Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.409exploits catalogados
37.196CVEs com exploração pública
24.695testados em laboratório
15.347 exploits
GitHub PoC
Python exploit for CVE-2021-41773 - Apache HTTP Server 2.4.49 Path Traversal vulnerability
CVE-2021-41773HIGHsob ataqueransomware02 jul 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC1
MAVRICK-1/cve-2024-23113-test-env
CVE-2024-23113CRITICALsob ataque02 jul 2025
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RISCO
abrir
GitHub PoC530
Escalation of Privilege to the root through sudo binary with chroot option. CVE-2025-32463
CVE-2025-32463CRITICALsob ataque01 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC1
Detects Apache HTTP Server path traversal vulnerabilities (CVE-2021-41773, CVE-2021-42013) by checking for exposure of /etc/passwd through various traversal techniques.
CVE-2021-41773HIGHsob ataqueransomware01 jul 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC54
Wing FTP Server Remote Code Execution (RCE) Exploit (CVE-2025-47812)
CVE-2025-47812CRITICALsob ataque01 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir
GitHub PoC
POC script for CVE-2025-32462 a vulnerability in sudo
CVE-2025-32462LOW01 jul 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RISCO
abrir
GitHub PoC13
Simple exploit for Wing FTP Server RCE (CVE-2025-47812) to run commands and get a reverse shell. For educational use only.
CVE-2025-47812CRITICALsob ataque01 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir
GitHub PoC1
depers-rus/CVE-2007-4559
CVE-2007-4559CRITICAL01 jul 2025
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows
53RISCO
abrir
GitHub PoC30
CVE-2025-32463 Proof of concept
CVE-2025-32463CRITICALsob ataque01 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC1
4f-kira/CVE-2025-32463
CVE-2025-32463CRITICALsob ataque01 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC2
WordPress Custom Login And Signup Widget Plugin <= 1.0 is vulnerable to Arbitrary Code Execution
CVE-2025-49029CRITICAL01 jul 2025
WordPress Custom Login And Signup Widget plugin <= 1.0 - Arbitrary Code Execution vulnerability
63RISCO
abrir
GitHub PoC2
7r00t/cve-2025-32463-lab
CVE-2025-32463CRITICALsob ataque01 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC8
Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution in WonderCMS. This tool uses PentestMonkey's PHP reverse shell script as the payload
CVE-2023-41425MEDIUM01 jul 2025
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISCO
abrir
GitHub PoC9
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation
CVE-2025-6934CRITICAL01 jul 2025
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RISCO
abrir
GitHub PoC
DirtyPipe (CVE-2022-0847) exploit written in Rust
CVE-2022-0847HIGHsob ataque01 jul 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC1
Proof of concept of CVE-2025-20282, the perfect 10.
CVE-2025-20282CRITICAL01 jul 2025
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
68RISCO
abrir
GitHub PoC10
End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full memory and network forensic analysis.
CVE-2025-32463CRITICALsob ataque01 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC31
Proof of Concept for CVE-2025-6218, demonstrating the exploitation of a vulnerability in WinRAR versions 7.11 and under, involving improper handling of archive extraction paths.
CVE-2025-6218HIGHsob ataque01 jul 2025
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
93RISCO
abrir
GitHub PoC17
详细讲解CitrixBleed 2 — CVE-2025-5777(越界泄漏)PoC 和检测套件
CVE-2025-5777CRITICALsob ataqueransomware30 jun 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
GitHub PoC
Simulação educacional de exploração de falha em dispositivos IoT com base no CVE-2017-17761
CVE-2017-1776130 jun 2025
An issue was discovered on Ichano AtHome IP Camera devices. The device runs the "noodles" binary - a service on port 130
23RISCO
abrir
GitHub PoC2
This Python script is a Proof-of-Concept (PoC) scanner for detecting the vulnerability CVE-2024-40898, which affects Apache HTTP Server’s SSL certificate validation.
CVE-2024-40898CRITICAL30 jun 2025
Apache HTTP Server: SSRF with mod_rewrite in server/vhost context on Windows
48RISCO
abrir
GitHub PoC
Citrix Bleed 2 PoC
CVE-2025-6543CRITICALsob ataque30 jun 2025
Memory overflow vulnerability leading to unintended control flow and Denial of Service
83RISCO
abrir
GitHub PoC1
CVE‑2025‑30208 is a medium-severity arbitrary file read vulnerability in the Vite development server (a popular frontend build tool)
CVE-2025-30208MEDIUM29 jun 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir
GitHub PoC2
Just poc for CVE 2024-54085
CVE-2024-54085CRITICALsob ataque29 jun 2025
Redfish Authentication Bypass
90RISCO
abrir
GitHub PoC13
A simple proof of concept for WinRAR Path Traversal | RCE | CVE-2025-6218
CVE-2025-6218HIGHsob ataque29 jun 2025
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
93RISCO
abrir
GitHub PoC
Exploit Code for CVE-2024-39930 gogs ssh server RCE
CVE-2024-39930CRITICAL29 jun 2025
The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code
48RISCO
abrir
GitHub PoC
obscura-cert/CVE-2025-31650
CVE-2025-31650HIGH28 jun 2025
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
53RISCO
abrir
GitHub PoC
aninfosec/CVE-2024-43425-Poc
CVE-2024-43425HIGH28 jun 2025
Moodle: remote code execution via calculated question types
78RISCO
abrir
GitHub PoC1
obscura-cert/CVE-2025-33073
CVE-2025-33073HIGHsob ataque28 jun 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RISCO
abrir
GitHub PoC2
POC for PDF JS' CVE-2024-4367 vuln
CVE-2024-4367MEDIUM28 jun 2025
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir
anteriorpágina 199 / 512próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.