Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
14.946 exploits
GitHub PoC2
Learn how I found my first two CVEs by pure accident.
CVE-2026-19745MEDIUM29 ago 2026
Calix GigaSpire Web Management utilities_configurationsave.cgi denial of service
33RISCO
abrir
GitHub PoC
joaovicdev/EXPLOIT-CVE-2026-9198
CVE-2026-9198CRITICALsob ataque29 ago 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISCO
abrir
GitHub PoC
FranklinF25/cve-2026-42533
CVE-2026-42533CRITICAL29 ago 2026
NGINX Map directive and Regex matching vulnerability
48RISCO
abrir
GitHub PoC
SOC investigation of a CVE-2024-49138 exploitation alert using log analysis, threat intelligence, and endpoint containment.
CVE-2024-49138HIGHsob ataque29 ago 2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC
Static XML fixtures for authorized bug bounty testing of XML parser behaviour (CVE-2026-45071).
CVE-2026-45071HIGH29 ago 2026
Symfony: XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse = true
41RISCO
abrir
GitHub PoC
morzelowski/CVE-2026-12243-NLTK-PoC
CVE-2026-1224329 ago 2026
23RISCO
abrir
GitHub PoC1
hideki233/CVE-2025-3248-Langflow-RCE
CVE-2025-3248CRITICALsob ataqueransomware28 ago 2026
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
GitHub PoC
CVE-2023-27350, CVE-2023-27351 - PaperCut - Draft or TODO
CVE-2023-27350CRITICALsob ataqueransomware28 ago 2026
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir
GitHub PoC
Testing CVE-2026-70463 by Fyyre
CVE-2026-70463HIGH28 ago 2026
rsync 3.1.0 < 3.5.0 Authorization Bypass via auth users Directive Parsing
41RISCO
abrir
GitHub PoC
fastjson-cve-2026-16723
CVE-2026-16723CRITICAL28 ago 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISCO
abrir
GitHub PoC
Jenkins CVE-2024-23897 — CSRF-crumb aware PoC
CVE-2024-23897CRITICALsob ataqueransomware28 ago 2026
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
GitHub PoC
Wazuh Rules for Detection Zimbra (CVE-2026-73570).
CVE-2026-73570HIGHsob ataque28 ago 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
91RISCO
abrir
GitHub PoC
IKEv1 VPN scanners, attempts a Check Point authentication-bypass exploit, and includes internal network scanning and reverse-shell features.
CVE-2026-50751CRITICALsob ataqueransomware28 ago 2026
User Authentication Bypass in VPN Remote Access and Mobile Access
100RISCO
abrir
GitHub PoC
CVE-2026-33017 - Langflow Unauthenticated RCE Exploit
CVE-2026-33017CRITICALsob ataque28 ago 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir
GitHub PoC
CVE-2026-33017 PoC Reverse Shell
CVE-2026-33017CRITICALsob ataque28 ago 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir
GitHub PoC
Hari-v542/CVE-2026-52923
CVE-2026-52923HIGH28 ago 2026
ipc: limit next_id allocation to the valid ID range
41RISCO
abrir
GitHub PoC1
poc and yara rules
CVE-2025-59528CRITICAL28 ago 2026
Flowise has Remote Code Execution vulnerability
85RISCO
abrir
GitHub PoC
Cacti 1.2.22 unauthenticated command injection
CVE-2022-46169CRITICALsob ataque28 ago 2026
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC
I know you are probably here from Hack the Box, if so, yes this one actually works.
CVE-2025-55182CRITICALsob ataqueransomware28 ago 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
A specialized Python framework that executes unauthenticated remote code execution via the 9Router Model Context Protocol (MCP) bridge by deploying a 33-layer temporal phase cascade, Riemann-Hadamard dispersion, and an 11 ns wedge filter to bypass traditional proxy and process-monitoring defenses.
CVE-2026-46339CRITICAL28 ago 2026
9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
63RISCO
abrir
GitHub PoC
A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass
CVE-2026-24061CRITICALsob ataque28 ago 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
CVE-2026-66384 - Draft or TODO
CVE-2026-66384MEDIUM28 ago 2026
Authenticated users may write data outside the intended Docker cache path
33RISCO
abrir
GitHub PoC
Oracle WebLogic Console unauthenticated auth bypass + RCE exploit (CVE-2020-14882 / CVE-2020-14750)
CVE-2020-14882CRITICALsob ataque27 ago 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC1
CVE-2026-18431 - Draft or TODO
CVE-2026-18431CRITICAL27 ago 2026
Avada <= 7.16 and Fusion Builder <= 3.16 - Unauthenticated Remote Code Execution via Arbitrary File Write
48RISCO
abrir
GitHub PoC
CVE-2026-55040
CVE-2026-55040CRITICALsob ataque27 ago 2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISCO
abrir
GitHub PoC
CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, CVE-2026-20313
CVE-2026-20303CRITICAL27 ago 2026
Cisco Catalyst SD-WAN Security Hardening Release - Input Validation Vulnerabilities
48RISCO
abrir
GitHub PoC3
GitLab Code injection
CVE-2026-19478CRITICAL27 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir
GitHub PoC
sahmsec/CVE-2026-32475
CVE-2026-32475CRITICAL27 ago 2026
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RISCO
abrir
GitHub PoC
SneakyNachos/CVE-2026-74936-gc-potato
CVE-2026-74936CRITICAL27 ago 2026
Use-after-free in the JavaScript: WebAssembly component
48RISCO
abrir
GitHub PoC2
CVE-2026-18963 Keycloak Reset-Credentials State Bypass Detector
CVE-2026-18963CRITICAL27 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISCO
abrir
página 1 / 499próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.