Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.760exploits catalogados
32.083CVEs com exploração pública
1.932testados em laboratório
13.235 exploits
GitHub PoC1
A new way to exploit CVE-2025-58360 bypass WAF
CVE-2025-58360HIGHsob ataque31 dez 2025
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RISCO
abrir
GitHub PoC
Rishi-kaul/CVE-2025-14847-MongoBleed
CVE-2025-14847HIGHsob ataque31 dez 2025
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir
GitHub PoC2
nkuty/CVE-2025-54322-exploit
CVE-2025-54322CRITICAL31 dez 2025
Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid paramete
53RISCO
abrir
GitHub PoC
Goultarde/CVE-2025-55182-React2Shell-Lab
CVE-2025-55182CRITICALsob ataqueransomware31 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Audit de sécurité Black Box d'un serveur Drupal 7. Démonstration d'une Kill Chain complète : Injection SQL (CVE-2014-3704) ➔ RCE ➔ Reverse Shell ➔ Escalade vers Root (SUID). Ce dépôt contient le rapport technique détaillé, les preuves d'exploitation (PoC) et les mesures de remédiation pour sécuriser l'infrastructure.
CVE-2014-370431 dez 2025
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISCO
abrir
GitHub PoC
🎯 Automated vulnerability scanner for React2Shell RCE - Google dorking + safe detection for CVE-2025-55182/CVE-2025-66478 (CVSS 10.0)
CVE-2025-55182CRITICALsob ataqueransomware30 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
This repository provides a proof-of-concept for CVE-2025-55182 (React2Shell), a remote code execution vulnerability in React Server Components. It demonstrates how the exploit works, including the payload and impact.
CVE-2025-55182CRITICALsob ataqueransomware30 dez 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
CVE-2024-4577 PHP CGI Argument Injection - Detection Lab with Vagrant VMs and Wazuh SIEM rules
CVE-2024-4577CRITICALsob ataqueransomware30 dez 2025
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
YanC1e/CVE-2025-8191
CVE-2025-8191MEDIUM30 dez 2025
macrozheng mall Swagger UI index.html cross site scripting
33RISCO
abrir
GitHub PoC
Remake of CVE-2025-14847 MongoDB vulnerability demonstration
CVE-2025-14847HIGHsob ataque30 dez 2025
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir
GitHub PoC
Udyz/CVE-2025-52691
CVE-2025-52691CRITICALsob ataqueransomware30 dez 2025
Upload Arbitrary Files
100RISCO
abrir
GitHub PoC1
This repository contains a safe Proof of Concept (PoC) to detect vulnerable SmarterMail versions affected by CVE‑2025‑52691. The script performs version detection only and does not exploit the vulnerability.
CVE-2025-52691CRITICALsob ataqueransomware30 dez 2025
Upload Arbitrary Files
100RISCO
abrir
GitHub PoC3
An enhanced proof-of-concept exploit for CVE-2025-52691 (SmarterMail Arbitrary File Upload RCE) with APT-level features like stealth obfuscation, persistence, exfiltration, and interactive mode. For educational and authorized testing only. Credits to the original PoC by yt2w/CVE-2025-52691.
CVE-2025-52691CRITICALsob ataqueransomware30 dez 2025
Upload Arbitrary Files
100RISCO
abrir
GitHub PoC
Exploit code for Clinic patient management system v1 unauth rce cpms rce CVE-2022-40471
CVE-2022-40471CRITICAL30 dez 2025
Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via p
68RISCO
abrir
GitHub PoC2
Academic proof-of-concept demonstrating CVE-2025-68645 for authorized security research.
CVE-2025-68645HIGHsob ataque30 dez 2025
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1
98RISCO
abrir
GitHub PoC1
CVE-2025-14847 MongoBleed - MongoDB Memory Leak Vulnerability PoC
CVE-2025-14847HIGHsob ataque30 dez 2025
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir
GitHub PoC
cve-2025-54236 poc
CVE-2025-54236CRITICALsob ataque30 dez 2025
Adobe Commerce | Improper Input Validation (CWE-20)
100RISCO
abrir
GitHub PoC1
This repo contains my python script version of CVE-2025-14847 (MongoBleed)
CVE-2025-14847HIGHsob ataque30 dez 2025
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir
GitHub PoC
nyambiblaise/Microsoft-Windows-SMBGhost-Vulnerability-Checker---CVE-2020-0796---SMBv3-RCE
CVE-2020-0796CRITICALsob ataqueransomware30 dez 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC
Burp Suite extension to detect CVE-2025-14847 (MongoBleed) via manual leak tests from a dedicated UI tab.
CVE-2025-14847HIGHsob ataque30 dez 2025
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir
GitHub PoC19
Detection for CVE-2025-52691
CVE-2025-52691CRITICALsob ataqueransomware30 dez 2025
Upload Arbitrary Files
100RISCO
abrir
GitHub PoC
Rishi-kaul/n8n-CVE-2025-68613
CVE-2025-68613CRITICALsob ataque29 dez 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISCO
abrir
GitHub PoC4
Academic proof-of-concept demonstrating CVE-2025-14847 for authorized security research.
CVE-2025-14847HIGHsob ataque29 dez 2025
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir
GitHub PoC13
Exploit lab, docker and code scanner for mongobleed Vulnerability CVE-2025-14847 plus Phoenix Security Sync tools
CVE-2025-14847HIGHsob ataque29 dez 2025
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir
GitHub PoC
Detect exposed MongoDB instances and CVE-2025-14847 "MongoBleed" risks — Zero-Trust Python scanner
CVE-2025-14847HIGHsob ataque29 dez 2025
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir
GitHub PoC
MongoBleed: CVE-2025-14847 Memory Leak Discovery Tool
CVE-2025-14847HIGHsob ataque29 dez 2025
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir
GitHub PoC
cv-sai-kamesh/n8n-CVE-2025-68613
CVE-2025-68613CRITICALsob ataque29 dez 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISCO
abrir
GitHub PoC1
CVE-2025-14847 – MongoDB Unauthenticated Memory‑Leak Exploit
CVE-2025-14847HIGHsob ataque29 dez 2025
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir
GitHub PoC1
aexdyhaxor/CVE-2025-32463
CVE-2025-32463CRITICALsob ataque29 dez 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC
Context-Aware Memory Leak Scanner & Exploit for CVE-2025-14847.
CVE-2025-14847HIGHsob ataque29 dez 2025
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir
anteriorpágina 85 / 442próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.