Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.646exploits catalogados
37.382CVEs com exploração pública
24.695testados em laboratório
15.392 exploits
GitHub PoC232
POC exploit for CVE-2025-21333 heap-based buffer overflow. It leverages WNF state data and I/O ring IOP_MC_BUFFER_ENTRY
CVE-2025-21333HIGHsob ataque27 fev 2025
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RISCO
abrir
GitHub PoC1
skrkcb2/CVE-2023-46604
CVE-2023-46604CRITICALsob ataqueransomware27 fev 2025
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISCO
abrir
GitHub PoC6
CVE-2025-26263 - GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less, is vulnerable to credentials disclosure due to improper memory handling in the ASManagerService.exe process.
CVE-2025-26263MEDIUM26 fev 2025
GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to cred
33RISCO
abrir
GitHub PoC
SpiX-7/CVE-2024-24919-POC
CVE-2024-24919HIGHsob ataqueransomware26 fev 2025
Information disclosure
100RISCO
abrir
GitHub PoC7
CVE-2025-26264 - GeoVision GV-ASWeb with the version 6.1.2.0 or less, contains a Remote Code Execution (RCE) vulnerability within its Notification Settings feature. An authenticated attacker with "System Settings" privileges in ASWeb can exploit this flaw to execute arbitrary commands on the server, leading to a full system compromise.
CVE-2025-26264HIGH26 fev 2025
GeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), contains a Remote Code Execution (RCE) vulnerabili
46RISCO
abrir
GitHub PoC
monjheta/CVE-2020-0796
CVE-2020-0796CRITICALsob ataqueransomware26 fev 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC
Automation script to exploit the Shellshock vulnerability.
CVE-2014-6271CRITICALsob ataque26 fev 2025
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC
cojoben/CVE-2018-13382
CVE-2018-13382CRITICALsob ataqueransomware26 fev 2025
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti
100RISCO
abrir
GitHub PoC
A Rust exploit for CVE-2024-23346 that functions as a "terminal" (tested on chemistry.htb)
CVE-2024-23346CRITICAL25 fev 2025
pymatgen arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
48RISCO
abrir
GitHub PoC21
JSONPath-plus Remote Code Execution
CVE-2025-1302CRITICAL25 fev 2025
Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input
68RISCO
abrir
GitHub PoC3
WP Load Gallery <= 2.1.6 - Authenticated (Author+) Arbitrary File Upload
CVE-2025-23942CRITICAL25 fev 2025
WordPress WP Load Gallery Plugin <= 2.1.6 - Arbitrary File Upload vulnerability
48RISCO
abrir
GitHub PoC10
XWiki SolrSearchMacros 远程代码执行漏洞PoC(CVE-2025-24893)
CVE-2025-24893CRITICALsob ataque25 fev 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC3
shishirghimir/CVE-2024-53677-Exploit
CVE-2024-53677CRITICAL24 fev 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir
GitHub PoC4
numanturle/CVE-2025-25279
CVE-2025-25279CRITICAL24 fev 2025
Arbitrary file read in Mattermost Boards via import & export board archive
53RISCO
abrir
GitHub PoC
vivigotnotime/CVE-2023-22515-Exploit-Script
CVE-2023-22515CRITICALsob ataqueransomware24 fev 2025
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISCO
abrir
GitHub PoC1
Copy of the POC for CVE-2023-1545
CVE-2023-1545HIGH24 fev 2025
SQL Injection in nilsteampassnet/teampass
41RISCO
abrir
GitHub PoC
Code to exploit CVE-2021-4034
CVE-2021-4034HIGHsob ataqueransomware24 fev 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC2
cesarbtakeda/7-Zip-CVE-2025-0411-POC
CVE-2025-0411HIGHsob ataque23 fev 2025
7-Zip Mark-of-the-Web Bypass Vulnerability
83RISCO
abrir
GitHub PoC
WinVerifyTrust Signature Validation CVE-2013-3900 Mitigation (EnableCertPaddingCheck)
CVE-2013-3900MEDIUMsob ataque23 fev 2025
WinVerifyTrust Signature Validation Vulnerability
75RISCO
abrir
GitHub PoC1
WordPress CVE-2024-10924 Exploit for Really Simple Security plugin
CVE-2024-10924CRITICAL23 fev 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir
GitHub PoC
Example usage: exploit.sh http://site.com
CVE-2023-1545HIGH22 fev 2025
SQL Injection in nilsteampassnet/teampass
41RISCO
abrir
GitHub PoC4
CVE-2023-1698 Proof of Concept (PoC)
CVE-2023-1698CRITICAL21 fev 2025
WAGO: WBM Command Injection in multiple products
85RISCO
abrir
GitHub PoC1
funixone/CVE-2024-24919---Exploit-Script
CVE-2024-24919HIGHsob ataqueransomware21 fev 2025
Information disclosure
100RISCO
abrir
GitHub PoC1
CVE-2025-24016: RCE in Wazuh server! Remote Code Execution
CVE-2025-24016CRITICALsob ataque21 fev 2025
Remote code execution in Wazuh server
100RISCO
abrir
GitHub PoC5
CVE-2025-24016: RCE in Wazuh server! Remote Code Execution
CVE-2025-24016CRITICALsob ataque20 fev 2025
Remote code execution in Wazuh server
100RISCO
abrir
GitHub PoC
CVE-2025-24971 exploit
CVE-2025-24971CRITICAL20 fev 2025
OS Command Injection endpoint '/upload/init' parameter 'filename' (RCE) in DumpDrop
48RISCO
abrir
GitHub PoC2
PoC of the vulnerability CVE-2024-23346
CVE-2024-23346CRITICAL20 fev 2025
pymatgen arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
48RISCO
abrir
GitHub PoC
anu
CVE-2024-1651CRITICAL20 fev 2025
Torrentpier 2.4.1 - RCE
60RISCO
abrir
GitHub PoC
A fully functional exploit for a stack-based buffer overflow vulnerability in VideoLan’s VLC Media Player 0.9.4 when processing TiVo files.
CVE-2008-465419 fev 2025
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RISCO
abrir
GitHub PoC
Exploit hecho en python para vsftpd 2.3.4 | CVE-2011-2523
CVE-2011-252319 fev 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
anteriorpágina 228 / 514próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.