Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

72.018exploits catalogados
32.219CVEs com exploração pública
1.932testados em laboratório
72.018 exploits
GitHub PoC1
Final Project in Fundamental network security,POC CVE-202438063
CVE-2024-38063CRITICAL21 jan 2026
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC
nimesh895/Malware-Analysis-Follina-CVE-2022-30190
CVE-2022-30190HIGHsob ataqueransomware21 jan 2026
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALsob ataque21 jan 2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISCO
abrir
GitHub PoC
Vladjrfhfg/React-site-CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware20 jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
CVE-2025-55182(命令执行、反弹shell、注入内存马)
CVE-2025-55182CRITICALsob ataqueransomware20 jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
dragosbanica/CVE-2023-0386_POC
CVE-2023-0386HIGHsob ataque20 jan 2026
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISCO
abrir
GitHub PoC
This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.
CVE-2025-14847HIGHsob ataque20 jan 2026
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir
GitHub PoC
vsftpd 2.3.4 (CVE-2011-2523) a critical vulnerability that leads to Reverse Root Shell. In this repo I will do a PoC how to exploit it step by step, Manually & Automatically (Python) for educational purposes.
CVE-2011-252320 jan 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
GitHub PoC
SSP H3
CVE-2024-38063CRITICAL20 jan 2026
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC8
CVE-2026-23744 - Versions 1.4.2 and earlier of MCPJam inspector are vulnerable to remote code execution (RCE). Because the tool listens on 0.0.0.0 by default, an attacker can trigger the installation and execution of a malicious MCP server by sending a crafted HTTP request. Version 1.4.3 contains a patch for this issue.
CVE-2026-23744CRITICAL20 jan 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
GitHub PoC5
A tool designed to exploit CVE-2025-54068 and Remote Command Execution of the Livewire project.
CVE-2025-54068CRITICALsob ataque20 jan 2026
Livewire vulnerable to remote command execution during property update hydration
100RISCO
abrir
GitHub PoC
Cacti exploit
CVE-2024-25641CRITICAL20 jan 2026
Cacti RCE vulnerability when importing packages
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-54068CRITICALsob ataque20 jan 2026
Livewire vulnerable to remote command execution during property update hydration
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-21858CRITICAL20 jan 2026
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RISCO
abrir
VulnCheck XDB
local
CVE-2023-0386HIGHsob ataque20 jan 2026
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-21858CRITICAL20 jan 2026
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RISCO
abrir
GitHub PoC
CVE-2025-55182 React Server Components Remote Code Execution Exploit Lab
CVE-2025-55182CRITICALsob ataqueransomware20 jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
info-leak
CVE-2025-14847HIGHsob ataque20 jan 2026
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL20 jan 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
GitHub PoC
Spring4Shell (CVE-2022-22965) DFIR lab with exploit simulation, Python WAF, IOC-based detection, and PCAP analysis.
CVE-2022-22965CRITICALsob ataque20 jan 2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC
Secure Web Gateway 10.2.11 - Cross-Site Scripting (XSS)
CVE-2023-0214MEDIUM19 jan 2026
XSS in Skyhigh Security SWG
33RISCO
abrir
GitHub PoC
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.
CVE-2019-2725HIGHsob ataqueransomware19 jan 2026
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISCO
abrir
GitHub PoC
This repository provides a high-fidelity technical deconstruction and production-ready exploitation suite for CVE-2019-5736. It demonstrates how a root user inside a container can achieve a Host Root Shell by overwriting the host runc binary using an OverlayFS mount and ld.so.preload manipulation.
CVE-2019-573619 jan 2026
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-2725HIGHsob ataqueransomware19 jan 2026
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISCO
abrir
GitHub PoC
ViniciusFariasDev/cve-2024-21413-outlook-monikerlink-lab
CVE-2024-21413CRITICALsob ataque19 jan 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
This script audits ServiceNow AI Agents for vulnerabilities like CVE-2025-12420, governance gaps, and compliance risks. Powered by CYBERDUDEBIVASH – your global ecosystem for cybersecurity, AI apps, services, and consulting.
CVE-2025-12420CRITICAL19 jan 2026
Unauthenticated Privilege Escalation in ServiceNow AI Platform
60RISCO
abrir
GitHub PoC
Killian0713/Assignement_3-CVE-2017-7269
CVE-2017-7269CRITICALsob ataque19 jan 2026
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISCO
abrir
VulnCheck XDB
info-leak
CVE-2026-20805MEDIUMsob ataque19 jan 2026
Desktop Window Manager Information Disclosure Vulnerability
63RISCO
abrir
GitHub PoC
Exploitation report for ProFTPD 1.3.5 mod_copy (CVE-2015-3306) lab.
CVE-2015-330618 jan 2026
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISCO
abrir
GitHub PoC
rdana55/CVE-2021-29447-PoC
CVE-2021-29447HIGH18 jan 2026
WordPress Authenticated XXE attack when installation is running PHP 8
63RISCO
abrir
anteriorpágina 129 / 2.401próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.