Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.930exploits catalogados
37.572CVEs com exploração pública
24.695testados em laboratório
80.842 exploits
GitHub PoC
CVE-2025-55182 - React Server Components RCE Exploit & Scanner Supports external servers and CLI interface
CVE-2025-55182CRITICALsob ataqueransomware03 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
towaos/towaos-lab-cve-2020-11023
CVE-2020-11023MEDIUMsob ataque02 dez 2025
Potential XSS vulnerability in jQuery
85RISCO
abrir
GitHub PoC
boro03/CVE-2021-4034
CVE-2021-4034HIGHsob ataqueransomware02 dez 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
Metasploit600
WordPress ACF Extended Unauthenticated RCE via prepare_form()
CVE-2025-13486CRITICAL02 dez 2025
Advanced Custom Fields: Extended 0.9.0.5 - 0.9.1.1 - Unauthenticated Remote Code Execution in prepare_form
75RISCO
abrir
Exploit-DB
phpIPAM 1.6 - Reflected Cross-Site Scripting (XSS)
CVE-2024-41358MEDIUMwebappsphp02 dez 2025
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php.
33RISCO
abrir
GitHub PoC1
PoC for testing CVE-2025-29927 for Next.js versions 11.x, 12.x <= 12.3.5, 13.x <= 13.5.9, 14.x <=14.2.25, 15.x <= 15.2.3
CVE-2025-29927CRITICAL02 dez 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC1
Jorge2Rubio/CVE-2019-0232
CVE-2019-023202 dez 2025
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-023202 dez 2025
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-7494CRITICALsob ataqueransomware02 dez 2025
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2025-29927CRITICAL02 dez 2025
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
Vulnerable environment for testing CVE-2021-22941 Nuclei template
CVE-2021-22941CRITICALsob ataqueransomware02 dez 2025
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacke
90RISCO
abrir
VulnCheck XDB
local
CVE-2021-21551HIGHsob ataque02 dez 2025
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RISCO
abrir
Exploit-DB
phpMyFAQ 3.1.7 - Reflected Cross-Site Scripting (XSS)
CVE-2022-3766HIGHwebappsmultiple02 dez 2025
Cross-site Scripting (XSS) - Reflected in thorsten/phpmyfaq
56RISCO
abrir
GitHub PoC
sudlit/CVE-2017-7494
CVE-2017-7494CRITICALsob ataqueransomware02 dez 2025
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISCO
abrir
GitHub PoC
This repo contain a PoC I have done when blind analysis the dbutil_2_3.sys driver for vulnerability. This was created by personal analysis without looking at writeups or even know which CVE exist in this driver. All the knowledge I have is that this driver is vulnerable in some way.
CVE-2021-21551HIGHsob ataque02 dez 2025
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RISCO
abrir
Exploit-DB
phpIPAM 1.6 - Reflected-Cross-Site Scripting (XSS)
CVE-2024-41357HIGHwebappsphp02 dez 2025
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.
41RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-43300CRITICALsob ataque02 dez 2025
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1
83RISCO
abrir
Exploit-DB
Piwigo 13.6.0 - SQL Injection
CVE-2023-33362CRITICALwebappsphp02 dez 2025
Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function.
48RISCO
abrir
Exploit-DB
phpIPAM 1.5.1 - SQL Injection
CVE-2023-1211HIGHwebappsphp02 dez 2025
SQL Injection in phpipam/phpipam
41RISCO
abrir
Exploit-DB
YOURLS 1.8.2 - Cross-Site Request Forgery (CSRF)
CVE-2022-0088LOWwebappsmultiple02 dez 2025
Cross-Site Request Forgery (CSRF) in yourls/yourls
28RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-6440CRITICAL01 dez 2025
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISCO
abrir
Metasploit600
Grav CMS Twig SSTI Authenticated Sandbox Bypass RCE
CVE-2025-66301HIGH01 dez 2025
Grav ihas Broken Access Control which allows an Editor to modify the page's YAML Frontmatter to alter form processing actions
36RISCO
abrir
Metasploit600
Eclipse Che machine-exec Unauthenticated RCE
CVE-2025-12548CRITICAL01 dez 2025
Github.com/che-incubator/che-code: eclipse che — unauthenticated rce and secret exfiltration via tcp/3333
43RISCO
abrir
Metasploit600
Grav CMS Twig SSTI Authenticated Sandbox Bypass RCE
CVE-2025-66294HIGH01 dez 2025
Grav is vulnerable to RCE via SSTI through Twig Sandbox Bypass
36RISCO
abrir
GitHub PoC
letsr00t/CVE-2013-2094
CVE-2013-2094HIGHsob ataque01 dez 2025
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data t
83RISCO
abrir
GitHub PoC2
Vulnerability: SQL Injection via QuerySet and Q() keyword argument unpacking. CVE ID: CVE-2025-64459 Severity: Critical (CVSS 9.1) Affected Versions: Django 5.1 < 5.1.14, 4.2 < 4.2.26, and 5.2 < 5.2.8. Researcher: Cyberstan (University of Warwick)
CVE-2025-64459CRITICAL01 dez 2025
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RISCO
abrir
VulnCheck XDB
infoleak
CVE-2021-2198001 dez 2025
The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with n
23RISCO
abrir
GitHub PoC8
Reverse engineering research and custom firmware for the Allwinner V3-based SJCAM SJ4000 Air, including firmware parsers, an AVIOCTRL client, security research, and the CVE-2026-52656 proof of concept.
CVE-2026-52656CRITICAL01 dez 2025
An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an a
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-919301 dez 2025
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-21413CRITICALsob ataque30 nov 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir
anteriorpágina 247 / 2.695próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.