Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
79.305 exploits
GitHub PoC
CVE-2026-32475
CVE-2026-32475CRITICAL22 ago 2026
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RISCO
abrir
GitHub PoC
Metasploit-based penetration test on an isolated Metasploitable2 lab VM — remote exploitation via DistCC (CVE-2004-2687), privilege escalation via udev netlink (CVE-2009-1185), and vsftpd 2.3.4 backdoor analysis (CVE-2011-2523), with firewall mitigation validated end-to-end.
CVE-2009-118522 ago 2026
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to ga
60RISCO
abrir
GitHub PoC
Educational proof-of-concept automation for CVE-2022-22963, demonstrated in an authorized Hack The Box lab environment.
CVE-2022-22963CRITICALsob ataque22 ago 2026
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir
GitHub PoC
Metasploit-based penetration test on an isolated Metasploitable2 lab VM — remote exploitation via DistCC (CVE-2004-2687), privilege escalation via udev netlink (CVE-2009-1185), and vsftpd 2.3.4 backdoor analysis (CVE-2011-2523), with firewall mitigation validated end-to-end.
CVE-2011-252322 ago 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
GitHub PoC1
Exploit Title: Unauthenticated SQL Injection on CMS Made Simple <= 2.2.9
CVE-2019-905322 ago 2026
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
GitHub PoC
Stored XSS in J2Commerce Guest Checkout via Cookie Filter Bypass
CVE-2026-74252HIGH22 ago 2026
Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5
41RISCO
abrir
GitHub PoC
Metasploit-based penetration test on an isolated Metasploitable2 lab VM — remote exploitation via DistCC (CVE-2004-2687), privilege escalation via udev netlink (CVE-2009-1185), and vsftpd 2.3.4 backdoor analysis (CVE-2011-2523), with firewall mitigation validated end-to-end.
CVE-2004-268722 ago 2026
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote at
60RISCO
abrir
GitHub PoC
llaytynher/CVE-2026-0740-upload-template
CVE-2026-0740CRITICAL22 ago 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-65400CRITICALsob ataque22 ago 2026
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS
78RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-19478CRITICAL22 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-13671HIGHsob ataque22 ago 2026
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as
83RISCO
abrir
GitHub PoC3
내 공유기가 Zbtlink ENDLESSDOORS 백도어(CVE-2026-66747) 대상인지 클릭 한 번으로 검사하는 Windows 프로그램
CVE-2026-66747CRITICAL22 ago 2026
ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-34910CRITICALsob ataque22 ago 2026
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-0740CRITICAL22 ago 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-13671HIGHsob ataque22 ago 2026
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as
83RISCO
abrir
GitHub PoC
Investigation and Incident Response report for LetsDefend Alert SOC335 (CVE-2024-49138 Exploitation)
CVE-2024-49138HIGHsob ataque22 ago 2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHsob ataque22 ago 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
VulnCheck XDB
info-leak
CVE-2026-34909CRITICALsob ataque22 ago 2026
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to a
90RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-28000CRITICAL22 ago 2026
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISCO
abrir
GitHub PoC
Hands-on reproduction of CVE-2024-28000 in LiteSpeed Cache using an isolated WordPress lab. Includes reconnaissance, vulnerable hash recovery, Administrator privilege escalation proof, cleanup, and remediation-focused documentation.
CVE-2024-28000CRITICAL22 ago 2026
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISCO
abrir
GitHub PoC4
Apple MacOS Screen Sharing Arbitrary File read/write -> RCE
CVE-2026-65400CRITICALsob ataque22 ago 2026
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS
78RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALsob ataque21 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-32475CRITICAL21 ago 2026
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RISCO
abrir
GitHub PoC1
PoC for CVE-2026-58455: Dockwatch <=0.6.567 unauthenticated RCE. Stdlib-only Python.
CVE-2026-58455CRITICAL21 ago 2026
Dockwatch 0.6.567 Unauthenticated OS Command Injection via ajax/compose.php
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-58455CRITICAL21 ago 2026
Dockwatch 0.6.567 Unauthenticated OS Command Injection via ajax/compose.php
63RISCO
abrir
VulnCheck XDB
info-leak
CVE-2026-65400CRITICALsob ataque21 ago 2026
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS
78RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-60137MEDIUMsob ataque21 ago 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-8181CRITICAL21 ago 2026
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RISCO
abrir
VulnCheck XDB
client-side
CVE-2024-4947CRITICALsob ataque21 ago 2026
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside
83RISCO
abrir
VulnCheck XDB
local
CVE-2022-2586MEDIUMsob ataque21 ago 2026
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-a
68RISCO
abrir
anteriorpágina 11 / 2.644próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.