Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.184exploits catalogados
37.029CVEs com exploração pública
24.695testados em laboratório
15.321 exploits
GitHub PoC
Vuln lab for CVE-2024-3408 - D-Tale Authentication Bypass & RCE
CVE-2024-3408CRITICAL22 dez 2025
Authentication Bypass and RCE in man-group/dtale
85RISCO
abrir
GitHub PoC28
Detection for CVE-2025-68613
CVE-2025-68613CRITICALsob ataque22 dez 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISCO
abrir
GitHub PoC25
Public PoC + Scanner and research for CVE-2025-68613: Critical RCE in n8n Workflow Automation via Expression Injection (CVSS 10.0). Includes detection tools, full exploit, and remediation guidance.
CVE-2025-68613CRITICALsob ataque22 dez 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISCO
abrir
GitHub PoC6
A C++ security scanner tool to detect Cross-Site Scripting (XSS) vulnerabilities in Roundcube Webmail installations.
CVE-2025-68461HIGHsob ataque22 dez 2025
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the ani
76RISCO
abrir
GitHub PoC
CVE-2025-68613
CVE-2025-68613CRITICALsob ataque22 dez 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISCO
abrir
GitHub PoC98
CVE-2025-68613: n8n RCE vulnerability exploit and documentation
CVE-2025-68613CRITICALsob ataque22 dez 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISCO
abrir
GitHub PoC13
React2Shell: An exploitation framework for CVE-2025-55182 (Next.js/React RCE).
CVE-2025-55182CRITICALsob ataqueransomware22 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
zaydbf/CVE-2025-9074-Poc
CVE-2025-9074CRITICAL22 dez 2025
Docker Desktop allows unauthenticated access to Docker Engine API from containers
48RISCO
abrir
GitHub PoC
Security research on Fortinet FortiWeb vulnerabilities (CVE-2025-64446, CVE-2025-58034)
CVE-2025-64446CRITICALsob ataque21 dez 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISCO
abrir
GitHub PoC
nicolasdamians/ms09-050-CVE-2009-3103-exploit
CVE-2009-310321 dez 2025
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RISCO
abrir
GitHub PoC1
NextJS exploiter for CVE-2025-55182 and more.
CVE-2025-55182CRITICALsob ataqueransomware21 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Test & Analyze the CVE-2025-55182 vulnerability within Next.js Server Actions
CVE-2025-55182CRITICALsob ataqueransomware21 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
CVE-2023-32315(java7)
CVE-2023-32315HIGHsob ataque21 dez 2025
Openfire administration console authentication bypass
100RISCO
abrir
GitHub PoC106
This is a proof of concept for CVE-2025-38352, a vulnerability in the Linux kernel's POSIX CPU timers implementation. The September 2025 Android Bulletin mentions that this vulnerability has been used in limited, targeted exploitation in the wild.
CVE-2025-38352HIGHsob ataque21 dez 2025
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
71RISCO
abrir
GitHub PoC1
PoC exploit for CVE-2018-11736 affecting Pluck CMS versions prior to 4.7.7-dev2 with a File Upload Vulnerability
CVE-2018-1173621 dez 2025
An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute a
23RISCO
abrir
GitHub PoC4
Hello friend. This is the Fsociety Exploit Framework for CVE-2025-24071. Generates malicious .library-ms files to steal NTLMv2 hashes. Includes a 'Living Terminal' Cinematic Mode, Deep Trace logging, and stealth evasion techniques. Join the revolution. #Hacking #Exploit #CVE-2025-24071
CVE-2025-24071MEDIUM21 dez 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
GitHub PoC
tamagorengs/react2shell-poc-CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware20 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC13
FreeBSD rtsold DNSSL Command Injection (RCE)
CVE-2025-14558HIGH20 dez 2025
Remote code execution via ND6 Router Advertisements
56RISCO
abrir
GitHub PoC1
A self-hosted vulnerable Next.js environment running on Docker for simulating CVE-2025-55182. Built for educational security research and CTF practice.
CVE-2025-55182CRITICALsob ataqueransomware20 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Secure-by-default demo lab showing how container hardening (distroless images, non-root, read-only filesystem, runtime-injected secrets) can neutralize a critical Next.js/React Server Actions RCE (CVE-2025-55182 “React2Shell”), with side-by-side safe vs unsafe deployments and exploit logs
CVE-2025-55182CRITICALsob ataqueransomware20 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
writeups for (CVE-2025-67586, CVE-2025-67985, CVE-2025-67986)
CVE-2025-67586MEDIUM20 dez 2025
WordPress Highlight and Share plugin <= 5.2.0 - Broken Access Control vulnerability
33RISCO
abrir
GitHub PoC1
CVE-2019-11231 PoC
CVE-2019-1123120 dez 2025
An issue was discovered in GetSimple CMS through 3.3.15. insufficient input sanitation in the theme-edit.php file allows
60RISCO
abrir
GitHub PoC9
CVE-2025-55182 React2Shell PoC - Critical RCE in React Server Components / Next.js. CVSS 10.0. Error-based exfil, reverse shell, interactive mode.
CVE-2025-55182CRITICALsob ataqueransomware20 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC21
RSC Detect CVE 2025 55182
CVE-2025-55182CRITICALsob ataqueransomware20 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
PaperCut NG/MG Authentication Bypass and Remote Code Execution (RCE) Exploit Tool. A standalone Bash implementation of the PaperCut exploit chain, featuring optional proxy support, automated session elevation, and dynamic command injection via the print scripting engine. Designed for security auditing and authorized penetration testing.
CVE-2023-27350CRITICALsob ataqueransomware19 dez 2025
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir
GitHub PoC1
lamaper/CVE-2025-55182-Toolbox
CVE-2025-55182CRITICALsob ataqueransomware19 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
A Python-based security scanner for detecting and exploiting **React Server Components (RSC)** vulnerabilities in Next.js applications. This tool performs passive detection, active fingerprinting, and RCE exploitation testing.
CVE-2025-55182CRITICALsob ataqueransomware19 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC3
React2Shell vulnerability (CVE-2025-55182 / CVE-2025-66478) Full Script
CVE-2025-55182CRITICALsob ataqueransomware19 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC6
PoC for CVE-2025-37164
CVE-2025-37164CRITICALsob ataque19 dez 2025
A remote code execution issue exists in HPE OneView.
100RISCO
abrir
GitHub PoC16
Detection for CVE-2025-68461
CVE-2025-68461HIGHsob ataque19 dez 2025
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the ani
76RISCO
abrir
anteriorpágina 147 / 511próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.