Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
71.886 exploits
VulnCheck XDB
initial-access
CVE-2025-8110HIGHsob ataque13 abr 2026
File overwrite in file update API in Gogs
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-59528CRITICAL13 abr 2026
Flowise has Remote Code Execution vulnerability
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-29357CRITICALsob ataqueransomware13 abr 2026
Microsoft SharePoint Server Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC1
CVE-2025-59528 Proof of Concept
CVE-2025-59528CRITICAL13 abr 2026
Flowise has Remote Code Execution vulnerability
85RISCO
abrir
GitHub PoC16
Combined PoC for CVE-2025-28434 and CVE-2025-59528
CVE-2025-58434CRITICAL13 abr 2026
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
75RISCO
abrir
GitHub PoC1
CVE-2025-59528 - FlowiseAI CustomMCP Remote Code Execution
CVE-2025-59528CRITICAL13 abr 2026
Flowise has Remote Code Execution vulnerability
85RISCO
abrir
GitHub PoC
Gogs Symlink Traversal → RCE
CVE-2025-8110HIGHsob ataque13 abr 2026
File overwrite in file update API in Gogs
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware13 abr 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-39987CRITICALsob ataque13 abr 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISCO
abrir
GitHub PoC1
This repository contains a Proof of Concept (PoC) exploit for CVE-2023-6972.
CVE-2023-6972CRITICAL13 abr 2026
Backup Migration <= 1.3.9 - Unauthenticated Path Traversal to Arbitrary File Deletion
48RISCO
abrir
GitHub PoC
Firefox extension for detecting and exploiting CVE-2025-55182 — Prototype Pollution RCE in Next.js React Server Actions
CVE-2025-55182CRITICALsob ataqueransomware12 abr 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
CVE-2025-58434 & CVE-2025-59528
CVE-2025-58434CRITICAL12 abr 2026
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
75RISCO
abrir
GitHub PoC3
CVE-2025-58434 and CVE-2025-59528 chain POC
CVE-2025-58434CRITICAL12 abr 2026
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
75RISCO
abrir
GitHub PoC1
RCE exploit for Gogs <= 0.13.3
CVE-2025-8110HIGHsob ataque12 abr 2026
File overwrite in file update API in Gogs
100RISCO
abrir
GitHub PoC
Found 200+ vulnerabilities on scanme.nmap.org including CVE-2023-38408 (9.8 critical)
CVE-2023-38408CRITICAL12 abr 2026
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISCO
abrir
GitHub PoC
CVE-2025-58434 PoC
CVE-2025-58434CRITICAL12 abr 2026
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
75RISCO
abrir
GitHub PoC1
kartik2005221/CVE-2025-58434-poc
CVE-2025-58434CRITICAL12 abr 2026
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
75RISCO
abrir
GitHub PoC1
Critical unauthenticated kill chain leading to full RCE in FlowiseAI (CVE-2025-58434 + CVE-2025-59528)
CVE-2025-58434CRITICAL12 abr 2026
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
75RISCO
abrir
GitHub PoC2
Exploitation Silentium HTB-CTF
CVE-2025-58434CRITICAL12 abr 2026
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
75RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-59528CRITICAL12 abr 2026
Flowise has Remote Code Execution vulnerability
85RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-59528CRITICAL12 abr 2026
Flowise has Remote Code Execution vulnerability
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-59528CRITICAL12 abr 2026
Flowise has Remote Code Execution vulnerability
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-59528CRITICAL12 abr 2026
Flowise has Remote Code Execution vulnerability
85RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-8110HIGHsob ataque12 abr 2026
File overwrite in file update API in Gogs
100RISCO
abrir
GitHub PoC
Security research and CVE write-ups by Steven Amador (HackinKraken) - CVE-2022-2650, CVE-2026-39338
CVE-2026-39338HIGH12 abr 2026
ChurchCRM has Blind XSS via Global Search – Administrative Cookie Session Exfiltration
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-8110HIGHsob ataque12 abr 2026
File overwrite in file update API in Gogs
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-8110HIGHsob ataque11 abr 2026
File overwrite in file update API in Gogs
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-8110HIGHsob ataque11 abr 2026
File overwrite in file update API in Gogs
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-8110HIGHsob ataque11 abr 2026
File overwrite in file update API in Gogs
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALsob ataqueransomware11 abr 2026
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
anteriorpágina 92 / 2.397próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.