Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
71.957 exploits
Exploit-DB
WordPress Backup Migration 1.3.7 - Remote Command Execution
CVE-2023-6553CRITICAL03 mar 2026
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RISCO
abrir
Exploit-DB
Boss Mini v1.4.0 - Local File Inclusion (LFI)
CVE-2023-3643HIGH03 mar 2026
Boss Mini document file inclusion
78RISCO
abrir
GitHub PoC
CVE-2025-68613 — n8n RCE via Expression Injection
CVE-2025-68613CRITICALsob ataque03 mar 2026
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISCO
abrir
GitHub PoC
CVE-2025-32463
CVE-2025-32463CRITICALsob ataque03 mar 2026
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC19
Dahua IP camera CVE research toolkit (CVE-2021-33044/33045, CVE-2025-31700/31701)
CVE-2021-33044CRITICALsob ataque03 mar 2026
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISCO
abrir
GitHub PoC
CVE-2023-3452 exploit for WordPress Canto plugin RCE, HTTPS support included
CVE-2023-3452CRITICAL03 mar 2026
Canto <= 3.0.4 - Unauthenticated Remote File Inclusion
63RISCO
abrir
Exploit-DB
mailcow 2025-01a - Host Header Password Reset Poisoning
CVE-2025-25198HIGH03 mar 2026
mailcow: dockerized vulnerable to password reset poisoning
41RISCO
abrir
GitHub PoC1
Demonstrate a proof-of-concept exploit for CVE-2026-2441, a high-risk Chrome use-after-free vulnerability in the Blink CSS engine.
CVE-2026-2441HIGHsob ataque03 mar 2026
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside
76RISCO
abrir
GitHub PoC
CVE-2024-23897: Jenkins Arbitrary File Read Lead to RCE
CVE-2024-23897CRITICALsob ataqueransomware03 mar 2026
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
GitHub PoC9
gowonisgood/CVE-2025-62215-POC
CVE-2025-62215HIGHsob ataque02 mar 2026
Windows Kernel Elevation of Privilege Vulnerability
71RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-3395MEDIUM02 mar 2026
MaxSite CMS MarkItUp Preview AJAX Endpoint preview-ajax.php eval code injection
33RISCO
abrir
GitHub PoC1
CVE-2025-43529 Test
CVE-2025-43529HIGHsob ataque02 mar 2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
71RISCO
abrir
GitHub PoC
CVE-2025-5777
CVE-2025-5777CRITICALsob ataqueransomware02 mar 2026
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataque02 mar 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2025-62215HIGHsob ataque02 mar 2026
Windows Kernel Elevation of Privilege Vulnerability
71RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-58034MEDIUMsob ataque02 mar 2026
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vul
90RISCO
abrir
VulnCheck XDB
local
CVE-2023-4911HIGHsob ataque02 mar 2026
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISCO
abrir
GitHub PoC
PoC of CVE-2021-4034 (PwnKit) for personal training purposes.
CVE-2021-4034HIGHsob ataque02 mar 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
Aryan20057/CVE-2023-4911
CVE-2023-4911HIGHsob ataque02 mar 2026
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-43529HIGHsob ataque02 mar 2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
71RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-1357CRITICAL02 mar 2026
Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload
75RISCO
abrir
GitHub PoC
Metasploit module to exploit CVE-2024-46987 - an authenticated path traversal vulnerability in Camaleon CMS versions 2.8.0 through 2.8.2 and 2.9.0
CVE-2024-46987HIGH02 mar 2026
Arbitrary path traversal in Camaleon CMS
61RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-3395MEDIUM01 mar 2026
MaxSite CMS MarkItUp Preview AJAX Endpoint preview-ajax.php eval code injection
33RISCO
abrir
GitHub PoC
CVE-2014-0160
CVE-2014-0160HIGHsob ataque01 mar 2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC
Laravel-RCE: CVE-2017-9841
CVE-2017-9841CRITICALsob ataque01 mar 2026
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISCO
abrir
GitHub PoC
7rootsec/CVE-2022-21661-Technical-Analysis
CVE-2022-21661HIGH01 mar 2026
SQL injection in WordPress
78RISCO
abrir
GitHub PoC
This repository provides production-ready detection engineering content for **CVE-2025-25257**, a pre-authentication SQL Injection vulnerability in Fortinet FortiWeb Fabric Connector versions 7.0 through 7.6.x. Successful exploitation can lead to Remote Code Execution without any prior authentication.
CVE-2025-25257CRITICALsob ataque01 mar 2026
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISCO
abrir
GitHub PoC
Black box penetration test — WordPress exploitation, privilege escalation via CVE-2022-0847
CVE-2022-0847HIGHsob ataque01 mar 2026
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
Metasploit600
FreeScout Unauthenticated RCE via ZWSP .htaccess Bypass
CVE-2026-27636HIGH01 mar 2026
FreeScout: Missing .htaccess in Restricted File Extensions Allows Remote Code Execution on Apache
36RISCO
abrir
Metasploit600
FreeScout Unauthenticated RCE via ZWSP .htaccess Bypass
CVE-2026-28289CRITICAL01 mar 2026
FreeScout 1.8.206 Patch Bypass for CVE-2026-27636 via Zero-Width Space Character Leads to Remote Code Execution
55RISCO
abrir
anteriorpágina 110 / 2.399próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.