Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.557exploits catalogados
37.313CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.478Referência 23.776GitHub PoC 15.367VulnCheck XDB 9.019Nuclei 4.415Metasploit 3.502✓ só verificadosrecentespopularesrisco
15.367 exploits
GitHub PoC★ 12
Onapsis/Onapsis_CVE-2025-31324_Scanner_Tools
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISCO
abrir ↗GitHub PoC★ 2
CVE-2022-3552 RCE with detailed exploitation steps
Unrestricted Upload of File with Dangerous Type in boxbilling/boxbilling
53RISCO
abrir ↗GitHub PoC★ 24
CVE-2025-31324, SAP Exploit
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISCO
abrir ↗GitHub PoC★ 27
This repository contains a proof-of-concept exploit script for CVE-2025-32432, a pre-authentication Remote Code Execution (RCE) vulnerability affecting CraftCMS versions 4.x and 5.x. The vulnerability exists in the asset transform generation feature of CraftCMS.
Craft CMS Allows Remote Code Execution
100RISCO
abrir ↗GitHub PoC
Attacks a vulnerable WordPress site with the wp-automatic plugin. Inserts a new user called eviladmin directly into the database (INSERT INTO wp_users). Searches for the ID of the newly created user (cyclic SELECT). Promotes eviladmin to Administrator (INSERT INTO wp_usermeta).
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISCO
abrir ↗GitHub PoC
Proof of Concept (PoC) script for CVE-2025-24813, vulnerability in Apache Tomcat.
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗GitHub PoC
WHS3기 가상화 취약한(CVE) Docker 환경 구성 과제
ingress-nginx admission controller RCE escalation
85RISCO
abrir ↗GitHub PoC
airtiels 5650 CVE-2015-2797 PoC
Stack-based buffer overflow in AirTies Air 6372, 5760, 5750, 5650TT, 5453, 5444TT, 5443, 5442, 5343, 5342, 5341, and 502
60RISCO
abrir ↗GitHub PoC
Dowonkwon/drupal-cve-2018-7600-poc
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir ↗GitHub PoC
shun1403/PIL-CVE-2017-8291-study
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion
100RISCO
abrir ↗GitHub PoC
CVE-2025-32433 Summary and Attack Overview
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir ↗GitHub PoC
shun1403/CVE-2017-8291
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion
100RISCO
abrir ↗GitHub PoC
ChoDeokCheol/CVE-2023-39361
Unauthenticated SQL Injection in graph_view.php in Cacti
85RISCO
abrir ↗GitHub PoC
romanedutov/CVE-2025-2294
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISCO
abrir ↗GitHub PoC★ 10
CraftCMS RCE Checker (CVE-2025-32432)
Craft CMS Allows Remote Code Execution
100RISCO
abrir ↗GitHub PoC★ 2
CVE-2021-42287/CVE-2021-42278/OTHER Scanner & Exploiter.
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISCO
abrir ↗GitHub PoC
K4Der11000/k4_cve-2023-41064
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1
83RISCO
abrir ↗GitHub PoC
WonderCMS v3.4.2 NSE Discovery Script
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISCO
abrir ↗GitHub PoC
A PoC of CVE-2019-5420 I made for PentesterLab
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISCO
abrir ↗GitHub PoC
Python Proof of Concept for CVE-2023-1545 (SQL Injection for Teampass versions prior to 3.0.0.23).
SQL Injection in nilsteampassnet/teampass
41RISCO
abrir ↗GitHub PoC
A PoC of CVE-2016-10033 I made for PentesterLab
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir ↗GitHub PoC★ 4
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISCO
abrir ↗GitHub PoC★ 1
Erlang OTP SSH NSE Discovery Script
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir ↗GitHub PoC★ 2
Next.js middleware bypass exploit
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC
A PoC of CVE-2018-0114 I made for PentesterLab
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISCO
abrir ↗GitHub PoC
A PoC of CVE-2016-2098 I made for PentesterLab
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RISCO
abrir ↗GitHub PoC★ 4
Proof-of-Concept (PoC) for CVE-2025-29306, a Remote Code Execution vulnerability in FoxCMS. This Python script scans single or multiple targets, executes commands, and reports vulnerable hosts.
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.