Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.646exploits catalogados
37.382CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.482Referência 23.825GitHub PoC 15.392VulnCheck XDB 9.029Nuclei 4.416Metasploit 3.502✓ só verificadosrecentespopularesrisco
15.392 exploits
GitHub PoC
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
75RISCO
abrir ↗GitHub PoC★ 1
bsec404/CVE-2020-0796
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir ↗GitHub PoC★ 11
A comprehensive all-in-one Python-based Proof of Concept script to discover and exploit a critical authentication bypass vulnerability (CVE-2024-55591) in certain Fortinet devices.
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISCO
abrir ↗GitHub PoC★ 1
A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.
Rsync: heap buffer overflow in rsync due to improper checksum length handling
70RISCO
abrir ↗GitHub PoC★ 2
Ivanti Connect Secure, Policy Secure & ZTA Gateways - CVE-2025-0282
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RISCO
abrir ↗GitHub PoC★ 3
watchtowrlabs/nakivo-arbitrary-file-read-poc-CVE-2024-48248
NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /
100RISCO
abrir ↗GitHub PoC★ 289
针对JWT渗透开发的漏洞验证/密钥爆破工具,针对CVE-2015-9235/空白密钥/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ,也可使用字典/字符枚举(包括JJWT)的方式进行爆破(JWT Crack)
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISCO
abrir ↗GitHub PoC★ 77
watchtowrlabs/fortios-auth-bypass-poc-CVE-2024-55591
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISCO
abrir ↗GitHub PoC
A rewrite of the Polkit vulnerability.
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir ↗GitHub PoC★ 1
7-Zip Mark-of-the-Web绕过漏洞PoC(CVE-2025-0411)
7-Zip Mark-of-the-Web Bypass Vulnerability
83RISCO
abrir ↗GitHub PoC
Repository for internship test task.
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir ↗GitHub PoC★ 1
CVE-2016-2555 Exploit
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbi
60RISCO
abrir ↗GitHub PoC★ 4
Exploit for WordPress File Upload Plugin - All versions up to 4.24.11 are vulnerable.
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
85RISCO
abrir ↗GitHub PoC★ 1
Proof of Concept for CVE-2024-45337 against Gitea and Forgejo
Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
48RISCO
abrir ↗GitHub PoC
This repository contains informaion about the Fortigate firewall vulnerability (CVE-2022-40684) and affected data that were publicly disclosed by the Belsen Group. This information is being shared for security research and defensive purposes to help organizations identify if they were impacted.
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir ↗GitHub PoC★ 1
CVE-2024-3673 Exploit: Local File Inclusion in Web Directory Free WordPress Plugin ( before 1.7.3 )
Web Directory Free < 1.7.3 - Unauthenticated LFI
63RISCO
abrir ↗GitHub PoC★ 1
Exploit for CVE-2023-4220
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir ↗GitHub PoC
CVE-2017-7921 exploit. Allows admin password retrieval and automatic snapshot download.
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISCO
abrir ↗GitHub PoC★ 8
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS and FortiProxy may allow a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISCO
abrir ↗GitHub PoC★ 1
Course Booking System <= 6.0.5 - Unauthenticated SQL Injection
WordPress Course Booking System plugin <= 6.0.6 - SQL Injection vulnerability
63RISCO
abrir ↗GitHub PoC
CVE-2024-38077-POC
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC★ 2
ExploitDB CVE-2024-50379 a vulnerability that enables attackers to upload a JSP shell to a vulnerable server and execute commands remotely. The exploit is especially effective when the /uploads directory is either unprotected or missing on the target server.
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RISCO
abrir ↗GitHub PoC★ 1
XalfiE/Fortigate-Belsen-Leak-Dump-CVE-2022-40684-
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir ↗GitHub PoC★ 2
Exploit for CVE-2025-0282: A remote unauthenticated stack based buffer overflow affecting Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA gateways
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RISCO
abrir ↗GitHub PoC★ 3
sysirq/fortios-auth-bypass-exploit-CVE-2024-55591
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISCO
abrir ↗GitHub PoC
Exploit for CVE-2024-53704 - SonicWall SonicOS SSLVPN authentication bypass
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe
100RISCO
abrir ↗GitHub PoC★ 155
This repository contains POC scenarios as part of CVE-2025-0411 MotW bypass.
7-Zip Mark-of-the-Web Bypass Vulnerability
83RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.