Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
71.760exploits catalogados
32.083CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 19.934GitHub PoC 13.235VulnCheck XDB 8.150Nuclei 4.193Metasploit 3.462✓ só verificadosrecentespopularesrisco
13.235 exploits
GitHub PoC★ 3
CVE-2025-52694 Critical SQL Injection in Advantech IoTSuite/SaaS-Composer
Execution of arbitrary SQL commands
75RISCO
abrir ↗GitHub PoC
posix sh poc for CVE-2009-2265 (deps: curl,msfvenom,uuidgen,tr)
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RISCO
abrir ↗GitHub PoC
Technical analysis and reproduction lab for the Apache HTTP Server 2.4.49 Path Traversal and RCE vulnerability.
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗GitHub PoC★ 2
CVE-2025-55182漏洞检测工具
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗GitHub PoC
sahar042/CVE-2025-14847
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir ↗GitHub PoC★ 1
Defensive PowerShell tool for static inspection of RAR archives and detection of CVE-2025-8088 path traversal anomalies.
Path traversal vulnerability in WinRAR
93RISCO
abrir ↗GitHub PoC
js2py <= 0.74 sandbox escape (CVE-2024-28397)
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISCO
abrir ↗GitHub PoC★ 1
PoC Authentication Bypass to RCE to Exploit CVE-2025-31161
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISCO
abrir ↗GitHub PoC
comerc/CVE-2025-68664
LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
53RISCO
abrir ↗GitHub PoC
Secure fork of Startklar Elementor Addons. Patched CVE-2024-5153 & File Upload vulnerabilities.
Startklar Elementor Addons <= 1.7.15 - Unauthenticated Path Traversal to Arbitrary Directory Deletion
48RISCO
abrir ↗GitHub PoC★ 2
A security-hardened fork of "Simply Show Hooks". Replaces the compromised original (CVE-2024-6297) and patches unlisted Cross-Site Scripting (XSS) vulnerabilities.
Several WordPress.org Plugins <= Various Versions - Injected Backdoor
48RISCO
abrir ↗GitHub PoC
Original security research into container boundary weaknesses. Published: OCI hook privilege escalation in rootless Podman deployments (CVE-2025-23266).
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, wher
48RISCO
abrir ↗GitHub PoC
mooowu/cve-2025-55182-poc
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗GitHub PoC
Full-lifecycle penetration test of a legacy Linux environment (Metasploitable 2) emulated on Apple Silicon. Demonstrating network reconnaissance, RCE via service backdoors (CVE-2011-2523), and cryptographic credential recovery.
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir ↗GitHub PoC★ 1
CVE-2015-3224 Exploit - Rails Web Console RCE
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-
50RISCO
abrir ↗GitHub PoC
CVE-2023-38831 - WinRAR
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir ↗GitHub PoC★ 1
Two POCs I created for the CVE-2023-23397 Outlook NTLM vulnerability, to be used internally.
Microsoft Outlook Elevation of Privilege Vulnerability
100RISCO
abrir ↗GitHub PoC
A drop-in fix for CVE-2023-29689 - SSTI in PyroCMS, via a custom Twig Sandbox implementation
PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template in
35RISCO
abrir ↗GitHub PoC★ 1
CVE-2025-14847 explaination and lab
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir ↗GitHub PoC
Unauthenticated RCE exploit for XWiki CVE-2025-24893 via Groovy script injection
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir ↗GitHub PoC★ 1
Crime2/poc-CVE-2025-38352
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
71RISCO
abrir ↗GitHub PoC
alxsourin/Helpdesk-Telecom-CVE-2025-64459
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RISCO
abrir ↗GitHub PoC
Authenticated RCE for Webmin 1.9.0
Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Dow
43RISCO
abrir ↗GitHub PoC★ 19
watchtowrlabs/watchTowr-vs-SmarterMail-CVE-2025-52691
Upload Arbitrary Files
100RISCO
abrir ↗GitHub PoC★ 1
flame-11/CVE-2025-54068-livewire
Livewire vulnerable to remote command execution during property update hydration
100RISCO
abrir ↗GitHub PoC★ 24
CVE-2025-68428 Proof of Concept
jsPDF has Local File Inclusion/Path Traversal vulnerability
48RISCO
abrir ↗GitHub PoC
CVE-2025-14847 PoC exploit for MongoDB heap memory disclosure
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir ↗GitHub PoC★ 31
CVE-2025-55182-bypass-waf
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.