Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.557exploits catalogados
37.313CVEs com exploração pública
24.695testados em laboratório
15.367 exploits
GitHub PoC
OD&H's scanner for CVE-2024-25600 vulnerability in the Bricks Builder WordPress plugin. For use in Try Hack Me (THM) environments.
CVE-2024-25600CRITICAL09 abr 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir
GitHub PoC1
A simple, easy-to-use POC for CVE-2025-42813 (Apache Tomcat versions below 9.0.99).
CVE-2025-24813CRITICALsob ataque09 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC1
A simple, easy-to-use POC for CVE-2025-42813 (Apache Tomcat versions below 9.0.99).
CVE-2025-24813CRITICALsob ataque09 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC2
CVE-2025-31651 PoC
CVE-2025-31651CRITICAL08 abr 2025
Apache Tomcat: Bypass of rules in Rewrite Valve
48RISCO
abrir
GitHub PoC48
Proof of Concept for CVE-2025-31161 / CVE-2025-2825
CVE-2025-31161CRITICALsob ataqueransomware08 abr 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISCO
abrir
GitHub PoC1
GadaLuBau1337/CVE-2025-24813
CVE-2025-24813CRITICALsob ataque08 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC1
0xnxt1me/CVE-2025-29927
CVE-2025-29927CRITICAL08 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
pickovven/vulnerable-nextjs-14-CVE-2025-29927
CVE-2025-29927CRITICAL08 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
CVE-2025-29927 ~ a poc of the next.js middleware authentication bypass
CVE-2025-29927CRITICAL08 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC2
Prevent CVE-2025-22457 and other security problems with Juniper/Ivanti Secure Connect SSL VPN
CVE-2025-22457CRITICALsob ataqueransomware08 abr 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7
100RISCO
abrir
GitHub PoC
Project Repository for Exploitation, Detection and Mitigation of Folina Vulnerability (CVE-2022-30190)
CVE-2022-30190HIGHsob ataqueransomware08 abr 2025
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC2
sandsoncosta/CVE-2025-26633
CVE-2025-26633HIGHsob ataqueransomware08 abr 2025
Microsoft Management Console Security Feature Bypass Vulnerability
83RISCO
abrir
GitHub PoC
vances25/CVE-2024-44871
CVE-2024-44871HIGH07 abr 2025
An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute a
46RISCO
abrir
GitHub PoC3
mouadk/parquet-rce-poc-CVE-2025-30065
CVE-2025-30065CRITICAL07 abr 2025
Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
60RISCO
abrir
GitHub PoC
DFG register allocation bug in JavaScriptCore
CVE-2024-44308HIGHsob ataque07 abr 2025
The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18
76RISCO
abrir
GitHub PoC1
CVE-2025-29927
CVE-2025-29927CRITICAL07 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
Demonstration of CVE-2023-23397 Outlook Privellege Escalation vulnerability
CVE-2023-23397CRITICALsob ataque07 abr 2025
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC
Heimd411/CVE-2025-24813-noPoC
CVE-2025-24813CRITICALsob ataque07 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC
Hello researchers, I have a checker for the recent vulnerability CVE-2025-24813-checker.
CVE-2025-24813CRITICALsob ataque07 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC
WHS 3기 장대혁 취약한(CVE) Docker 환경 구성 과제입니다.
CVE-2019-5418HIGHsob ataque07 abr 2025
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir
GitHub PoC
vulnerable-nextjs-14-CVE-2025-29927
CVE-2025-29927CRITICAL06 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
Koray123-debug/CVE-2024-34102
CVE-2024-34102CRITICALsob ataque06 abr 2025
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir
GitHub PoC2
CVE-2025-24813-POC JSP Web Shell Uploader
CVE-2025-24813CRITICALsob ataque06 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
GitHub PoC
VVeakee/CVE-2024-4367
CVE-2024-4367MEDIUM06 abr 2025
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir
GitHub PoC8
Next.js Middleware Bypass Scanne
CVE-2025-29927CRITICAL06 abr 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
A POC lab environment for CVE-2024-56145 CraftCMS RCE.
CVE-2024-56145CRITICALsob ataque06 abr 2025
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
100RISCO
abrir
GitHub PoC33
Simulated PoC for CVE-2025-2783 — a sandbox escape vulnerability in Chrome's Mojo IPC. Includes phishing delivery, memory fuzzing, IPC simulation, and logging. Safe for red team demos, detection engineering, and educational use.
CVE-2025-2783HIGHsob ataque06 abr 2025
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
71RISCO
abrir
GitHub PoC1
cybermads/CVE-2011-2523
CVE-2011-252306 abr 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
GitHub PoC
d0x-awrqxavc/-CVE-2024-10924
CVE-2024-10924CRITICAL06 abr 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir
GitHub PoC3
WordPress FEUP Arbitrary File Upload Exploit (CVE-2025-2005)
CVE-2025-2005CRITICAL06 abr 2025
Front-End-Only-Users <= 3.2.32 - Unauthenticated Arbitrary File Upload
53RISCO
abrir
anteriorpágina 217 / 513próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.