Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.836exploits catalogados
32.133CVEs com exploração pública
1.932testados em laboratório
13.264 exploits
GitHub PoC
CVE-1999-0678- /doc directory browsable
CVE-1999-067816 dez 2025
A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read
35RISCO
abrir
GitHub PoC
An advanced vulnerability scanner for detecting **CVE-2025-55182** and **CVE-2025-66478** - critical Remote Code Execution (RCE) vulnerabilities in Next.js applications using React Server Components (RSC).
CVE-2025-55182CRITICALsob ataqueransomware16 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
d0cnull/nextjs-CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware16 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
S-Mughal/NextJS-app-CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware16 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
CVE-2022-0492
CVE-2022-0492HIGHsob ataque16 dez 2025
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
86RISCO
abrir
GitHub PoC1
This repository documents three security vulnerabilities discovered in FreePBX (CVE-2025-66039, CVE-2025-61678, CVE-2025-61675), including analysis, impact, and proof-of-concept details for security research and awareness purposes.
CVE-2025-66039CRITICAL16 dez 2025
FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header
63RISCO
abrir
GitHub PoC
yasa
CVE-2024-43202CRITICAL15 dez 2025
Apache DolphinScheduler: Remote Code Execution Vulnerability
48RISCO
abrir
GitHub PoC2
Comprehensive analysis and proof-of-concept for CVE-2025-6218 - WinRAR path traversal RCE vulnerability affecting versions 7.11 and earlier
CVE-2025-6218HIGHsob ataque15 dez 2025
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
93RISCO
abrir
GitHub PoC2
This project provides a fully functional demonstration of CVE-2025-55182 (React2Shell) - a critical Remote Code Execution vulnerability in React Server Components and Next.js.
CVE-2025-55182CRITICALsob ataqueransomware15 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
A cybersecurity case study analysing CVE-2023-20198 in Cisco IOS XE, covering vulnerability exploitation, mitigation strategies, secure software development frameworks, and patch management policies, with practical insights from a controlled lab environment
CVE-2023-20198CRITICALsob ataque15 dez 2025
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISCO
abrir
GitHub PoC
A script for exploiting a vulnerability in PyTorch with subsequent RCE in library versions < 2.6.0
CVE-2025-32434CRITICAL15 dez 2025
PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
48RISCO
abrir
GitHub PoC1
mivmi/CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware15 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
cve-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware15 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
hulh122/CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware15 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
simantchaudhari/CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware15 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
This repo contains the scripts you can execute to simulate the (CVE-2025-55182) along with next.js server
CVE-2025-55182CRITICALsob ataqueransomware15 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC1
ACharaf06/CVE-2017-5638-Attack-and-Defense
CVE-2017-5638CRITICALsob ataqueransomware15 dez 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC
o0wo0o/CVE-2025-24893_Shell
CVE-2025-24893CRITICALsob ataque15 dez 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC
tinashelorenzi/CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware14 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC1
Ermensonx/CVE-2024-38077-MadLicense-exploit
CVE-2024-38077CRITICAL14 dez 2025
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC1
The Ultimate DAEMON_KILLER. Control is an illusion. This Exploit forces CVE-2025-9074 to break the Docker cage. Advanced Container Escape & Root Escalation toolkit. Verify the vulnerability, take the host, destroy the logs. > We Are Fsociety_
CVE-2025-9074CRITICAL14 dez 2025
Docker Desktop allows unauthenticated access to Docker Engine API from containers
48RISCO
abrir
GitHub PoC
Test
CVE-2025-48384HIGHsob ataque14 dez 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC5
Precision-Based Detection of RSC/Next.js Remote Code Execution Vulnerabilities (CVE-2025-55182, CVE-2025-66478)
CVE-2025-55182CRITICALsob ataqueransomware14 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Étude technique et mise en œuvre d'un environnement de test pour la faille Apache Log4j (CVE-2021-44228). Contient un Proof of Concept (PoC) Dockerisé et une proposition de mise à jour de PSSI. Pour un objectif de TP
CVE-2021-44228CRITICALsob ataqueransomware14 dez 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC3
💥Extension Tool para Auditoría y Explotación avanzada RCE/Source Leak/Dos (CVE-2025-55182/83/84) para entornos Next.js y React Server Components (RSC) directamente desde tu navegador + Laboratorio Vulnerable❌
CVE-2025-55182CRITICALsob ataqueransomware14 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC1
Proof-of-Concept for CVE-2025-55182, a critical unauthenticated RCE in React Server Components.
CVE-2025-55182CRITICALsob ataqueransomware14 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
CVE-2025-55182-Advanced-Scanner is an automated security tool designed to detect and validate the CVE-2025-55182 vulnerability efficiently. it helps security researchers and bug bounty hunters quickly identify affected targets with accurate results and minimal false positives.
CVE-2025-55182CRITICALsob ataqueransomware14 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC1
An advanced command-line framework for discovery, validation, and exploitation of CVE-2025-55182 and CVE-2025-66478 affecting Next.js applications using React Server Components (RSC).
CVE-2025-55182CRITICALsob ataqueransomware14 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
GIT vulnerability | Carriage Return and RCE on cloning
CVE-2025-48384HIGHsob ataque14 dez 2025
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC
NabilBoudra/cve-2017-5123
CVE-2017-512314 dez 2025
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RISCO
abrir
anteriorpágina 92 / 443próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.