Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
71.957 exploits
VulnCheck XDB
remote-with-credentials
CVE-2025-47812CRITICALsob ataque19 fev 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-1281CRITICALsob ataque19 fev 2026
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-71243CRITICAL19 fev 2026
SPIP Saisies Plugin < 5.11.1 Remote Code Execution
63RISCO
abrir
GitHub PoC4
CVE-2025-71243 - SPIP Saisies Plugin RCE (Unauthenticated PHP Code Injection)
CVE-2025-71243CRITICAL19 fev 2026
SPIP Saisies Plugin < 5.11.1 Remote Code Execution
63RISCO
abrir
GitHub PoC1
Unauthenticated remote code execution vulnerability in Wing FTP Server <= 7.4.3.
CVE-2025-47812CRITICALsob ataque19 fev 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir
GitHub PoC1
这是基于cve-2016-4437简单的漏洞复现代码
CVE-2016-4437CRITICALsob ataque19 fev 2026
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RISCO
abrir
GitHub PoC
Unauthenticated remote code execution vulnerability in WordPress Bricks Builder <= 1.9.6. The template render endpoint accepts PHP code without authentication, allowing arbitrary command execution as the web server user.
CVE-2024-25600CRITICAL18 fev 2026
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir
GitHub PoC1
Command injection vulnerability in elFinder <= 2.1.47 via the PHP connector component. Allows unauthenticated remote code execution as the web server user.
CVE-2019-919418 fev 2026
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RISCO
abrir
GitHub PoC
A deep-dive security analysis into the 2020 Virgin Mobile KSA data breach. This study dissects the exploitation of CVE-2020-0688, evaluates the impact of delayed patch management, and proposes a robust multi-layered defense architecture to prevent sophisticated exfiltration tactics.
CVE-2020-0688HIGHsob ataqueransomware18 fev 2026
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
GitHub PoC
ross-ns/WSUS-CVE-2025-59287
CVE-2025-59287CRITICALsob ataque18 fev 2026
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
havbay/CVE-2025-47812-PoC
CVE-2025-47812CRITICALsob ataque18 fev 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-59287CRITICALsob ataque18 fev 2026
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-47812CRITICALsob ataque18 fev 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-1731CRITICALsob ataqueransomware18 fev 2026
Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-919418 fev 2026
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RISCO
abrir
GitHub PoC
Exploit for CVE-2024-6232 - Python Tarfile Realpath Overflow
CVE-2025-4517CRITICAL18 fev 2026
Arbitrary writes via tarfile realpath overflow
48RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2024-25600CRITICAL18 fev 2026
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir
VulnCheck XDB
info-leak
CVE-2023-31059HIGH18 fev 2026
Repetier Server through 1.4.10 allows ..%5c directory traversal for reading files that contain credentials, as demonstra
56RISCO
abrir
GitHub PoC1
orgito1015/CVE-2025-55182-Researching-process
CVE-2025-55182CRITICALsob ataqueransomware18 fev 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
Metasploit600
MajorDoMo Console Eval Unauthenticated RCE
CVE-2026-27174CRITICAL18 fev 2026
MajorDoMo Unauthenticated Remote Code Execution via Admin Console Eval
63RISCO
abrir
Metasploit600
MajorDoMo Supply Chain RCE via Update Poisoning
CVE-2026-27180CRITICAL18 fev 2026
MajorDoMo Supply Chain Remote Code Execution via Update URL Poisoning
43RISCO
abrir
Metasploit500
GrandStream GXP1600 Unauthenticated Remote Code Execution
CVE-2026-2329CRITICAL18 fev 2026
Grandstream GXP1600 VoIP Phones - Unauthenticated stack buffer overflow
75RISCO
abrir
Metasploit600
MajorDoMo Remote Command Injection via cycle_execs Race Condition
CVE-2026-27175CRITICAL18 fev 2026
MajorDoMo Command Injection in rc/index.php via Race Condition
43RISCO
abrir
GitHub PoC
Interactive shell client for React Server Components RCE exploitation via __proto__ pollution (CVE-2025-55182)
CVE-2025-55182CRITICALsob ataqueransomware17 fev 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Proof-of-concept exploit for CVE-2023-20198, an authentication bypass vulnerability affecting Cisco IOS XE Web UI
CVE-2023-20198CRITICALsob ataque17 fev 2026
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISCO
abrir
GitHub PoC
andres101c/Shellshock-CVE-2014-6271
CVE-2014-6271CRITICALsob ataque17 fev 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-7609CRITICALsob ataque17 fev 2026
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-55182CRITICALsob ataqueransomware17 fev 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
PoC and explanation for CVE-2025-4517 used in a CTF I was playing.
CVE-2025-4517CRITICAL17 fev 2026
Arbitrary writes via tarfile realpath overflow
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-20198CRITICALsob ataque17 fev 2026
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISCO
abrir
anteriorpágina 115 / 2.399próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.