Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.064exploits catalogados
37.667CVEs com exploração pública
24.695testados em laboratório
80.930 exploits
GitHub PoC1
Fix for undefined method each in Metasploit’s bailiwicked_domain.rb (CVE-2008-1447 DNS cache poisoning module)
CVE-2008-144722 ago 2025
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windo
60RISCO
abrir
GitHub PoC
Explotación vulnerabilidad Dirty COW (CVE-2016-5195) en Ubuntu 16.04.1.
CVE-2016-5195HIGHsob ataque22 ago 2025
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC1
CVE-2023-35078 - Ivanti MobileIron Core Remote Unauthenticated API Access Exploit tool
CVE-2023-35078CRITICALsob ataqueransomware21 ago 2025
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RISCO
abrir
GitHub PoC
Customized this for my own use
CVE-2023-41892CRITICAL21 ago 2025
Craft CMS Remote Code Execution vulnerability
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-41892CRITICAL21 ago 2025
Craft CMS Remote Code Execution vulnerability
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2015-835121 ago 2025
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_includ
35RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-3721MEDIUM21 ago 2025
TBK DVR-4104/DVR-4216 os command injection
55RISCO
abrir
GitHub PoC
This PoC is for authorized study and testing. CVE-2025-8088 is actively exploited, and misuse may violate laws or cause harm. Update to WinRAR 7.13+ to avoid suspicious RARs.
CVE-2025-8088HIGHsob ataqueransomware21 ago 2025
Path traversal vulnerability in WinRAR
93RISCO
abrir
GitHub PoC
Exploit code for CVE-2015-8351
CVE-2015-835121 ago 2025
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_includ
35RISCO
abrir
GitHub PoC3
A Windows GUI tool demonstrating a proof-of-concept archive traversal technique related to CVE-2025-8088 using WinRAR’s CLI. Allows building crafted RAR files with payload + decoy files through an easy modern interface. For educational and security-research purposes only.
CVE-2025-8088HIGHsob ataqueransomware20 ago 2025
Path traversal vulnerability in WinRAR
93RISCO
abrir
Metasploit300
Elasticsearch ingest-attachment Apache Tika XFA XXE Local File Read
CVE-2025-66516HIGH20 ago 2025
Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected
58RISCO
abrir
Metasploit300
Elasticsearch ingest-attachment Apache Tika XFA XXE Local File Read
CVE-2025-54988HIGH20 ago 2025
Apache Tika PDF parser module: XXE vulnerability in PDFParser's handling of XFA
48RISCO
abrir
GitHub PoC
Ianthinus/CVE-2024-4577
CVE-2024-4577CRITICALsob ataqueransomware20 ago 2025
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
shoucheng3/jmrozanec__cron-utils_CVE-2021-41269_9-1-5
CVE-2021-41269CRITICAL20 ago 2025
Unauthenticated remote code injection in cron-utils
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALsob ataqueransomware20 ago 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
VulnCheck XDB
local
CVE-2016-666220 ago 2025
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RISCO
abrir
GitHub PoC
shoucheng3/asf__commons-text_CVE-2022-42889_1-9
CVE-2022-4288920 ago 2025
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC
This repository showcases a fully self-developed Proof-of-Concept (PoC) for CVE-2018-7600, widely known as Drupalgeddon 2. This critical vulnerability in Drupal 7 and 8 core enables remote code execution (RCE), and the PoC demonstrates its exploitation in a clear and educational manner.
CVE-2018-7600CRITICALsob ataqueransomware20 ago 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC1
The objective is to conduct a full-scale security assessment of a WordPress-based web application, culminating in a complete server compromise. The assessment will focus on exploiting a specific, real-world vulnerability (CVE-2021-29447) to achieve initial access.
CVE-2021-29447HIGH20 ago 2025
WordPress Authenticated XXE attack when installation is running PHP 8
63RISCO
abrir
GitHub PoC
Sheep-Hunter/CVE-2025-5777-POC
CVE-2025-5777CRITICALsob ataqueransomware20 ago 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
GitHub PoC
shoucheng3/spring-projects__spring-framework_CVE-2022-22965_5-2-19-RELEASE
CVE-2022-22965CRITICALsob ataque20 ago 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC3
Exploit for CVE-2025-5777: Citrix NetScaler Memory Disclosure (CitrixBleed 2)
CVE-2025-5777CRITICALsob ataqueransomware20 ago 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-48384HIGHsob ataque20 ago 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-54782CRITICAL20 ago 2025
@nestjs/devtools-integration's CSRF to Sandbox Escape Allows for RCE against JS Developers
75RISCO
abrir
GitHub PoC
shoucheng3/apache__flink_CVE-2020-17519_1-11-2
CVE-2020-17519CRITICALsob ataque20 ago 2025
Apache Flink directory traversal attack: reading remote files through the REST API
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALsob ataqueransomware20 ago 2025
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
shoucheng3/spring-cloud__spring-cloud-gateway_CVE-2022-22947_3-0-6
CVE-2022-22947CRITICALsob ataque20 ago 2025
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISCO
abrir
GitHub PoC
replicatorbot/CVE-2025-48384-POC
CVE-2025-48384HIGHsob ataque20 ago 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC
replicatorbot/CVE-2025-48384
CVE-2025-48384HIGHsob ataque20 ago 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC
harshitvarma05/CVE-2025-31324-Exploits
CVE-2025-31324CRITICALsob ataqueransomware20 ago 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISCO
abrir
anteriorpágina 281 / 2.698próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.