Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.445exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
75.445 exploits
GitHub PoC
rahul-securify/React2Shell-CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware12 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC50
Advanced Exploitation Toolkit for Next.js Server Actions (CVE-2025-55182)
CVE-2025-55182CRITICALsob ataqueransomware12 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC5
WEB-CLI_RCE_React2Shell is an educational PoC exploit tool for CVE-2025-55182, a critical Prototype Pollution flaw in Next.js applications using React Server Components. Designed for CTFs and research, it features a single-command mode, an interactive web CLI, and reverse shell capabilities to demonstrate RCE.
CVE-2025-55182CRITICALsob ataqueransomware12 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC8
CVE-2025-55182 security test kit: CLI scanner + Chrome extension + Nuclei templates + Docker lab.
CVE-2025-55182CRITICALsob ataqueransomware12 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC1
CVE-2025-55182 payload
CVE-2025-55182CRITICALsob ataqueransomware12 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
POC React2Shell-CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware12 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
CVE-2025-55182 の検証用
CVE-2025-55182CRITICALsob ataqueransomware12 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC1
CVE-2025-55182 – CVE-2025-66478 – React2Shell
CVE-2025-55182CRITICALsob ataqueransomware12 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
ryanhafid/Scan_CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware12 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
ryanhafid/PoC_CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware12 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC3
A Chrome extension for detecting React2Shell vulnerabilities (CVE-2025-55182 & CVE-2025-66478) in web applications
CVE-2025-55182CRITICALsob ataqueransomware11 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC1
Burp Suite extension for identifying the React Server Components unsafe deserialization vulnerability (React2Shell / CVE-2025-55182). It provides a focused UI tab, context-menu actions, active-scanner integration, and optional Burp Collaborator confirmation.
CVE-2025-55182CRITICALsob ataqueransomware11 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It provides an interactive shell with advanced features for penetration testing, including file transfer, persistence, enumeration, privilege escalation checks, and more.
CVE-2025-55182CRITICALsob ataqueransomware11 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
CVE-2025-55182 & CVE-2025-66478 proof of concepts
CVE-2025-55182CRITICALsob ataqueransomware11 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC2
Nkwenti-Severian-Ndongtsop/POC_react2shell_CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware11 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC3
Interactive visualization of the React2Shell (CVE-2025-55182) RCE vulnerability with narrated animations for three audiences: Expert, Practitioner, and Stakeholder. Audio synced via ElevenLabs + Whisper.
CVE-2025-55182CRITICALsob ataqueransomware11 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
React2Shell (CVE-2025-55182) scanner
CVE-2025-55182CRITICALsob ataqueransomware11 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC5
This tool is a Proof of Concept (PoC) intended for security research and educational purposes only. Using this tool on systems without explicit permission is illegal and punishable by law. The author (Tiger-Foxx) assumes no responsibility for misuse.
CVE-2025-55182CRITICALsob ataqueransomware11 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC2
LC-pro/CVE-2025-55182-EXP
CVE-2025-55182CRITICALsob ataqueransomware11 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC1
Educational / research tool related to React / Next.js vulnerability CVE‑2025‑55182 (“React2Shell”).
CVE-2025-55182CRITICALsob ataqueransomware11 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
exrienz/CVE-2025-55182-NextJS-Scanner-React2Shell-PoC
CVE-2025-55182CRITICALsob ataqueransomware11 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC1
Intentionally vulnerable Next.js app for CVE-2025-55182 security research and CTF challenges
CVE-2025-55182CRITICALsob ataqueransomware11 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
min8282/CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware11 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
Metasploit300
FreePBX Custom Extension SQL Injection
CVE-2025-61675HIGH11 dez 2025
FreePBX Endpoint Manager vulnerable to authenticated SQL injection in multiple configuration parameters
48RISCO
abrir
Metasploit600
FreePBX firmware file upload
CVE-2025-66039CRITICAL11 dez 2025
FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header
63RISCO
abrir
Metasploit600
FreePBX firmware file upload
CVE-2025-61678HIGH11 dez 2025
FreePBX Endpoint Manager vulnerable to authenticated arbitrary file upload via fwbrand parameter
48RISCO
abrir
GitHub PoC
Apache Tomcat AJP Ghostcat (CVE-2020-1938) exploit tool for file disclosure with multi-target scanning, custom wordlists, and upload point detection capabilities
CVE-2020-1938CRITICALsob ataque11 dez 2025
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
Metasploit600
FreePBX endpoint SQLi to RCE
CVE-2025-66039CRITICAL11 dez 2025
FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header
63RISCO
abrir
Metasploit600
FreePBX endpoint SQLi to RCE
CVE-2025-61675HIGH11 dez 2025
FreePBX Endpoint Manager vulnerable to authenticated SQL injection in multiple configuration parameters
48RISCO
abrir
GitHub PoC22
Detection template for CVE-2025-8110
CVE-2025-8110HIGHsob ataque11 dez 2025
File overwrite in file update API in Gogs
100RISCO
abrir
anteriorpágina 159 / 2.515próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.