verificadosrecentespopularesrisco
15.330 exploits
GitHub PoC★ 8
💥 Python Exploit for CVE-2025-49113 | Roundcube Webmail RCE via PHP Object Injection
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir ↗GitHub PoC
PoC for CVE-2024-47575
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2
100RISCO
abrir ↗GitHub PoC
r0otk3r/CVE-2025-31161
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISCO
abrir ↗GitHub PoC★ 1
CVE‑2025‑25257 is a critical pre-authentication SQL injection vulnerability affecting Fortinet FortiWeb’s
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISCO
abrir ↗GitHub PoC★ 5
Public PoC for CVE-2025-25257: FortiWeb pre-auth SQLi to RCE
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISCO
abrir ↗GitHub PoC★ 9
A tool that identifies writable web directories in Apache Tomcat via HTTP PUT method [CVE-2025-24813]
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗GitHub PoC★ 14
PoC for NVIDIAScape bug
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, wher
48RISCO
abrir ↗GitHub PoC★ 2
Proof-of-Concept exploit for CVE-2025-7795 – A buffer overflow vulnerability affecting certain Tenda routers. The exploit sends crafted POST requests to trigger a crash and confirms the impact using ICMP (ping) checks.
Tenda FH451 P2pListFilter fromP2pListFilter stack-based overflow
41RISCO
abrir ↗GitHub PoC
r0otk3r/CVE-2025-41646
RevPi Webstatus application is vulnerable to an authentication bypass
75RISCO
abrir ↗GitHub PoC
Anezatraa/CVE-2025-48384-submodule
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir ↗GitHub PoC★ 1
Joelp03/CVE-2025-49113
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir ↗GitHub PoC★ 1
Zenar CMS 9.3 suffers from an unrestricted file upload vulnerability in its file management module, allowing authenticated attackers (with minimal privileges) to upload arbitrary files, including malicious PHP scripts, to the web server.
Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).
48RISCO
abrir ↗GitHub PoC
Local Privilege Escalation to Root via Sudo chroot in Linux
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗GitHub PoC★ 8
Exploit para explotar la vulnerabilidad CVE-2025-32463
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗GitHub PoC★ 8
Exploit para explotar la vulnerabilidad CVE-2025-32463
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir ↗GitHub PoC★ 32
POC of CVE-2025-7783
Usage of unsafe random function in form-data for choosing boundary
48RISCO
abrir ↗GitHub PoC
simplyfurious/CVE-2025-48384-submodule_test
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir ↗GitHub PoC
This is the exploit for the CVE-2025-32463
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗GitHub PoC
admin-ping/CVE-2025-48384-RCE
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir ↗GitHub PoC
PoC of cve-2016-6210
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RISCO
abrir ↗GitHub PoC★ 1
blindma1den/CVE-2025-47812
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir ↗GitHub PoC
Detection for CVE-2025-47812
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir ↗GitHub PoC
nguyentranbaotran/cve-2025-48384-poc
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir ↗GitHub PoC
Floodnut/CVE-2025-32463
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗GitHub PoC★ 5
An in-depth analysis of CVE 2023 38408, a critical OpenSSH vulnerability, including technical background, exploitation in controlled environments, and mitigation strategies.
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISCO
abrir ↗GitHub PoC
CVE-2025-53833
LaRecipe is vulnerable to Server-Side Template Injection attacks
63RISCO
abrir ↗GitHub PoC
rpc.py 0.6.0 - Remote Code Execution (RCE)
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header i
35RISCO
abrir ↗GitHub PoC
malaya-m/cve-2013-3900-remediation-report
WinVerifyTrust Signature Validation Vulnerability
75RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.