Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
71.957 exploits
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL10 fev 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL10 fev 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-6019HIGH10 fev 2026
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware10 fev 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-6019HIGH10 fev 2026
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RISCO
abrir
GitHub PoC1
George0Papasotiriou/CVE-2025-61882-Oracle-BI-Publisher-RCE
CVE-2025-61882CRITICALsob ataqueransomware10 fev 2026
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integratio
100RISCO
abrir
GitHub PoC1
George0Papasotiriou/CVE-2025-59470-PostgreSQL-Command-Injection
CVE-2025-59470CRITICAL10 fev 2026
This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a mal
48RISCO
abrir
GitHub PoC1
George0Papasotiriou/CVE-2025-15556-Notepad-WinGUp-Updater-RCE
CVE-2025-15556HIGHsob ataque10 fev 2026
Notepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verification
71RISCO
abrir
GitHub PoC3
CVE-2025-54253 | CVE-2025-54254 | Adobe Experience Manager Forms XXE → RCE Framework
CVE-2025-54253CRITICALsob ataque10 fev 2026
Adobe Experience Manager | Incorrect Authorization (CWE-863)
100RISCO
abrir
GitHub PoC
Laboratorio criado para PenTest da Vuln CVE 2024-214113(MONIKER LINK).
CVE-2024-21413CRITICALsob ataque10 fev 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC1
Enumeration tool for CVE-2024-45440
CVE-2024-45440MEDIUM10 fev 2026
core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash
48RISCO
abrir
GitHub PoC
bixiPRO/Drupalgeddon2-CVE-2018-7600
CVE-2018-7600CRITICALsob ataqueransomware10 fev 2026
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC1
George0Papasotiriou/CVE-2025-8110-Gogs-Remote-Code-Execution
CVE-2025-8110HIGHsob ataque10 fev 2026
File overwrite in file update API in Gogs
100RISCO
abrir
GitHub PoC3
George0Papasotiriou/CVE-2025-14174-Chrome-Zero-Day
CVE-2025-14174HIGHsob ataque10 fev 2026
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perfor
76RISCO
abrir
GitHub PoC1
CVE-2025-49132: Pterodactyl Panel UnauthN LFI to RCE (w/ pearcmd) in posix sh
CVE-2025-49132CRITICAL10 fev 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISCO
abrir
GitHub PoC1
George0Papasotiriou/CVE-2025-55182-React2Shell-CVSS-10.0-
CVE-2025-55182CRITICALsob ataqueransomware10 fev 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
RCE on Next 16.0.6
CVE-2025-55182CRITICALsob ataqueransomware10 fev 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-36847CRITICAL10 fev 2026
Simple File List < 4.2.3 - Remote Code Execution
68RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2023-44487HIGHsob ataque10 fev 2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-3408510 fev 2026
35RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-1254209 fev 2026
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RISCO
abrir
GitHub PoC
Proof-of-concept exploit for CVE-2017-12542, an authentication bypass vulnerability in HP iLO. Allows vulnerability detection and unauthorized account creation on affected systems
CVE-2017-1254209 fev 2026
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RISCO
abrir
GitHub PoC1
An exploitation tool for the Next.js vulnerability CVE-2025-55182 that allows remote command execution through a poisoning prototype in React Server Components.
CVE-2025-55182CRITICALsob ataqueransomware09 fev 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
ISabbiI/PoC---CVE-2023-26482-RCE-LAB-Nextcloud
CVE-2023-26482CRITICAL09 fev 2026
Scope of workflow operations is not validated in nextcloud server
63RISCO
abrir
VulnCheck XDB
local
CVE-2025-6019HIGH09 fev 2026
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-7921CRITICALsob ataque09 fev 2026
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL09 fev 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-6019HIGH09 fev 2026
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-55182CRITICALsob ataqueransomware09 fev 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-6019HIGH09 fev 2026
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RISCO
abrir
anteriorpágina 119 / 2.399próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.