Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.760exploits catalogados
32.083CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 19.934GitHub PoC 13.235VulnCheck XDB 8.150Nuclei 4.193Metasploit 3.462✓ só verificadosrecentespopularesrisco
13.235 exploits
GitHub PoC
androidteacher/CVE-2024-50498-wpquery
WordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability
75RISCO
abrir ↗GitHub PoC★ 1
0xLittleSpidy/CVE-2025-54309
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RISCO
abrir ↗GitHub PoC
Sn0wBaall/CVE-2024-23334-PoC
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISCO
abrir ↗GitHub PoC
Looking at current high-impact vulnerabilities, let's use the VMware vCenter Server CVE-2021-21972 (CVSS 9.8) as our base. This is a publicly known RCE with patches available, perfect for demonstrating CTT enhancements.
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir ↗GitHub PoC
An advanced exploit for Microsoft Exchange Server (CVE-2021-26855, CVE-2021-27065) enhanced with Convergent Time Theory principles, achieving near-perfect theoretical rating through quantum temporal resonance and α-dispersion techniques.
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC★ 6
This is a security exploit tool targeting CVE-2025-55182. It exploits a Remote Code Execution (RCE) vulnerability in React Server Components
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗GitHub PoC
CVE-2025-24893 | Vulnérabilité d'exécution de code à distance sur la plateforme XWiki (preuve de concept)
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir ↗GitHub PoC
🔍 Analyze WebKit and ANGLE vulnerabilities with this repository for CVE-2025-43529 and CVE-2025-14174, focusing on verified components and ongoing efforts.
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
71RISCO
abrir ↗GitHub PoC
afifudinmtop/CVE-2009-3103
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RISCO
abrir ↗GitHub PoC★ 1
A Proof of Concept for CVE-2025-29927 demonstrating a middleware bypass in Next.js versions prior to 13.5.9
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗GitHub PoC
Spring Cloud Gateway SpEL RCE Vulnerability Environment
Spring Expression Language property modification using Spring Cloud Gateway Server WebFlux
63RISCO
abrir ↗GitHub PoC
Python demo simulating CVE-2024-3094: a supply chain backdoor in XZ Utils with a trigger-based stealth activation.
Xz: malicious code in distributed source
70RISCO
abrir ↗GitHub PoC★ 4
POC (RCE) -> CVE-2019-9978
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir ↗GitHub PoC
Baza-NATO/CVE-2021-33044
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISCO
abrir ↗GitHub PoC
CVE-2025-60021
Apache bRPC: Remote command injection vulnerability in heap builtin service
53RISCO
abrir ↗GitHub PoC
CVE-2025-64155
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
60RISCO
abrir ↗GitHub PoC
dionissh/CVE-2024-21413
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC★ 2
CVE-2015-2291 Local Privilege Escalation PoC
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows all
71RISCO
abrir ↗GitHub PoC
jagg3rsec/CVE-2014-6287
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir ↗GitHub PoC
ranasen-rat/cve-2021-42013
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir ↗GitHub PoC
xitexploiter96-dot/CVE-2023-38408
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISCO
abrir ↗GitHub PoC
For HTB practice
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISCO
abrir ↗GitHub PoC★ 1
A secure, zero-trust database management tool for WordPress. Fixes critical SSRF vulnerabilities (CVE-2021-21311) by enforcing local connections only.
SSRF in adminer
100RISCO
abrir ↗GitHub PoC
Replica of CVE-2019-15715 in Python3
MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.
35RISCO
abrir ↗GitHub PoC★ 2
The Kubio AI Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.5.1 via the `kubio_hybrid_theme_load_template` function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files..
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISCO
abrir ↗GitHub PoC
CVE-2025-52691 PoC: Based on watchtowr's article WT-2026-0001 about an authentication bypass exploit, this one is a functional Python attack script.
Upload Arbitrary Files
100RISCO
abrir ↗GitHub PoC★ 2
Sairbo/Unihackers---CVE-2025-55182-
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗GitHub PoC★ 1
Unauthenticated 0-click RCE exploit for CVE-2024-51793. Exploits an arbitrary file upload vulnerability via admin-ajax.php to upload a PHP payload and achieve remote command execution on vulnerable WordPress installations, including OS detection and an interactive command shell.
WordPress RepairBuddy plugin <= 3.8115 - Arbitrary File Upload vulnerability
48RISCO
abrir ↗GitHub PoC
Self-contained exploit for CVE-2021-4034 - Pkexec Local Privilege Escalation
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir ↗GitHub PoC★ 2
Unauthenticated 0-click RCE exploit for CVE-2024-9932. Exploits an arbitrary file upload vulnerability in the Wux Blog Editor WordPress plugin to upload a remote PHP payload, detect the target operating system, and achieve remote command execution through an interactive web shell.
Wux Blog Editor <= 3.0.0 - Unauthenticated Arbitrary File Upload
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.