Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
81.524exploits catalogados
37.962CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.482Referência 24.284GitHub PoC 15.675VulnCheck XDB 9.136Nuclei 4.441Metasploit 3.506✓ só verificadosrecentespopularesrisco
81.524 exploits
Exploit-DB
NEWS-BUZZ News Management System 1.0 - SQL Injection
code-projects/anirbandutta9 Content Management System/News-Buzz index.php sql injection
33RISCO
abrir ↗GitHub PoC★ 3
Exploit PoC for CVE-2023-20198
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISCO
abrir ↗Exploit-DB
CyberPanel 2.3.6 - Remote Code Execution (RCE)
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
100RISCO
abrir ↗Exploit-DB
MagnusSolution magnusbilling 7.3.0 - Command Injection
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISCO
abrir ↗Exploit-DB
phpIPAM 1.6 - Reflected Cross Site Scripting (XSS)
phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter
48RISCO
abrir ↗VulnCheck XDB
initial-access
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir ↗GitHub PoC
ngyinkit/cve-2019-18634
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISCO
abrir ↗VulnCheck XDB
initial-access
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir ↗Exploit-DB
GeoVision GV-ASManager 6.1.0.0 - Broken Access Control
Broken access control vulnerability in Geovision GV-ASWeb with version v6.1.0.0 or less. This vulnerability allows low p
41RISCO
abrir ↗VulnCheck XDB
initial-access
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir ↗GitHub PoC★ 11
A vulnerability scanner for CVE-2025-3248 in Langflow applications. 用于扫描 Langflow 应用中 CVE-2025-3248 漏洞的工具。
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir ↗GitHub PoC★ 3
POC of CVE-2025-3248, RCE of LangFlow
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir ↗VulnCheck XDB
initial-access
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗VulnCheck XDB
initial-access
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir ↗VulnCheck XDB
initial-access
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir ↗GitHub PoC★ 3
CVE-2019-15107-Scanner is a Python-based scanner that detects vulnerable Webmin (1.890 - 1.920) servers affected by CVE-2019-15107, an unauthenticated remote code execution (RCE) vulnerability in the /password_change.cgi endpoint.
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir ↗Exploit-DB
Typecho 1.3.0 - Race Condition
Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. This vulnerabil
33RISCO
abrir ↗GitHub PoC★ 18
CVE-2025-22457: Python Exploit POC Scanner to Detect Ivanti Connect Secure RCE
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7
100RISCO
abrir ↗GitHub PoC★ 2
Unverified Password Change (CWE-620)
A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to c
53RISCO
abrir ↗GitHub PoC★ 9
CVE-2025-24813 poc
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗VulnCheck XDB
denial-of-service
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7
100RISCO
abrir ↗Exploit-DB
CodeAstro Online Railway Reservation System 1.0 - Cross Site Scripting (XSS)
CodeAstro Online Railway Reservation System Update Employee Page admin-update-employee.php cross site scripting
33RISCO
abrir ↗Exploit-DB
Centron 19.04 - Remote Code Execution (RCE)
Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitra
35RISCO
abrir ↗VulnCheck XDB
initial-access
A potential security vulnerability has been identified in Hewlett Packard Enterprise OfficeConnect 1820, 1850, and 1920S
56RISCO
abrir ↗Exploit-DB
flatCore 1.5.5 - Arbitrary File Upload
An issue was discovered in flatCore 1.4.7. acp/acp.php allows remote authenticated administrators to upload arbitrary .p
23RISCO
abrir ↗GitHub PoC
Exploit CVE-2025-69985 to bypass authentication and execute remote commands on FUXA versions ≤ 1.2.8 via the /api/runscript endpoint.
FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnera
48RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.