Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.790exploits catalogados
37.482CVEs com exploração pública
24.695testados em laboratório
80.750 exploits
GitHub PoC
This is a lab for reproducing CVE-2025-55182.
CVE-2025-55182CRITICALsob ataqueransomware24 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
验证 Gogs 版本 0.13.2 是否存在 **CVE-2025-8110 (符号链接文件覆盖)** 漏洞。
CVE-2025-8110HIGHsob ataque24 dez 2025
File overwrite in file update API in Gogs
100RISCO
abrir
GitHub PoC
Technical audit of Kioptrix Level 1. Focus: Samba 2.2.1a exploitation (CVE-2003-0201), manual enumeration, and internal infrastructure hardening.
CVE-2003-020124 dez 2025
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x vers
60RISCO
abrir
VulnCheck XDB
client-side
CVE-2017-20192HIGH24 dez 2025
Formidable Form Builder < 2.05.03 - Unauthenticated Stored Cross-Site Scripting
56RISCO
abrir
GitHub PoC
🛡️ Explore CVE-2025-55182, a critical RCE vulnerability in React's Flight Protocol, demonstrating exploitation techniques and mitigation strategies.
CVE-2025-55182CRITICALsob ataqueransomware24 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware24 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
AnGrY-Althaf/CVE-2024-40110
CVE-2024-40110CRITICAL24 dez 2025
Sourcecodester Poultry Farm Management System v1.0 contains an Unauthenticated Remote Code Execution (RCE) vulnerability
48RISCO
abrir
GitHub PoC2
A evolved version of assetnote CVE-2025-55182 scanner
CVE-2025-55182CRITICALsob ataqueransomware24 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-8110HIGHsob ataque24 dez 2025
File overwrite in file update API in Gogs
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALsob ataque23 dez 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2023-44487HIGHsob ataque23 dez 2025
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALsob ataque23 dez 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-54068CRITICALsob ataque23 dez 2025
Livewire vulnerable to remote command execution during property update hydration
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware23 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
a controlled environment to test CVE-2025-55182.
CVE-2025-55182CRITICALsob ataqueransomware23 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC6
RCE exploit PoC for CVE-2025-55182 and CVE-2025-66478 in Next.js and React Server Components with scanner and exploitation tools.
CVE-2025-55182CRITICALsob ataqueransomware23 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC2
CVE-2025-62215: Windows Kernel Race Condition + Double-Free EoP
CVE-2025-62215HIGHsob ataque23 dez 2025
Windows Kernel Elevation of Privilege Vulnerability
71RISCO
abrir
VulnCheck XDB
local
CVE-2021-3493HIGHsob ataque23 dez 2025
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISCO
abrir
GitHub PoC1
js2py sandbox escape to reverse shell
CVE-2024-39205CRITICAL23 dez 2025
An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a
68RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-68613CRITICALsob ataque23 dez 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-68613CRITICALsob ataque23 dez 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISCO
abrir
GitHub PoC
Ushbu videoda Metasploitable 2 tizimidagi distccd servisidagi zaiflikdan foydalanib, Kali Linux orqali remote shell olish ko‘rsatib beriladi.
CVE-2004-268723 dez 2025
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote at
60RISCO
abrir
GitHub PoC
My poc to exploit this vuln :D
CVE-2025-68613CRITICALsob ataque23 dez 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISCO
abrir
GitHub PoC146
A tool designed to exploit CVE-2025-54068 and Remote Command Execution if the APP_KEY of the Livewire project is known.
CVE-2025-54068CRITICALsob ataque23 dez 2025
Livewire vulnerable to remote command execution during property update hydration
100RISCO
abrir
GitHub PoC
CVE-2021-3493 OverlayFS privilege escalation exploit framework with advanced red team features. Includes persistence mechanisms, post-exploitation modules, stealth capabilities, and comprehensive documentation. For authorized testing only.
CVE-2021-3493HIGHsob ataque23 dez 2025
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISCO
abrir
GitHub PoC
This repository contains a laboratory-grade analysis and a **safe Proof-of-Concept** for the vulnerability **CVE-2025-68613**, affecting the workflow automation platform **n8n**.
CVE-2025-68613CRITICALsob ataque23 dez 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISCO
abrir
GitHub PoC
POC for CVE-2025-68613
CVE-2025-68613CRITICALsob ataque23 dez 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISCO
abrir
GitHub PoC
通过GitHub Copilot 辅助分析CVE-2025-68613漏洞
CVE-2025-68613CRITICALsob ataque23 dez 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISCO
abrir
GitHub PoC
ali-py3/Exploit-CVE-2025-68613
CVE-2025-68613CRITICALsob ataque23 dez 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISCO
abrir
GitHub PoC
PoC for HTTP/2 Rapid Reset DDoS Vulnerability - CVE-2023-44487
CVE-2023-44487HIGHsob ataque23 dez 2025
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISCO
abrir
anteriorpágina 218 / 2.692próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.