Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.646exploits catalogados
37.382CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.482Referência 23.825GitHub PoC 15.392VulnCheck XDB 9.029Nuclei 4.416Metasploit 3.502✓ só verificadosrecentespopularesrisco
15.392 exploits
GitHub PoC
CVE-2016-6914-UniFiVideo-LPE
Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local u
23RISCO
abrir ↗GitHub PoC★ 4
huseyinstif/CVE-2025-24016-Nuclei-Template
Remote code execution in Wazuh server
100RISCO
abrir ↗GitHub PoC★ 32
Palo Alto Networks PAN-OS 身份验证绕过漏洞批量检测脚本(CVE-2025-0108)
PAN-OS: Authentication Bypass in the Management Web Interface
100RISCO
abrir ↗GitHub PoC★ 2
POC for Roundcube vulnerabilities CVE-2024-42008 and CVE-2024-42010
A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7
60RISCO
abrir ↗GitHub PoC
Apache Struts CVE-2024-53677 Exploitation
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir ↗GitHub PoC
An unauthenticated attacker can force server points to a shell file like ‘/bin/sh’ and execute arbitrary commands due to the failure in verifying the URL which leads to path traversal to any file that exists in the system. Nostromo’s versions such as 1.9.6 fail to verify this URL
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISCO
abrir ↗GitHub PoC
Active Exploitation of Atlassian’s Questions for Confluence App CVE-2022-26134
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir ↗GitHub PoC
qnole000/CVE-2024-51378
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
100RISCO
abrir ↗GitHub PoC
Modified exploit for CVE-2021-43798 compatible with both Windows and Linux hosts.
Grafana path traversal
100RISCO
abrir ↗GitHub PoC★ 1
yenyangmjaze/cve-2024-10914
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir ↗GitHub PoC★ 1
Exploit for Apache OFBiz - CVE-2024-38856
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISCO
abrir ↗GitHub PoC★ 2
demonstriert, wie mittels missbräuchlicher Nutzung eines Swap-Cookies eine VPN-Session übernommen werden kann. Wichtig: Dieses Projekt dient ausschliesslich zu Bildungs- und Forschungszwecken – bitte nur in Umgebungen verwenden, in denen Du explizit authorisiert bist.
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe
100RISCO
abrir ↗GitHub PoC
Alienfader/CVE-2020-29607
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access
35RISCO
abrir ↗GitHub PoC★ 4
This script exploits a stored XSS vulnerability (CVE-2024-42009) in Roundcube Webmail version 1.6.7. It injects a malicious payload into the webmail system, which, when triggered, exfiltrates email content from the victim’s inbox.
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RISCO
abrir ↗GitHub PoC★ 1
cve-2019-5420 POC simple ruby script
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISCO
abrir ↗GitHub PoC
This is a repository for Apache HugeGraph Remote Code Execution vulnerability(CVE-2024-27348))
Apache HugeGraph-Server: Command execution in gremlin
100RISCO
abrir ↗GitHub PoC
Yami0x777/Belsen_Group-et-exploitation-de-la-CVE-2022-40684
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir ↗GitHub PoC
skrkcb2/CVE-2024-5452
RCE via Property/Class Pollution in lightning-ai/pytorch-lightning
53RISCO
abrir ↗GitHub PoC★ 1
SSHEnum es una herramienta de enumeración de usuarios SSH basada en CVE-2018-15473. Permite detectar usuarios válidos aprovechando respuestas diferenciadas del servidor. Es rápida, compatible con Python 3.12 y soporta wordlists. Uso exclusivo para auditoría y pruebas de seguridad autorizadas.
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir ↗GitHub PoC
RogelioPumajulca/CVE-2022-0847
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir ↗GitHub PoC
0x7556/CVE-2024-55591
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISCO
abrir ↗GitHub PoC
pz-frontend-manager < 1.0.6 - CSRF Profile Picture Exploit
pz-frontend-manager < 1.0.6 - CSRF change user profile picture
41RISCO
abrir ↗GitHub PoC
This repository contains a Proof-of-Concept (PoC) exploit for the Baron Samedit vulnerability (CVE-2021-3156). The exploit demonstrates privilege escalation on Ubuntu 20.04 with sudo version 1.8.31 and glibc version 2.31. It includes an assembly-based exploit, a shared object payload, and a Makefile for automated compilation.
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir ↗GitHub PoC★ 4
Snizi/Moodle-CVE-2024-43425-Exploit
Moodle: remote code execution via calculated question types
78RISCO
abrir ↗GitHub PoC
PoC of CVE-2022-30190
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC★ 4
Cityworks deserialization of untrusted data vulnerability Detection
Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to
83RISCO
abrir ↗GitHub PoC★ 1
This is a Python script that exploits the CVE-2024-6624 vulnerability in the JSON API User <= 3.9.3 plugin for WordPress.
JSON API User <= 3.9.3 - Unauthenticated Privilege Escalation
48RISCO
abrir ↗GitHub PoC★ 4
Python script for CVE-2024-0012 / CVE-2024-9474 exploit
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISCO
abrir ↗GitHub PoC
Directory Traversal Exploit written in Bash for NVMS-1000 (CVE-2019-20085).
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RISCO
abrir ↗GitHub PoC★ 1
SOC287 - Arbitrary File Read on Checkpoint Security Gateway [CVE-2024-24919]
Information disclosure
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.