Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
81.524exploits catalogados
37.962CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.482Referência 24.284GitHub PoC 15.675VulnCheck XDB 9.136Nuclei 4.441Metasploit 3.506✓ só verificadosrecentespopularesrisco
81.524 exploits
GitHub PoC
vances25/CVE-2024-44871
An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute a
46RISCO
abrir ↗VulnCheck XDB
infoleak
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir ↗VulnCheck XDB
client-side
The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18
76RISCO
abrir ↗GitHub PoC
WHS 3기 장대혁 취약한(CVE) Docker 환경 구성 과제입니다.
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir ↗GitHub PoC
d0x-awrqxavc/-CVE-2024-10924
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir ↗GitHub PoC★ 8
Next.js Middleware Bypass Scanne
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC
VVeakee/CVE-2024-4367
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir ↗Exploit-DB
Watcharr 1.43.0 - Remote Code Execution (RCE)
An issue in sbondCo Watcharr v.1.43.0 allows a remote attacker to execute arbitrary code and escalate privileges via the
41RISCO
abrir ↗GitHub PoC★ 33
Simulated PoC for CVE-2025-2783 — a sandbox escape vulnerability in Chrome's Mojo IPC. Includes phishing delivery, memory fuzzing, IPC simulation, and logging. Safe for red team demos, detection engineering, and educational use.
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
71RISCO
abrir ↗VulnCheck XDB
initial-access
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISCO
abrir ↗GitHub PoC
A POC lab environment for CVE-2024-56145 CraftCMS RCE.
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
100RISCO
abrir ↗GitHub PoC★ 1
cybermads/CVE-2011-2523
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir ↗Exploit-DB
Reservit Hotel 2.1 - Stored Cross-Site Scripting (XSS)
Reservit Hotel < 3.0 - Admin+ Stored XSS
33RISCO
abrir ↗GitHub PoC★ 2
CVE-2025-24813-POC JSP Web Shell Uploader
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗GitHub PoC★ 3
WordPress FEUP Arbitrary File Upload Exploit (CVE-2025-2005)
Front-End-Only-Users <= 3.2.32 - Unauthenticated Arbitrary File Upload
53RISCO
abrir ↗GitHub PoC
Koray123-debug/CVE-2024-34102
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir ↗GitHub PoC
vulnerable-nextjs-14-CVE-2025-29927
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗Exploit-DB
Backup and Staging by WP Time Capsule 1.22.21 - Unauthenticated Arbitrary File Upload
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RISCO
abrir ↗Exploit-DB
DataEase 2.4.0 - Database Configuration Information Exposure
DataEase has database configuration information exposure vulnerability
53RISCO
abrir ↗Exploit-DB
Palo Alto Networks Expedition 1.2.90.1 - Admin Account Takeover
Expedition: Missing Authentication Leads to Admin Account Takeover
100RISCO
abrir ↗GitHub PoC★ 1
Vite-CVE-2025-30208-EXP单目标检测,支持自定义读取路径,深度检索
Vite bypasses server.fs.deny when using `?raw??`
70RISCO
abrir ↗GitHub PoC
CVE-2025-30065 PoC
Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
60RISCO
abrir ↗GitHub PoC★ 2
Vulnerability assessment and exploitation of vsftpd 2.3.4 (CVE-2011-2523) using Metasploit. Full report and proof of root access included.
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir ↗Exploit-DB
Exclusive Addons for Elementor 2.6.9 - Stored Cross-Site Scripting (XSS)
Exclusive Addons for Elementor <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
33RISCO
abrir ↗Exploit-DB
Microchip TimeProvider 4100 Grandmaster (Data plot modules) 2.4.6 - SQL Injection
SQL injection in get_chart_data in TimeProvider 4100
33RISCO
abrir ↗Exploit-DB
Royal Elementor Addons and Templates 1.3.78 - Unauthenticated Arbitrary File Upload
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RISCO
abrir ↗VulnCheck XDB
initial-access
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.