Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.646exploits catalogados
37.382CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.482Referência 23.825GitHub PoC 15.392VulnCheck XDB 9.029Nuclei 4.416Metasploit 3.502✓ só verificadosrecentespopularesrisco
15.392 exploits
GitHub PoC
Resources for teh Apache Tomcat CVE lab
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗GitHub PoC
CVE-2018-7600.
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir ↗GitHub PoC
Windows File Explorer Spoofing Vulnerability (CVE-2025-24071)
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir ↗GitHub PoC★ 2
Alternativa CVE-2025-24071_PoC
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir ↗GitHub PoC
CVE-2021-41773
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗GitHub PoC★ 1
Checkmarx/Checkmarx-CVE-2025-30066-Detection-Tool
tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 thr
83RISCO
abrir ↗GitHub PoC★ 7
Apache Tomcat Remote Code Execution (RCE) Exploit - CVE-2025-24813
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗GitHub PoC★ 7
Otsmane-Ahmed/cve-2025-29384-poc
In Tenda AC9 v1.0 V15.03.05.14_multi, the wanMTU parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability
48RISCO
abrir ↗GitHub PoC★ 1
iOS/macOS library that exploits CVE-2023-41991 for signing iOS applications.
A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A mal
63RISCO
abrir ↗GitHub PoC★ 25
Metasploit module for CVE-2025-24071 - Windows NTLM Hash Leak via .library-ms
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir ↗GitHub PoC
HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion (LFI)
HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion
75RISCO
abrir ↗GitHub PoC★ 1
WordPress WPMasterToolKit plugin <= 1.13.1 - Arbitrary File Upload vulnerability
WordPress WPMasterToolKit plugin <= 1.13.1 - Arbitrary File Upload vulnerability
48RISCO
abrir ↗GitHub PoC
Microsoft Windows File Explorer Spoofing Vulnerability / NTLM Hash Leak
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir ↗GitHub PoC★ 2
CVE-2024-57040 is a security vulnerability found in certain TP-Link TL-WR845N router models. Specifically, it involves a "hardcoded" password for the router's root account. This means a default, unchanging password is built into the router's software.
TP-Link TL-WR845N devices with firmware TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a
48RISCO
abrir ↗GitHub PoC
regantemudo/CVE-2024-25641-Exploit-for-Cacti-1.2.26
Cacti RCE vulnerability when importing packages
85RISCO
abrir ↗GitHub PoC★ 1
orilevy8/cve-2023-0386
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISCO
abrir ↗GitHub PoC★ 3
Nuclei Template CVE-2025–24813
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗GitHub PoC
KillReal01/CVE-2023-4911
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISCO
abrir ↗GitHub PoC★ 1
Jimmy01240397/CVE-2024-12641_12642_12645
Chunghwa Telecom TenderDocTransfer - Reflected Cross-site Scripting to RCE
48RISCO
abrir ↗GitHub PoC
DavidBr27/CVE-2013-3900-Remediation-Script
WinVerifyTrust Signature Validation Vulnerability
75RISCO
abrir ↗GitHub PoC
CVE-2024-9047, wfu_file_downloader.php
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
85RISCO
abrir ↗GitHub PoC★ 2
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISCO
abrir ↗GitHub PoC★ 408
CVE-2025-24071: NTLM Hash Leak via RAR/ZIP Extraction and .library-ms File
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir ↗GitHub PoC
RCE, Citirx ADC and Gateway Directory Traversal
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir ↗GitHub PoC★ 16
CVE-2025-24813利用工具
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗GitHub PoC★ 2
One-Click-Root program based on CVE-2016-5195, that works on the old 'PlayStation Certified' android devices
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir ↗GitHub PoC
ishwardeepp/CVE-2025-22604-Cacti-RCE
Cacti has Authenticated RCE via multi-line SNMP responses
48RISCO
abrir ↗GitHub PoC★ 2
CVE-2024-51788 - WordPress The Novel Design Store Directory plugin <= 4.3.0 - Unauthenticated Arbitrary File Upload Vulnerability
WordPress The Novel Design Store Directory plugin <= 4.3.0 - Arbitrary File Upload vulnerability
48RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.