Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.184exploits catalogados
37.029CVEs com exploração pública
24.695testados em laboratório
15.321 exploits
GitHub PoC
open-flaw/CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware19 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC16
Detection for CVE-2025-68461
CVE-2025-68461HIGHsob ataque19 dez 2025
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the ani
76RISCO
abrir
GitHub PoC3
Fox LMS – WordPress LMS Plugin 1.0.4.7 - 1.0.5.1 - Unauthenticated Privilege Escalation via 'createOrder'
CVE-2025-14156CRITICAL18 dez 2025
Fox LMS – WordPress LMS Plugin 1.0.4.7 - 1.0.5.1 - Unauthenticated Privilege Escalation via 'createOrder'
48RISCO
abrir
GitHub PoC
React2Shell Vulnerability Verification Script (React2Shell also known as CVE-2025-55182).
CVE-2025-55182CRITICALsob ataqueransomware18 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Lightweight Go toolkit plus a Dockerized Next.js lab to explore and triage CVE-2025-55182.
CVE-2025-55182CRITICALsob ataqueransomware18 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Proof of Concept for Authenticated RCE in Crafty Controller
CVE-2025-14700CRITICAL18 dez 2025
Improper Neutralization of Special Elements Used in a Template Engine in Crafty Controller
48RISCO
abrir
GitHub PoC
cyberok-org/CVE-2025-67887
CVE-2025-67887CRITICAL18 dez 2025
1C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Transla
48RISCO
abrir
GitHub PoC4
This is a Proof-Of-Concept of CVE-2025-63353
CVE-2025-63353CRITICAL18 dez 2025
A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-s
48RISCO
abrir
GitHub PoC1
CVE-2025-40602 is a local privilege escalation vulnerability in the appliance management console (AMC) of SonicWall Secure Mobile Access (SMA) 1000 series appliances.
CVE-2025-40602MEDIUMsob ataque18 dez 2025
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance manageme
63RISCO
abrir
GitHub PoC
This repo describes about cve-2021-29447 and a small script for exploiting automatically
CVE-2021-29447HIGH18 dez 2025
WordPress Authenticated XXE attack when installation is running PHP 8
63RISCO
abrir
GitHub PoC2
Detection for CVE-2025-37164
CVE-2025-37164CRITICALsob ataque18 dez 2025
A remote code execution issue exists in HPE OneView.
100RISCO
abrir
GitHub PoC
Bitrix24 <= 25.100.300 (Translate Module) Remote Code Execution Vulnerability
CVE-2025-67886MEDIUM18 dez 2025
Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translat
33RISCO
abrir
GitHub PoC4
React2Shell (CVE-2025-66478): A Python-based Proof of Concept for Critical Remote Code Execution (RCE) in Next.js Server Components. Features an interactive CLI, custom payload injection, and cleaner output formatting. For educational research only.
CVE-2025-55182CRITICALsob ataqueransomware18 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
rashedhasan090/cve-2025-55182-mitigator
CVE-2025-55182CRITICALsob ataqueransomware18 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
1C-Bitrix <= 25.100.500 (Translate Module) Remote Code Execution Vulnerability
CVE-2025-67887CRITICAL18 dez 2025
1C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Transla
48RISCO
abrir
GitHub PoC
Control Web Panel <= 0.9.8.1208 (admin/index.php) OS Command Injection Vulnerability • Software Link:
CVE-2025-67888HIGH18 dez 2025
An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /
56RISCO
abrir
GitHub PoC3
Detection for CVE-2025-40602
CVE-2025-40602MEDIUMsob ataque18 dez 2025
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance manageme
63RISCO
abrir
GitHub PoC
POC for CVE-2025-33053 WebDav Exploit, demonstrating how the vulnerability can be triggered in a real environment. This repository focuses on hands-on exploitation steps, reproducible test cases, and observable impact, helping security researchers and defenders understand the issue and validate fixes.
CVE-2025-33053HIGHsob ataque18 dez 2025
Internet Shortcut Files Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC2
Cisco is aware of a potential vulnerability.&nbsp; Cisco is currently investigating and&nbsp;will update these details as appropriate&nbsp;as more information becomes available.
CVE-2025-20393CRITICALsob ataque18 dez 2025
Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability
83RISCO
abrir
GitHub PoC
KingHacker353/CVE-2025-20393
CVE-2025-20393CRITICALsob ataque18 dez 2025
Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability
83RISCO
abrir
GitHub PoC22
Script to detect CVE-2025-20393 for Cisco Secure Email Gateway And Cisco Secure Email and Web Manager
CVE-2025-20393CRITICALsob ataque18 dez 2025
Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability
83RISCO
abrir
GitHub PoC9
Proof-of-Concept exploit for CVE-2025-14174 (EUVD-2025-203113) - Memory corruption in ANGLE allowing out-of-bounds access and RCE in web browsers. Reliable on iOS/Android/Windows, including patched systems with incomplete fixes.
CVE-2025-14174HIGHsob ataque18 dez 2025
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perfor
76RISCO
abrir
GitHub PoC2
Proof-of-concept research tool for CVE-2025-55182, a critical unauthenticated RCE in Next.js App Router caused by server-side object injection in React Server Components and Server Actions, including UTF-16LE WAF evasion techniques.
CVE-2025-55182CRITICALsob ataqueransomware17 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC6
Fortinet announced two closely related authentication‑bypass vulnerabilities on 9 December 2025. Both flaws involve improper verification of cryptographic signatures (CWE‑347) in the handling of SAML responses for the FortiCloud SSO login feature.
CVE-2025-59718CRITICALsob ataque17 dez 2025
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0
90RISCO
abrir
GitHub PoC1
proof-of-concept mass scanner targeting JetBrains TeamCity instances affected by CVE-2024-27198
CVE-2024-27198CRITICALsob ataqueransomware17 dez 2025
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir
GitHub PoC
React2shell vulnerable lab (CVE-2025-55182)
CVE-2025-55182CRITICALsob ataqueransomware17 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Improved poc of CVE-2017-0785 on DS-MDP002
CVE-2017-078517 dez 2025
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RISCO
abrir
GitHub PoC1
Proof of Concept for Authenticated RCE in Crafty Controller <= 4.6.1
CVE-2025-14700CRITICAL17 dez 2025
Improper Neutralization of Special Elements Used in a Template Engine in Crafty Controller
48RISCO
abrir
GitHub PoC
An advanced vulnerability scanner for detecting **CVE-2025-55182** and **CVE-2025-66478** - critical Remote Code Execution (RCE) vulnerabilities in Next.js applications using React Server Components (RSC).
CVE-2025-55182CRITICALsob ataqueransomware16 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
React2Shell Exploitation Tool (CVE-2025-55182)
CVE-2025-55182CRITICALsob ataqueransomware16 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
anteriorpágina 148 / 511próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.