Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.324exploits catalogados
37.130CVEs com exploração pública
24.695testados em laboratório
15.330 exploits
GitHub PoC1
Exploiting the CVE-2025-25257 vulnerability in FortiWeb. This repository demonstrates secure pre-authenticated SQL injection.
CVE-2025-25257CRITICALsob ataque12 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISCO
abrir
GitHub PoC
WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload
CVE-2025-6058CRITICAL12 jul 2025
WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload
63RISCO
abrir
GitHub PoC
r0otk3r/CVE-2024-1212
CVE-2024-1212CRITICALsob ataque12 jul 2025
LoadMaster Pre-Authenticated OS Command Injection
100RISCO
abrir
GitHub PoC
pkblanks/Remediating-CVE-2013-3900-EnableCertPaddingCheck-
CVE-2013-3900MEDIUMsob ataque12 jul 2025
WinVerifyTrust Signature Validation Vulnerability
75RISCO
abrir
GitHub PoC
MacUchegit/Detecting-and-Analyzing-CVE-2024-24919-Exploitation
CVE-2024-24919HIGHsob ataqueransomware12 jul 2025
Information disclosure
100RISCO
abrir
GitHub PoC
This repository contains Detailed explanation and working poc for Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution.
CVE-2014-6287CRITICALsob ataque11 jul 2025
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir
GitHub PoC
Critical Sudo Vulnerabilities Let Local Users Gain Root Access on Linux, Impacting Major Distros
CVE-2025-32462LOW11 jul 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RISCO
abrir
GitHub PoC
CVE-2024-32113 & CVE-2024-38856
CVE-2024-32113CRITICALsob ataque11 jul 2025
Apache OFBiz: Path traversal leading to RCE
100RISCO
abrir
GitHub PoC
cuijiung/log4j-CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware11 jul 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Documentation for CVE-2025-6514. MCP-Remote RCE.
CVE-2025-6514CRITICAL11 jul 2025
OS command injection in mcp-remote when connecting to untrusted MCP servers
70RISCO
abrir
GitHub PoC
p1026/CVE-2025-48384
CVE-2025-48384HIGHsob ataque11 jul 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC1
PoC dockerfile image for CVE-2025-48384
CVE-2025-48384HIGHsob ataque11 jul 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC
Rust PoC for CVE-2025-32463 (sudo chroot "chwoot" Local PrivEsc)
CVE-2025-32463CRITICALsob ataque11 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC
r0otk3r/CVE-2024-10915
CVE-2024-10915CRITICAL11 jul 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir
GitHub PoC
hackmelocal/CVE-2025-49113-Simulation
CVE-2025-49113CRITICALsob ataque11 jul 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
GitHub PoC
just remeber how small mistake in santisize username could give yoy root access to the full machine
CVE-2007-244711 jul 2025
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir
GitHub PoC6
CVE-2025-24201 WebKit Vulnerability Detector (PoC)
CVE-2025-24201CRITICALsob ataque11 jul 2025
An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in
78RISCO
abrir
GitHub PoC
Metasploit module for MailEnable CVE-2022-36934 authentication bypass RCE
CVE-2022-36934CRITICAL11 jul 2025
An integer overflow in WhatsApp could result in remote code execution in an established video call.
48RISCO
abrir
GitHub PoC
Delivering PHP RCE (CVE-2024-4577) to the Local Network Servers
CVE-2024-4577CRITICALsob ataqueransomware11 jul 2025
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
CVE-2025-6554 PoC
CVE-2025-6554HIGHsob ataque10 jul 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
76RISCO
abrir
GitHub PoC
altm4n/cve-2025-48384
CVE-2025-48384HIGHsob ataque10 jul 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC
r0otk3r/CVE-2024-27954
CVE-2024-27954CRITICAL10 jul 2025
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability
85RISCO
abrir
GitHub PoC
Praktische Demonstration der Log4Shell-Sicherheitslücke (CVE-2021-44228)
CVE-2021-44228CRITICALsob ataqueransomware10 jul 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC30
CVE-2025-5777 Citrix NetScaler Memory Leak Exploit (CitrixBleed 2)
CVE-2025-5777CRITICALsob ataqueransomware10 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
GitHub PoC
Citrix NetScaler Memory Leak PoC
CVE-2025-5777CRITICALsob ataqueransomware10 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
GitHub PoC
漏洞测试
CVE-2025-48384HIGHsob ataque10 jul 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC
greatyy/CVE-2025-48384-p
CVE-2025-48384HIGHsob ataque10 jul 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC
CVE-2025-48384
CVE-2025-48384HIGHsob ataque10 jul 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC
Exploit for CVE-2025-32023
CVE-2025-32023HIGH10 jul 2025
Redis allows out of bounds writes in hyperloglog commands leading to RCE
41RISCO
abrir
GitHub PoC
altm4n/cve-2025-48384-hub
CVE-2025-48384HIGHsob ataque10 jul 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
anteriorpágina 194 / 511próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.