Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.445exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
75.445 exploits
VulnCheck XDB
infoleak
CVE-2021-43798HIGHsob ataque22 dez 2025
Grafana path traversal
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-33045CRITICALsob ataque22 dez 2025
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALsob ataque22 dez 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-68613CRITICALsob ataque22 dez 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISCO
abrir
GitHub PoC
Comprehensive Penetration Testing report and exploit chain for Metasploitable 2 focusing on CVE-2011-2523.
CVE-2011-252322 dez 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware22 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware21 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
CVE-2023-32315(java7)
CVE-2023-32315HIGHsob ataque21 dez 2025
Openfire administration console authentication bypass
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-24071MEDIUM21 dez 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-55182CRITICALsob ataqueransomware21 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
local
CVE-2025-38352HIGHsob ataque21 dez 2025
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
71RISCO
abrir
GitHub PoC
nicolasdamians/ms09-050-CVE-2009-3103-exploit
CVE-2009-310321 dez 2025
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RISCO
abrir
GitHub PoC4
Hello friend. This is the Fsociety Exploit Framework for CVE-2025-24071. Generates malicious .library-ms files to steal NTLMv2 hashes. Includes a 'Living Terminal' Cinematic Mode, Deep Trace logging, and stealth evasion techniques. Join the revolution. #Hacking #Exploit #CVE-2025-24071
CVE-2025-24071MEDIUM21 dez 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
GitHub PoC1
NextJS exploiter for CVE-2025-55182 and more.
CVE-2025-55182CRITICALsob ataqueransomware21 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Test & Analyze the CVE-2025-55182 vulnerability within Next.js Server Actions
CVE-2025-55182CRITICALsob ataqueransomware21 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Security research on Fortinet FortiWeb vulnerabilities (CVE-2025-64446, CVE-2025-58034)
CVE-2025-64446CRITICALsob ataque21 dez 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISCO
abrir
GitHub PoC106
This is a proof of concept for CVE-2025-38352, a vulnerability in the Linux kernel's POSIX CPU timers implementation. The September 2025 Android Bulletin mentions that this vulnerability has been used in limited, targeted exploitation in the wild.
CVE-2025-38352HIGHsob ataque21 dez 2025
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
71RISCO
abrir
GitHub PoC1
PoC exploit for CVE-2018-11736 affecting Pluck CMS versions prior to 4.7.7-dev2 with a File Upload Vulnerability
CVE-2018-1173621 dez 2025
An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute a
23RISCO
abrir
GitHub PoC13
FreeBSD rtsold DNSSL Command Injection (RCE)
CVE-2025-14558HIGH20 dez 2025
Remote code execution via ND6 Router Advertisements
56RISCO
abrir
GitHub PoC
writeups for (CVE-2025-67586, CVE-2025-67985, CVE-2025-67986)
CVE-2025-67586MEDIUM20 dez 2025
WordPress Highlight and Share plugin <= 5.2.0 - Broken Access Control vulnerability
33RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-0519HIGHsob ataque20 dez 2025
Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially expl
71RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware20 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware20 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware20 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC21
RSC Detect CVE 2025 55182
CVE-2025-55182CRITICALsob ataqueransomware20 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALsob ataque20 dez 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC9
CVE-2025-55182 React2Shell PoC - Critical RCE in React Server Components / Next.js. CVSS 10.0. Error-based exfil, reverse shell, interactive mode.
CVE-2025-55182CRITICALsob ataqueransomware20 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC1
A self-hosted vulnerable Next.js environment running on Docker for simulating CVE-2025-55182. Built for educational security research and CTF practice.
CVE-2025-55182CRITICALsob ataqueransomware20 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
tamagorengs/react2shell-poc-CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware20 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Secure-by-default demo lab showing how container hardening (distroless images, non-root, read-only filesystem, runtime-injected secrets) can neutralize a critical Next.js/React Server Actions RCE (CVE-2025-55182 “React2Shell”), with side-by-side safe vs unsafe deployments and exploit logs
CVE-2025-55182CRITICALsob ataqueransomware20 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
anteriorpágina 152 / 2.515próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.