Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.836exploits catalogados
32.133CVEs com exploração pública
1.932testados em laboratório
13.264 exploits
GitHub PoC
Mongobleed Detector CVE-2025-14847
CVE-2025-14847HIGHsob ataque04 jan 2026
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir
GitHub PoC
joaovicdev/EXPLOIT-CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware04 jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC1
Analysis and PoC for CVE-2025-14174 - ANGLE Metal OOB write (iOS Safari, macOS Chrome)
CVE-2025-14174HIGHsob ataque04 jan 2026
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perfor
76RISCO
abrir
GitHub PoC
CVE-2017-9805: Apache Struts 2 S2-052 RCE Exploit - PoC for Harvard University (OTD)
CVE-2017-9805HIGHsob ataque04 jan 2026
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISCO
abrir
GitHub PoC
一个容器逃逸漏洞POC
CVE-2025-9074CRITICAL04 jan 2026
Docker Desktop allows unauthenticated access to Docker Engine API from containers
48RISCO
abrir
GitHub PoC
Ermensonx/CVE-2025-14857-MongoBleed
CVE-2025-14857MEDIUM04 jan 2026
Semtech LR11xx Memory Write Access Control Bypass
33RISCO
abrir
GitHub PoC
n8n RCE (CVE-2025-68613)
CVE-2025-68613CRITICALsob ataque03 jan 2026
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISCO
abrir
GitHub PoC
hyunnna/NextChat_SSRF_CVE-2023-49785
CVE-2023-49785CRITICAL03 jan 2026
NextChat vulnerable to Server-Side Request Forgery and Cross-site Scripting
85RISCO
abrir
GitHub PoC1
rahuulmiishra/react2shell-CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware03 jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC1
CVE-2025-55182 漏洞检测与利用工具(GUI版)
CVE-2025-55182CRITICALsob ataqueransomware03 jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Expression injection payloads for n8n CVE-2025-68613 RCE
CVE-2025-68613CRITICALsob ataque03 jan 2026
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISCO
abrir
GitHub PoC
nuclei tamplate to CVE-2025-6440
CVE-2025-6440CRITICAL03 jan 2026
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISCO
abrir
GitHub PoC
CVE-2025-55182 - Tool React2Shell
CVE-2025-55182CRITICALsob ataqueransomware02 jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC1
🔍 Scan for CVE-2025-55182 vulnerabilities with a hybrid tool that combines static and dynamic analysis for improved security assessments.
CVE-2025-55182CRITICALsob ataqueransomware02 jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
MongoBleed (CVE-2025-14847) Lab & PoC : A complete educational environment to reproduce the critical unauthenticated memory leak in MongoDB. Includes a vulnerable Docker container with multi-database seeding (PII, API keys) and a Python exploit to demonstrate data extraction. Ideal for security research and awareness. 1-day analysis.
CVE-2025-14847HIGHsob ataque02 jan 2026
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir
GitHub PoC
Proof of Concept (PoC) for CVE-2022-42889 (Text4Shell) targeting Apache Commons Text versions prior to 1.10.0. This script automates Remote Code Execution (RCE) via script interpolation to establish a reverse shell. This version is a structured optimization based on the original exploit found at Exploit-DB (ID: 52261).
CVE-2022-4288902 jan 2026
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC1
🛡️ Scan and assess vulnerabilities in Next.js/Waku with the CVE-2025-55182-Scanner, combining static and dynamic analysis for robust security.
CVE-2025-55182CRITICALsob ataqueransomware02 jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
A HackIndex.io sandbox environment for the React2Shell vulnerability.
CVE-2025-55182CRITICALsob ataqueransomware02 jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Projeto educacional desenvolvido em Python com foco na análise da vulnerabilidade CVE-2021-3156 (Baron Samedit), uma falha crítica no sudo que permitia elevação de privilégio local em sistemas Linux.
CVE-2021-3156HIGHsob ataque02 jan 2026
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC
Automated Web Vulnerability Assessment of DVWA using OWASP ZAP to identify and analyze critical security flaws like Remote Code Execution (CVE-2012-1823).
CVE-2012-1823CRITICALsob ataque02 jan 2026
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RISCO
abrir
GitHub PoC
A custom Python proof-of-concept showcasing root-cause analysis and exploitation of CVE 2019-9978 (Social Warfare plugin),focusing on practical RFI to RCE attack flow.
CVE-2019-9978MEDIUMsob ataque01 jan 2026
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir
GitHub PoC1
CVE-2025-55182(React Server Components 反序列化远程代码执行漏洞)
CVE-2025-55182CRITICALsob ataqueransomware01 jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
MongoBleed CVE-2025-14847 Vulnerability Checker
CVE-2025-14847HIGHsob ataque01 jan 2026
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir
GitHub PoC3
CVE-2025-68645 - A Local File Inclusion (LFI) vulnerability in the Webmail Classic UI of Zimbra Collaboration
CVE-2025-68645HIGHsob ataque01 jan 2026
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1
98RISCO
abrir
GitHub PoC
CVE-2025-52691
CVE-2025-52691CRITICALsob ataqueransomware01 jan 2026
Upload Arbitrary Files
100RISCO
abrir
GitHub PoC3
Fast Python scanner detects vulnerable Laravel Livewire v3 sites (CVE-2025-54068, CVSS 9.2). Separates risky sites into vuln.txt, safe sites into safe.txt.
CVE-2025-54068CRITICALsob ataque01 jan 2026
Livewire vulnerable to remote command execution during property update hydration
100RISCO
abrir
GitHub PoC
ב־13 בפברואר 2024 פרסמה Microsoft חולשת אבטחה חמורה ב־Microsoft Outlook, אשר קיבלה את הזיהוי CVE-2024-21413, ומוכרת בשם Moniker Link Vulnerability. החולשה מאפשרת לתוקף לעקוף את מנגנון Protected View של Outlook
CVE-2024-21413CRITICALsob ataque01 jan 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
galois17/cve-2017-12149-playground
CVE-2017-12149CRITICALsob ataqueransomware01 jan 2026
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISCO
abrir
GitHub PoC1
A new way to exploit CVE-2025-58360 bypass WAF
CVE-2025-58360HIGHsob ataque31 dez 2025
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RISCO
abrir
GitHub PoC
Rishi-kaul/CVE-2025-14847-MongoBleed
CVE-2025-14847HIGHsob ataque31 dez 2025
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir
anteriorpágina 85 / 443próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.