Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.930exploits catalogados
37.572CVEs com exploração pública
24.695testados em laboratório
80.842 exploits
GitHub PoC2
oways/React2shell-CVE-2025-55182-checker
CVE-2025-55182CRITICALsob ataqueransomware04 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
Exploit-DB
phpMyFAQ 2.9.8 - Cross-Site Request Forgery(CSRF)
CVE-2017-15734webappsphp03 dez 2025
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.main.php.
23RISCO
abrir
Exploit-DB
phpMyFaq 2.9.8 - Cross Site Request Forgery (CSRF)
CVE-2017-15808webappsphp03 dez 2025
In phpMyFaq before 2.9.9, there is CSRF in admin/ajax.config.php.
23RISCO
abrir
GitHub PoC111
A non-intrusive surface scanner for CVE-2025-55182 (React Server Components RCE). Detects exposed RSC endpoints in React 19 and Next.js applications
CVE-2025-55182CRITICALsob ataqueransomware03 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC12
Script to quick check CVE-2025-55182 (React) and CVE-2025-66478 (Next.js) - Critical unauthenticated RCE vulnerabilities in the React Server Components (RSC) “Flight” protocol.
CVE-2025-55182CRITICALsob ataqueransomware03 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-46747CRITICALsob ataqueransomware03 dez 2025
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RISCO
abrir
Exploit-DB
RosarioSIS 6.7.2 - Cross Site Scripting (XSS)
CVE-2020-15716webappsphp03 dez 2025
RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Preferences.php scrip
23RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-2646903 dez 2025
In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server.
60RISCO
abrir
VulnCheck XDB
local
CVE-2019-10149CRITICALsob ataque03 dez 2025
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISCO
abrir
Exploit-DB
phpMyFAQ 2.9.8 - Cross-Site Request Forgery (CSRF)
CVE-2017-15735webappsphp03 dez 2025
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for modifying a glossary.
23RISCO
abrir
Exploit-DB
openSIS Community Edition 8.0 - SQL Injection
CVE-2021-40617webappsphp03 dez 2025
An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php.
23RISCO
abrir
Metasploit600
Unauthenticated RCE in React Server Components (React2Shell)
CVE-2025-55182CRITICALsob ataqueransomware03 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
0xDTC/XWiki-Platform-RCE-CVE-2025-24893
CVE-2025-24893CRITICALsob ataque03 dez 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC
Exploit and test stand for CVE-2025-41115
CVE-2025-41115CRITICAL03 dez 2025
Incorrect privilege assignment
53RISCO
abrir
GitHub PoC792
CVE-2025-55182 POC
CVE-2025-55182CRITICALsob ataqueransomware03 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
Metasploit600
Unauthenticated RCE in React Server Components (React2Shell)
CVE-2025-6647803 dez 2025
15RISCO
abrir
Exploit-DB
OpenRepeater 2.1 - OS Command Injection
CVE-2019-25024webappsphp03 dez 2025
OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_sy
28RISCO
abrir
Exploit-DB
phpIPAM 1.4 - SQL-Injection
CVE-2019-16693webappsphp03 dez 2025
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.
23RISCO
abrir
Exploit-DB
RosarioSIS 6.7.2 - Cross-Site Scripting (XSS)
CVE-2020-15718webappsphp03 dez 2025
RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php sc
38RISCO
abrir
GitHub PoC14
CVE-2025-55182 - React Server Components RCE Exploit & Scanner Supports external servers and CLI interface
CVE-2025-55182CRITICALsob ataqueransomware03 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Untested completition of the Redishell PoC made by AI
CVE-2025-49844CRITICAL03 dez 2025
Redis Lua Use-After-Free may lead to remote code execution
85RISCO
abrir
Exploit-DB
PluckCMS 4.7.10 - Unrestricted File Upload
CVE-2020-20969HIGHwebappsphp03 dez 2025
File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_resto
41RISCO
abrir
Exploit-DB
MobileDetect 2.8.31 - Cross-Site Scripting (XSS)
CVE-2018-25080LOWwebappsphp03 dez 2025
MobileDetect Example session_example.php initLayoutType cross site scripting
28RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALsob ataque03 dez 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
Exploit-DB
MaNGOSWebV4 4.0.6 - Reflected XSS
CVE-2017-6478webappsmultiple03 dez 2025
paintballrefjosh/MaNGOSWebV4 before 4.0.8 is vulnerable to a reflected XSS in install/index.php (step parameter).
38RISCO
abrir
GitHub PoC4
#F5-BIG-IP-CVE-2023-46747-Exploit – Unauthenticated RCE Python exploit & Nuclei template by Raguraman ✓ Automated TCP reverse shell (LHOST/LPORT) ✓ Tested on affected BIG-IP 13.x–17.x ⚠️ Authorized pentesting only
CVE-2023-46747CRITICALsob ataqueransomware03 dez 2025
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RISCO
abrir
Exploit-DB
Django 5.1.13 - SQL Injection
CVE-2025-64459CRITICALwebappsmultiple03 dez 2025
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RISCO
abrir
GitHub PoC
DaniilOrchikov/PIL-CVE-2017-8291
CVE-2017-8291HIGHsob ataque03 dez 2025
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion
100RISCO
abrir
GitHub PoC4
santihabib/CVE-2025-55182-analysis
CVE-2025-55182CRITICALsob ataqueransomware03 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
CVE-2025-55182 - React Server Components RCE Exploit & Scanner Supports external servers and CLI interface
CVE-2025-55182CRITICALsob ataqueransomware03 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
anteriorpágina 246 / 2.695próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.