Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
72.018exploits catalogados
32.219CVEs com exploração pública
1.932testados em laboratório
TodosExploit-DB 22.786Referência 20.023GitHub PoC 13.334VulnCheck XDB 8.195Nuclei 4.217Metasploit 3.463✓ só verificadosrecentespopularesrisco
72.018 exploits
VulnCheck XDB
info-leak
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1
98RISCO
abrir ↗GitHub PoC★ 1
CVE-2025-55182(React Server Components 反序列化远程代码执行漏洞)
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗GitHub PoC
galois17/cve-2017-12149-playground
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISCO
abrir ↗GitHub PoC★ 2
nkuty/CVE-2025-54322-exploit
Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid paramete
53RISCO
abrir ↗GitHub PoC
Rishi-kaul/CVE-2025-14847-MongoBleed
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir ↗GitHub PoC★ 5
Poc for CVE-2025-7771 to modify PPL Protection
Code Execution / Escalation of Privileges in ThrottleStop
41RISCO
abrir ↗VulnCheck XDB
info-leak
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00
35RISCO
abrir ↗GitHub PoC
Audit de sécurité Black Box d'un serveur Drupal 7. Démonstration d'une Kill Chain complète : Injection SQL (CVE-2014-3704) ➔ RCE ➔ Reverse Shell ➔ Escalade vers Root (SUID). Ce dépôt contient le rapport technique détaillé, les preuves d'exploitation (PoC) et les mesures de remédiation pour sécuriser l'infrastructure.
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISCO
abrir ↗GitHub PoC★ 1
A new way to exploit CVE-2025-58360 bypass WAF
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RISCO
abrir ↗GitHub PoC
Goultarde/CVE-2025-55182-React2Shell-Lab
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗GitHub PoC
This repository provides a proof-of-concept for CVE-2025-55182 (React2Shell), a remote code execution vulnerability in React Server Components. It demonstrates how the exploit works, including the payload and impact.
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗GitHub PoC
nyambiblaise/Microsoft-Windows-SMBGhost-Vulnerability-Checker---CVE-2020-0796---SMBv3-RCE
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir ↗GitHub PoC
CVE-2024-4577 PHP CGI Argument Injection - Detection Lab with Vagrant VMs and Wazuh SIEM rules
Argument Injection in PHP-CGI
100RISCO
abrir ↗GitHub PoC
🎯 Automated vulnerability scanner for React2Shell RCE - Google dorking + safe detection for CVE-2025-55182/CVE-2025-66478 (CVSS 10.0)
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗GitHub PoC
YanC1e/CVE-2025-8191
macrozheng mall Swagger UI index.html cross site scripting
33RISCO
abrir ↗VulnCheck XDB
info-leak
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir ↗VulnCheck XDB
info-leak
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir ↗VulnCheck XDB
initial-access
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir ↗VulnCheck XDB
info-leak
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir ↗VulnCheck XDB
initial-access
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗GitHub PoC★ 1
CVE-2025-14847 MongoBleed - MongoDB Memory Leak Vulnerability PoC
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir ↗GitHub PoC★ 1
This repository contains a safe Proof of Concept (PoC) to detect vulnerable SmarterMail versions affected by CVE‑2025‑52691. The script performs version detection only and does not exploit the vulnerability.
Upload Arbitrary Files
100RISCO
abrir ↗GitHub PoC★ 3
An enhanced proof-of-concept exploit for CVE-2025-52691 (SmarterMail Arbitrary File Upload RCE) with APT-level features like stealth obfuscation, persistence, exfiltration, and interactive mode. For educational and authorized testing only. Credits to the original PoC by yt2w/CVE-2025-52691.
Upload Arbitrary Files
100RISCO
abrir ↗GitHub PoC
Burp Suite extension to detect CVE-2025-14847 (MongoBleed) via manual leak tests from a dedicated UI tab.
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.