Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.836exploits catalogados
32.133CVEs com exploração pública
1.932testados em laboratório
13.264 exploits
GitHub PoC
Lightweight Go toolkit plus a Dockerized Next.js lab to explore and triage CVE-2025-55182.
CVE-2025-55182CRITICALsob ataqueransomware18 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
React2Shell Vulnerability Verification Script (React2Shell also known as CVE-2025-55182).
CVE-2025-55182CRITICALsob ataqueransomware18 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC2
Detection for CVE-2025-37164
CVE-2025-37164CRITICALsob ataque18 dez 2025
A remote code execution issue exists in HPE OneView.
100RISCO
abrir
GitHub PoC
Control Web Panel <= 0.9.8.1208 (admin/index.php) OS Command Injection Vulnerability • Software Link:
CVE-2025-67888HIGH18 dez 2025
An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /
56RISCO
abrir
GitHub PoC4
This is a Proof-Of-Concept of CVE-2025-63353
CVE-2025-63353CRITICAL18 dez 2025
A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-s
48RISCO
abrir
GitHub PoC1
CVE-2025-40602 is a local privilege escalation vulnerability in the appliance management console (AMC) of SonicWall Secure Mobile Access (SMA) 1000 series appliances.
CVE-2025-40602MEDIUMsob ataque18 dez 2025
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance manageme
63RISCO
abrir
GitHub PoC
1C-Bitrix <= 25.100.500 (Translate Module) Remote Code Execution Vulnerability
CVE-2025-67887CRITICAL18 dez 2025
1C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Transla
48RISCO
abrir
GitHub PoC
POC for CVE-2025-33053 WebDav Exploit, demonstrating how the vulnerability can be triggered in a real environment. This repository focuses on hands-on exploitation steps, reproducible test cases, and observable impact, helping security researchers and defenders understand the issue and validate fixes.
CVE-2025-33053HIGHsob ataque18 dez 2025
Internet Shortcut Files Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
This repo describes about cve-2021-29447 and a small script for exploiting automatically
CVE-2021-29447HIGH18 dez 2025
WordPress Authenticated XXE attack when installation is running PHP 8
63RISCO
abrir
GitHub PoC
Bitrix24 <= 25.100.300 (Translate Module) Remote Code Execution Vulnerability
CVE-2025-67886MEDIUM18 dez 2025
Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translat
33RISCO
abrir
GitHub PoC9
Proof-of-Concept exploit for CVE-2025-14174 (EUVD-2025-203113) - Memory corruption in ANGLE allowing out-of-bounds access and RCE in web browsers. Reliable on iOS/Android/Windows, including patched systems with incomplete fixes.
CVE-2025-14174HIGHsob ataque18 dez 2025
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perfor
76RISCO
abrir
GitHub PoC
KingHacker353/CVE-2025-20393
CVE-2025-20393CRITICALsob ataque18 dez 2025
Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability
83RISCO
abrir
GitHub PoC2
Cisco is aware of a potential vulnerability.&nbsp; Cisco is currently investigating and&nbsp;will update these details as appropriate&nbsp;as more information becomes available.
CVE-2025-20393CRITICALsob ataque18 dez 2025
Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability
83RISCO
abrir
GitHub PoC
Proof of Concept for Authenticated RCE in Crafty Controller
CVE-2025-14700CRITICAL18 dez 2025
Improper Neutralization of Special Elements Used in a Template Engine in Crafty Controller
48RISCO
abrir
GitHub PoC3
Fox LMS – WordPress LMS Plugin 1.0.4.7 - 1.0.5.1 - Unauthenticated Privilege Escalation via 'createOrder'
CVE-2025-14156CRITICAL18 dez 2025
Fox LMS – WordPress LMS Plugin 1.0.4.7 - 1.0.5.1 - Unauthenticated Privilege Escalation via 'createOrder'
48RISCO
abrir
GitHub PoC22
Script to detect CVE-2025-20393 for Cisco Secure Email Gateway And Cisco Secure Email and Web Manager
CVE-2025-20393CRITICALsob ataque18 dez 2025
Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability
83RISCO
abrir
GitHub PoC
Improved poc of CVE-2017-0785 on DS-MDP002
CVE-2017-078517 dez 2025
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RISCO
abrir
GitHub PoC1
Proof of Concept for Authenticated RCE in Crafty Controller <= 4.6.1
CVE-2025-14700CRITICAL17 dez 2025
Improper Neutralization of Special Elements Used in a Template Engine in Crafty Controller
48RISCO
abrir
GitHub PoC
React2shell vulnerable lab (CVE-2025-55182)
CVE-2025-55182CRITICALsob ataqueransomware17 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC1
Proof-of-concept research tool for CVE-2025-55182, a critical unauthenticated RCE in Next.js App Router caused by server-side object injection in React Server Components and Server Actions, including UTF-16LE WAF evasion techniques.
CVE-2025-55182CRITICALsob ataqueransomware17 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC1
proof-of-concept mass scanner targeting JetBrains TeamCity instances affected by CVE-2024-27198
CVE-2024-27198CRITICALsob ataqueransomware17 dez 2025
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir
GitHub PoC6
Fortinet announced two closely related authentication‑bypass vulnerabilities on 9 December 2025. Both flaws involve improper verification of cryptographic signatures (CWE‑347) in the handling of SAML responses for the FortiCloud SSO login feature.
CVE-2025-59718CRITICALsob ataque17 dez 2025
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0
90RISCO
abrir
GitHub PoC
CVE-2022-0492
CVE-2022-0492HIGHsob ataque16 dez 2025
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
86RISCO
abrir
GitHub PoC1
This is a python PoC scripts for CVE-2025-24071 which is a vulnerability in Windows File Explorer that allows unauthorized access to sensitive information like NTLM Exposure.
CVE-2025-24071MEDIUM16 dez 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
GitHub PoC
CVE-1999-0678- /doc directory browsable
CVE-1999-067816 dez 2025
A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read
35RISCO
abrir
GitHub PoC1
React2Shell
CVE-2025-55182CRITICALsob ataqueransomware16 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC1
A proof-of-concept tool for demonstrating the critical React2Shell vulnerability
CVE-2025-55182CRITICALsob ataqueransomware16 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Quyida to‘liq LAB rejasi: demo-vulnerable app → Python PoC → Metasploit exploit skeleton
CVE-2025-55182CRITICALsob ataqueransomware16 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability."
CVE-2017-0144HIGHsob ataqueransomware16 dez 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
GitHub PoC
An advanced vulnerability scanner for detecting **CVE-2025-55182** and **CVE-2025-66478** - critical Remote Code Execution (RCE) vulnerabilities in Next.js applications using React Server Components (RSC).
CVE-2025-55182CRITICALsob ataqueransomware16 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
anteriorpágina 91 / 443próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.