Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
15.250 exploits
GitHub PoC
Proof-of-concept exploit for CVE-2019-15107 (Webmin <= 1.920) enabling unauthenticated RCE via command injection.
CVE-2019-15107CRITICALsob ataqueransomware11 abr 2026
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
GitHub PoC
Real-world incident response for CVE-2025-55182 (React2Shell) — script injection, server remediation, and post-incident report
CVE-2025-55182CRITICALsob ataqueransomware11 abr 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
0xMOGA/CVE-2023-4911-Lab
CVE-2023-4911HIGHsob ataque11 abr 2026
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISCO
abrir
GitHub PoC
CVE-2025-69212 - OpenSTAManager has an OS Command Injection in P7M File Processing
CVE-2025-69212CRITICAL11 abr 2026
OpenSTAManager has an OS Command Injection in P7M File Processing
48RISCO
abrir
GitHub PoC
kaleth4/CVE-2025-14018
CVE-2025-14018HIGH11 abr 2026
Unquoted Service Path in NetBT Consultancy's e-Fatura
41RISCO
abrir
GitHub PoC4
GOGS RCE cve-2025-8110 python script that automates the whole attack chain of creating a repository with a symlink file pointing to .git/config and then triggering rce via a poisoned sshCommand on the config file.
CVE-2025-8110HIGHsob ataque11 abr 2026
File overwrite in file update API in Gogs
100RISCO
abrir
GitHub PoC2
Ghxstsec/CVE-2025-8110
CVE-2025-8110HIGHsob ataque11 abr 2026
File overwrite in file update API in Gogs
100RISCO
abrir
GitHub PoC2
CVE-2025-8110 — Gogs <= 0.13.3 Arbitrary File Write via Symlink Traversal in PutContents API
CVE-2025-8110HIGHsob ataque11 abr 2026
File overwrite in file update API in Gogs
100RISCO
abrir
GitHub PoC
CVE-2025-55182 (React2Shell) PoC: Unauthenticated RCE affecting React 19.x and Next.js < 15.1.4. Exploits vulnerabilities in the RSC Flight protocol.
CVE-2025-55182CRITICALsob ataqueransomware10 abr 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Estudio técnico de la vulnerabilidad CVE-2025-5548
CVE-2025-5548MEDIUM10 abr 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISCO
abrir
GitHub PoC2
The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file.
CVE-2023-6553CRITICAL10 abr 2026
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RISCO
abrir
GitHub PoC1
Hunt-Benito/samsung-exynos-sms-stack-overflow-cve-2025-54328-critical-zero-click-baseband-rce
CVE-2025-54328CRITICAL10 abr 2026
An issue was discovered in SMS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 21
48RISCO
abrir
GitHub PoC6
High-interaction honeypot mimicking a vulnerable Laravel/Livewire app. Captures RCE exploits and webshells targeting CVE-2024-47823, CVE-2025-54068, and CVE-2025-14894, then analyzes them in sandboxed Docker containers to extract IOCs.
CVE-2025-54068CRITICALsob ataque10 abr 2026
Livewire vulnerable to remote command execution during property update hydration
100RISCO
abrir
GitHub PoC
CVE-2025-55182 Auto Scanner - Improved Version For authorized CTF/testing purposes only
CVE-2025-55182CRITICALsob ataqueransomware10 abr 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
powerfull rust cve-2025-55182-scanner used for ctf & ethical purpose only
CVE-2025-55182CRITICALsob ataqueransomware10 abr 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Browser-based MCP CTF — OAuth token confusion and session isolation failure (CVE-2025-49596 pattern). DevTools only.
CVE-2025-49596CRITICAL10 abr 2026
MCP Inspector proxy server lacks authentication between the Inspector client and proxy
75RISCO
abrir
GitHub PoC3
MCPJam Inspector is a local-first development platform for MCP servers. In versions 1.4.2 (and earlier), a RCE flaw lets attackers send crafted HTTP request that installs an MCP server and runs code remotely, because the service listens on 0.0.0.0 (instead of 127.0.0.1) by default.
CVE-2026-23744CRITICAL10 abr 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
GitHub PoC
CVE-2021-22911 Rocket.Chat NoSQL Injection RCE Exploit - Educational Purpose
CVE-2021-2291110 abr 2026
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISCO
abrir
GitHub PoC
PoC of CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware10 abr 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Demo to remediate CVE-2023-20198 using forward networks and tines
CVE-2023-20198CRITICALsob ataque10 abr 2026
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISCO
abrir
GitHub PoC
Educational Proof-of-Concept for the CVE-2022-30190 (Follina) vulnerability.
CVE-2022-30190HIGHsob ataqueransomware10 abr 2026
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
Improper Access Control in Mysterium Node before v1.36.0
CVE-2026-31309CRITICAL10 abr 2026
Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows a
48RISCO
abrir
GitHub PoC
CVE-2025-32433
CVE-2025-32433CRITICALsob ataque09 abr 2026
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
GitHub PoC1
Unauthenticated RCE vulnerability in Fuel CMS 1.4.1.
CVE-2018-1676309 abr 2026
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir
GitHub PoC2
CVE-2025-63353
CVE-2025-63353CRITICAL09 abr 2026
A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-s
48RISCO
abrir
GitHub PoC
CVE-2024-3094 - XZ Utils Backdoor
CVE-2024-3094CRITICAL09 abr 2026
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC
Xibo CMS CVE-2023-33177 Vulnerability Tester
CVE-2023-33177HIGH09 abr 2026
Xibo CMS vulnerable to Remote Code Execution through Zip Slip
41RISCO
abrir
GitHub PoC
kaleth4/CVE-2014-6271
CVE-2014-6271CRITICALsob ataque09 abr 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC
Exploiting WordPress vulnerabilities (CVE-2025-34077), authentication bypass via cookie injection, and privilege escalation to root. Part of my Cybersecurity Specialization.
CVE-2025-34077CRITICAL09 abr 2026
WordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCE
68RISCO
abrir
GitHub PoC
kaleth4/-CVE-2014-6271
CVE-2014-6271CRITICALsob ataque09 abr 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
anteriorpágina 111 / 509próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.