Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

72.018exploits catalogados
32.219CVEs com exploração pública
1.932testados em laboratório
72.018 exploits
GitHub PoC
0x13-ByteZer0/CVE-2024-21762
CVE-2024-21762CRITICALsob ataqueransomware13 jan 2026
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISCO
abrir
GitHub PoC1
Local Priviledge Escalation for Druva
CVE-2020-575213 jan 2026
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitra
38RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-64155CRITICAL13 jan 2026
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware13 jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
local
CVE-2025-7771HIGH13 jan 2026
Code Execution / Escalation of Privileges in ThrottleStop
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-0692HIGH13 jan 2026
SolarWinds Security Event Manager Deserialization of Untrusted Data Remote Code Execution Vulnerability
78RISCO
abrir
GitHub PoC2
CVE-2025-14847 | MongoBleed vulnerability proof of concept project
CVE-2025-14847HIGHsob ataque12 jan 2026
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir
GitHub PoC3
CVE-2025-52694 Critical SQL Injection in Advantech IoTSuite/SaaS-Composer
CVE-2025-52694CRITICAL12 jan 2026
Execution of arbitrary SQL commands
75RISCO
abrir
GitHub PoC
posix sh poc for CVE-2009-2265 (deps: curl,msfvenom,uuidgen,tr)
CVE-2009-226512 jan 2026
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RISCO
abrir
GitHub PoC
Mr-In4inci3le/CVE-2025-11953-POC-
CVE-2025-11953CRITICALsob ataque12 jan 2026
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
90RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-11953CRITICALsob ataque12 jan 2026
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
90RISCO
abrir
GitHub PoC
Technical analysis and reproduction lab for the Apache HTTP Server 2.4.49 Path Traversal and RCE vulnerability.
CVE-2021-41773HIGHsob ataqueransomware12 jan 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC3
Proof-of-Concept 0day for SAP NetWeaver created by ShinyHunters
CVE-2025-31324CRITICALsob ataqueransomware12 jan 2026
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISCO
abrir
VulnCheck XDB
info-leak
CVE-2025-14847HIGHsob ataque12 jan 2026
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir
GitHub PoC
React2Shell is a high-performance vulnerability scanner written in Go, specifically designed to detect Server-Side Remote Code Execution (RCE) vulnerabilities in Next.js applications (CVE-2025-55182 & CVE-2025-66478).
CVE-2025-55182CRITICALsob ataqueransomware12 jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2009-226512 jan 2026
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RISCO
abrir
GitHub PoC
An exploit for CVE-2015-1538-1 - Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution
CVE-2015-153812 jan 2026
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RISCO
abrir
GitHub PoC
sahar042/CVE-2025-14847
CVE-2025-14847HIGHsob ataque11 jan 2026
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir
GitHub PoC3
rimbadirgantara/CVE-2025-52691-poc
CVE-2025-52691CRITICALsob ataqueransomware11 jan 2026
Upload Arbitrary Files
100RISCO
abrir
GitHub PoC1
Defensive PowerShell tool for static inspection of RAR archives and detection of CVE-2025-8088 path traversal anomalies.
CVE-2025-8088HIGHsob ataque11 jan 2026
Path traversal vulnerability in WinRAR
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware11 jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-29059MEDIUM11 jan 2026
Windmill: SUPERADMIN_SECRET (rarely used) can be accessed publicly
48RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-52691CRITICALsob ataqueransomware11 jan 2026
Upload Arbitrary Files
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-31161CRITICALsob ataqueransomware11 jan 2026
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISCO
abrir
GitHub PoC2
CVE-2025-55182漏洞检测工具
CVE-2025-55182CRITICALsob ataqueransomware11 jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC1
PoC Authentication Bypass to RCE to Exploit CVE-2025-31161
CVE-2025-31161CRITICALsob ataqueransomware11 jan 2026
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISCO
abrir
GitHub PoC
js2py <= 0.74 sandbox escape (CVE-2024-28397)
CVE-2024-28397MEDIUM11 jan 2026
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISCO
abrir
VulnCheck XDB
info-leak
CVE-2025-14847HIGHsob ataque11 jan 2026
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir
GitHub PoC
comerc/CVE-2025-68664
CVE-2025-68664CRITICAL10 jan 2026
LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
60RISCO
abrir
GitHub PoC
mooowu/cve-2025-55182-poc
CVE-2025-55182CRITICALsob ataqueransomware10 jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
anteriorpágina 132 / 2.401próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.