Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
3.489 exploits
Metasploit600
SPIP X-Spip-Filtre Unauthenticated RCE
CVE-2026-77647CRITICAL20 ago 2026
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August
43RISCO
abrir
Metasploit600
Tenable Security Center SCAP Audit File Command Injection
CVE-2026-19681CRITICAL13 ago 2026
Command Injection
63RISCO
abrir
Metasploit600
Tenable Security Center Report Charting RCE
CVE-2026-19626CRITICAL13 ago 2026
Remote Code Execution
63RISCO
abrir
Metasploit300
Ruby on Rails Active Storage Vips Arbitrary File Read and Remote Code Execution
CVE-2026-66066CRITICAL29 jul 2026
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RISCO
abrir
Metasploit300
Ruby on Rails Active Storage Vips Arbitrary File Read and Remote Code Execution
CVE-2025-24293CRITICAL29 jul 2026
# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of pote
63RISCO
abrir
Metasploit600
JetBrains TeamCity Agent Polling Unauthenticated Remote Code Execution
CVE-2026-63077CRITICALsob ataque27 jul 2026
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
100RISCO
abrir
Metasploit600
Check Point SmartConsole Authentication Bypass Run Script RCE
CVE-2026-16232CRITICALsob ataque22 jul 2026
Authentication Bypass in the SmartConsole Login Process Using an Application Token
100RISCO
abrir
Metasploit300
WordPress Core wp2shell Unauthenticated SQL Injection via REST Batch Route Confusion
CVE-2026-63030CRITICALsob ataque17 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
Metasploit300
WordPress Core wp2shell Unauthenticated SQL Injection via REST Batch Route Confusion
CVE-2026-60137MEDIUMsob ataque17 jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISCO
abrir
Metasploit600
Langflow AI auto_login RCE
CVE-2026-9198CRITICALsob ataque17 jul 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISCO
abrir
Metasploit600
WordPress WP2Shell REST API Batch Route Confusion SQLi to RCE
CVE-2026-60137MEDIUMsob ataque17 jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISCO
abrir
Metasploit600
WordPress WP2Shell REST API Batch Route Confusion SQLi to RCE
CVE-2026-63030CRITICALsob ataque17 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
Metasploit600
SonicWall SMA1000 WorkPlace wsproxy SSRF Remote Command Execution
CVE-2026-15409CRITICALsob ataqueransomware14 jul 2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RISCO
abrir
Metasploit300
Wordpress Planyo Online Reservation System Arbitrary File Read (CVE-2026-3576)
CVE-2026-3576HIGH10 jul 2026
Planyo online reservation system <= 3.0 - Unauthenticated Server-Side Request Forgery via 'ulap_url' Parameter
61RISCO
abrir
Metasploit600
Flowise MCP Server Remote Code Execution
CVE-2026-56274HIGH23 jun 2026
Flowise - Remote Code Execution via MCP Security Bypass in validateCommandFlags and validateArgsForLocalFileAccess
36RISCO
abrir
Metasploit600
Joomla Content Editor Unauthenticated File Upload RCE
CVE-2026-48907CRITICALsob ataque05 jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISCO
abrir
Metasploit500
HP Poly Voice Unauthenticated Remote Code Execution
CVE-2026-0826CRITICAL01 jun 2026
Poly Voice – Possible Remote Control of Certain Poly Devices
55RISCO
abrir
Metasploit300
PAN-OS GlobalProtect CAS CVE-2026-0265 Vulnerability Checker
CVE-2026-0265HIGH21 mai 2026
PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled
56RISCO
abrir
Metasploit300
Concrete CMS Unauthenticated File Usage Disclosure
CVE-2026-6826MEDIUM21 mai 2026
Concrete 9.5.0 and below has file usage disclosure via missing permission check in Usage controller
28RISCO
abrir
Metasploit300
Drupal Core PostgreSQL EntityQuery SQL Injection
CVE-2026-9082CRITICALsob ataque20 mai 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISCO
abrir
Metasploit500
Fragnesia LPE (CVE-2026-46300)
CVE-2026-46300HIGH14 mai 2026
net: skbuff: preserve shared-frag marker during coalescing
56RISCO
abrir
Metasploit300
Linux Kernel __ptrace_may_access() Exit Race chage File Disclosure
CVE-2026-46333HIGH14 mai 2026
ptrace: slightly saner 'get_dumpable()' logic
56RISCO
abrir
Metasploit400
xfrm-ESP Page-Cache Write via CVE-2026-43284
CVE-2026-43284HIGH08 mai 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISCO
abrir
Metasploit400
rxkad Page-Cache Write via CVE-2026-43500
CVE-2026-43500HIGH08 mai 2026
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
78RISCO
abrir
Metasploit300
Cisco Catalyst SD-WAN Controller vHub Authentication Bypass
CVE-2026-20182CRITICALsob ataque07 mai 2026
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
100RISCO
abrir
Metasploit600
Dalfox Found-Action Deserialization RCE
CVE-2026-45087CRITICAL07 mai 2026
Dalfox: Unauthenticated Remote Code Execution via `found-action` in Dalfox Server Mode
48RISCO
abrir
Metasploit600
Apache ActiveMQ RCE via Jolokia addNetworkConnector
CVE-2026-34197HIGHsob ataque29 abr 2026
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
100RISCO
abrir
Metasploit600
Copy Fail AF_ALG + authencesn Page-Cache Write
CVE-2026-31431HIGHsob ataque29 abr 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
Metasploit600
cPanel/WHM CRLF Injection Authentication Bypass RCE
CVE-2026-41940CRITICALsob ataqueransomware28 abr 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
Metasploit600
OpenCATS Installer PHP Code Injection
CVE-2026-27760CRITICAL28 abr 2026
OpenCATS PHP Code Injection via installer AJAX endpoint
75RISCO
abrir
página 1 / 117próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.