Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.445exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
75.445 exploits
GitHub PoC1
Intentionally vulnerable Next.js app for CVE-2025-55182 security research and CTF challenges
CVE-2025-55182CRITICALsob ataqueransomware11 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
min8282/CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware11 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC1
CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware11 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
Metasploit600
FreePBX endpoint SQLi to RCE
CVE-2025-66039CRITICAL11 dez 2025
FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header
63RISCO
abrir
Metasploit300
FreePBX Custom Extension SQL Injection
CVE-2025-61675HIGH11 dez 2025
FreePBX Endpoint Manager vulnerable to authenticated SQL injection in multiple configuration parameters
48RISCO
abrir
Metasploit600
FreePBX endpoint SQLi to RCE
CVE-2025-61675HIGH11 dez 2025
FreePBX Endpoint Manager vulnerable to authenticated SQL injection in multiple configuration parameters
48RISCO
abrir
Metasploit600
FreePBX firmware file upload
CVE-2025-61678HIGH11 dez 2025
FreePBX Endpoint Manager vulnerable to authenticated arbitrary file upload via fwbrand parameter
48RISCO
abrir
Metasploit600
FreePBX firmware file upload
CVE-2025-66039CRITICAL11 dez 2025
FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header
63RISCO
abrir
Metasploit300
FreePBX Custom Extension SQL Injection
CVE-2025-66039CRITICAL11 dez 2025
FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-7954CRITICAL11 dez 2025
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware11 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-8110HIGHsob ataque11 dez 2025
File overwrite in file update API in Gogs
100RISCO
abrir
GitHub PoC
Docker test environment for CVE-2025-34299 - Monsta FTP Pre-Auth RCE vulnerability
CVE-2025-34299CRITICAL11 dez 2025
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RISCO
abrir
GitHub PoC
CVE-2025-23061 - Mongoose Command Injection
CVE-2025-23061CRITICAL11 dez 2025
Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NO
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware11 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware11 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-55182CRITICALsob ataqueransomware11 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware11 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC1
CVE-2021-4045 CVE-2021-4045 is a Command Injection vulnerability that allows Remote Code Execution in the TP-Link Tapo c200 IP camera. It affects all firmware versions prior to 1.1.16 Build 211209 Rel. 37726N due to insufficient checks on user input in uhttpd, which is one of the main binaries of the device.
CVE-2021-4045CRITICAL11 dez 2025
TP-LINK Tapo C200 remote code execution vulnerability
70RISCO
abrir
VulnCheck XDB
local
CVE-2025-6019HIGH11 dez 2025
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-53558HIGH11 dez 2025
ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all installations. With the knowledge o
56RISCO
abrir
GitHub PoC22
Detection template for CVE-2025-8110
CVE-2025-8110HIGHsob ataque11 dez 2025
File overwrite in file update API in Gogs
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-34299CRITICAL11 dez 2025
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware11 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Apache Tomcat AJP Ghostcat (CVE-2020-1938) exploit tool for file disclosure with multi-target scanning, custom wordlists, and upload point detection capabilities
CVE-2020-1938CRITICALsob ataque11 dez 2025
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
GitHub PoC
Vulnerable ThinkPHP 8.0.4 test environment for CVE-2024-44902 nuclei template validation
CVE-2024-44902CRITICAL10 dez 2025
A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.
48RISCO
abrir
GitHub PoC1
PoC for testing if a target is vulnerable to RCE
CVE-2020-14882CRITICALsob ataque10 dez 2025
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-53772HIGH10 dez 2025
Web Deploy Remote Code Execution Vulnerability
46RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-6389CRITICAL10 dez 2025
Sneeit Framework <= 8.3 - Unauthenticated Remote Code Execution in sneeit_articles_pagination_callback
60RISCO
abrir
GitHub PoC1
pppxo/CVE-2025-9074-PoC-Bash
CVE-2025-9074CRITICAL10 dez 2025
Docker Desktop allows unauthenticated access to Docker Engine API from containers
48RISCO
abrir
anteriorpágina 160 / 2.515próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.