Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.842exploits catalogados
37.493CVEs com exploração pública
24.695testados em laboratório
80.753 exploits
GitHub PoC
React2Shell (CVE-2025-55182) scanner
CVE-2025-55182CRITICALsob ataqueransomware11 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC3
A Chrome extension for detecting React2Shell vulnerabilities (CVE-2025-55182 & CVE-2025-66478) in web applications
CVE-2025-55182CRITICALsob ataqueransomware11 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Docker test environment for CVE-2025-34299 - Monsta FTP Pre-Auth RCE vulnerability
CVE-2025-34299CRITICAL11 dez 2025
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RISCO
abrir
GitHub PoC
min8282/CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware11 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC1
Exploitation of a Remote Code Execution vulnerability- (CVE-2024-7954)
CVE-2024-7954CRITICAL11 dez 2025
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISCO
abrir
GitHub PoC2
Nkwenti-Severian-Ndongtsop/POC_react2shell_CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware11 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
CVE-2025-55182 & CVE-2025-66478 proof of concepts
CVE-2025-55182CRITICALsob ataqueransomware11 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC5
This tool is a Proof of Concept (PoC) intended for security research and educational purposes only. Using this tool on systems without explicit permission is illegal and punishable by law. The author (Tiger-Foxx) assumes no responsibility for misuse.
CVE-2025-55182CRITICALsob ataqueransomware11 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC1
CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware11 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
Metasploit600
FreePBX endpoint SQLi to RCE
CVE-2025-66039CRITICAL11 dez 2025
FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header
63RISCO
abrir
GitHub PoC
Modified ruby script for RCE
CVE-2013-015611 dez 2025
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RISCO
abrir
Metasploit600
FreePBX endpoint SQLi to RCE
CVE-2025-61675HIGH11 dez 2025
FreePBX Endpoint Manager vulnerable to authenticated SQL injection in multiple configuration parameters
48RISCO
abrir
Metasploit600
FreePBX firmware file upload
CVE-2025-66039CRITICAL11 dez 2025
FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header
63RISCO
abrir
Metasploit600
FreePBX firmware file upload
CVE-2025-61678HIGH11 dez 2025
FreePBX Endpoint Manager vulnerable to authenticated arbitrary file upload via fwbrand parameter
48RISCO
abrir
Metasploit300
FreePBX Custom Extension SQL Injection
CVE-2025-66039CRITICAL11 dez 2025
FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header
63RISCO
abrir
Metasploit300
FreePBX Custom Extension SQL Injection
CVE-2025-61675HIGH11 dez 2025
FreePBX Endpoint Manager vulnerable to authenticated SQL injection in multiple configuration parameters
48RISCO
abrir
GitHub PoC3
Interactive visualization of the React2Shell (CVE-2025-55182) RCE vulnerability with narrated animations for three audiences: Expert, Practitioner, and Stakeholder. Audio synced via ElevenLabs + Whisper.
CVE-2025-55182CRITICALsob ataqueransomware11 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-8110HIGHsob ataque11 dez 2025
File overwrite in file update API in Gogs
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-34299CRITICAL11 dez 2025
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2013-015611 dez 2025
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RISCO
abrir
GitHub PoC1
CVE-2021-4045 CVE-2021-4045 is a Command Injection vulnerability that allows Remote Code Execution in the TP-Link Tapo c200 IP camera. It affects all firmware versions prior to 1.1.16 Build 211209 Rel. 37726N due to insufficient checks on user input in uhttpd, which is one of the main binaries of the device.
CVE-2021-4045CRITICAL11 dez 2025
TP-LINK Tapo C200 remote code execution vulnerability
70RISCO
abrir
GitHub PoC
Legus-Yeung/CVE-2025-55182-exploit
CVE-2025-55182CRITICALsob ataqueransomware10 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Proof-of-Concept exploit for CVE-2025-9074
CVE-2025-9074CRITICAL10 dez 2025
Docker Desktop allows unauthenticated access to Docker Engine API from containers
48RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-33073HIGHsob ataque10 dez 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware10 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC3
A CTF challenge based on CVE-2025-55182 Vulnerability
CVE-2025-55182CRITICALsob ataqueransomware10 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-24071MEDIUM10 dez 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISCO
abrir
GitHub PoC6
A command-line tool for detecting CVE-2025-55182 and CVE-2025-66478 in Next.js applications using React Server Components.
CVE-2025-55182CRITICALsob ataqueransomware10 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
A portable Bash script to detect vulnerable versions of React Server DOM and Next.js packages affected by [CVE-2025-55182]
CVE-2025-55182CRITICALsob ataqueransomware10 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-1974CRITICAL10 dez 2025
ingress-nginx admission controller RCE escalation
85RISCO
abrir
anteriorpágina 228 / 2.692próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.