Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.409exploits catalogados
37.196CVEs com exploração pública
24.695testados em laboratório
15.347 exploits
GitHub PoC1
CVE-2023-33538 - TP-Link Command Injection Ruby module for Metasploit Framework
CVE-2023-33538HIGHsob ataque23 jun 2025
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerabili
83RISCO
abrir
GitHub PoC2
Exploit (C) CVE-2024-4577 on PHP CGI
CVE-2024-4577CRITICALsob ataqueransomware23 jun 2025
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC2
Check a list of Pterodactyl panels for vulnerabilities from a file.
CVE-2025-49132CRITICAL23 jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISCO
abrir
GitHub PoC
cuerv0x/CVE-2015-6967
CVE-2015-696723 jun 2025
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to
50RISCO
abrir
GitHub PoC
gmh5225/CVE-2025-1562
CVE-2025-1562CRITICAL22 jun 2025
Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit <= 3.5.3 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation
63RISCO
abrir
GitHub PoC1
sendINUX/CVE-2021-22600__DirtyPagetable
CVE-2021-22600MEDIUMsob ataque22 jun 2025
Double Free in net/packet/af_packet.c leading to priviledge escalation
63RISCO
abrir
GitHub PoC17
A script that gives you the credentials of a Pterodactyl panel vulnerable to CVE-2025-49132
CVE-2025-49132CRITICAL22 jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISCO
abrir
GitHub PoC
CVE 2018-9035: CSV Injection in Wordpress with plugin Contact Form 7 to Database Extension 2.10.3
CVE-2018-903522 jun 2025
CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPr
23RISCO
abrir
GitHub PoC1
Python Exploit for TP-Link TL-WR940N/TL-WR841N Command Injection Vulnerability
CVE-2023-33538HIGHsob ataque22 jun 2025
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerabili
83RISCO
abrir
GitHub PoC2
punitdarji/Grafana-cve-2025-4123
CVE-2025-4123HIGH21 jun 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISCO
abrir
GitHub PoC
CVE-2024-3094
CVE-2024-3094CRITICAL21 jun 2025
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC
PoC environment and exploit for the Apache Tomcat on Windows Remote Code Execution Vulnerability
CVE-2017-12615HIGHsob ataqueransomware21 jun 2025
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISCO
abrir
GitHub PoC
tomcat CVE-2025-24813 反序列化RCE环境
CVE-2025-24813CRITICALsob ataque21 jun 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC4
mbanyamer/PX4-Military-UAV-Autopilot-1.12.3-Stack-Buffer-Overflow-Exploit-CVE-2025-5640-
CVE-2025-5640MEDIUM21 jun 2025
PX4-Autopilot TRAJECTORY_REPRESENTATION_WAYPOINTS Message mavlink_receiver.cpp stack-based overflow
33RISCO
abrir
GitHub PoC
CVE-2021-44228 Vulnerability Reproduction Environment CVE-2021-44228 漏洞复现环境
CVE-2021-44228CRITICALsob ataqueransomware21 jun 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
CVE-2024-50562 is a session management vulnerability in Fortinet SSL-VPN portals
CVE-2024-50562MEDIUM20 jun 2025
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, ve
33RISCO
abrir
GitHub PoC
typicalsmc/CVE-2025-49132-PoC
CVE-2025-49132CRITICAL20 jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISCO
abrir
GitHub PoC
Rejetto HttpFileServer 2.3.x - Remote Command Execution (RevShell)
CVE-2014-6287CRITICALsob ataque20 jun 2025
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir
GitHub PoC
Tiny File Manager <= 2.4.6 - Remote Code Execution (RCE)
CVE-2021-4096420 jun 2025
A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to
23RISCO
abrir
GitHub PoC
This is a proof-of-concept Metasploit module exploit for CVE-2015-1578, a buffer overflow vulnerability in Achat 0.150 beta7 on Windows. Exploitation leads to remote code execution via a crafted UDP packet.
CVE-2015-157820 jun 2025
Multiple open redirect vulnerabilities in u5CMS before 3.9.4 allow remote attackers to redirect users to arbitrary web s
23RISCO
abrir
GitHub PoC
Unauthenticated RCE via Webmin Backdoor (CVE-2019–15107)
CVE-2019-15107CRITICALsob ataqueransomware19 jun 2025
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
GitHub PoC1
CVE-2025-3248 — Langflow RCE Exploit
CVE-2025-3248CRITICALsob ataqueransomware19 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
GitHub PoC
CVE-2019–11043: PHP-FPM Nginx Remote Code Execution Vulnerability
CVE-2019-11043HIGHsob ataqueransomware19 jun 2025
Underflow in PHP-FPM can lead to RCE
100RISCO
abrir
GitHub PoC
Exploit for CVE-2011-2523.
CVE-2011-252319 jun 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
GitHub PoC
DevinLiggins14/SMB-PenTest-Exploiting-CVE-2007-2447-on-Metasploitable-2
CVE-2007-244719 jun 2025
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir
GitHub PoC
This is a proof-of-concept exploit for CVE-2015-1578, a buffer overflow vulnerability in Achat 0.150 beta7 on Windows. Exploitation leads to remote code execution via a crafted UDP packet.
CVE-2015-157819 jun 2025
Multiple open redirect vulnerabilities in u5CMS before 3.9.4 allow remote attackers to redirect users to arbitrary web s
23RISCO
abrir
GitHub PoC1
Threat intelligence report analyzing the xz-utils backdoor vulnerability (CVE-2024-3094)
CVE-2024-3094CRITICAL19 jun 2025
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC
punitdarji/roundcube-cve-2025-49113
CVE-2025-49113CRITICALsob ataque18 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
GitHub PoC
Exploit for Langflow AI Remote Code Execution (Unauthenticated)
CVE-2025-3248CRITICALsob ataqueransomware18 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
GitHub PoC2
imbas007/CVE-2025-3248
CVE-2025-3248CRITICALsob ataqueransomware18 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
anteriorpágina 201 / 512próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.