Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

72.018exploits catalogados
32.219CVEs com exploração pública
1.932testados em laboratório
71.958 exploits
Metasploit500
HUSTOJ Admin users can zip-slip problem_import_qduoj.php, planting PHP files in webroot for RCE
CVE-2026-24479CRITICAL26 jan 2026
HUSTOJ has Arbitrary File Write (Zip Slip) in Problem Import Modules that leads to RCE
63RISCO
abrir
GitHub PoC2
CVE-2015-2291 Local Privilege Escalation PoC
CVE-2015-2291HIGHsob ataqueransomware25 jan 2026
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows all
71RISCO
abrir
GitHub PoC
CVE-2025-60021
CVE-2025-60021CRITICAL25 jan 2026
Apache bRPC: Remote command injection vulnerability in heap builtin service
53RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-0920CRITICAL25 jan 2026
LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter
48RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-24061CRITICALsob ataque25 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-24061CRITICALsob ataque25 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
CVE-2025-64155
CVE-2025-64155CRITICAL25 jan 2026
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-20045HIGHsob ataque25 jan 2026
Cisco Unified Communications Products Remote Code Execution Vulnerability
71RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-60021CRITICAL25 jan 2026
Apache bRPC: Remote command injection vulnerability in heap builtin service
53RISCO
abrir
GitHub PoC
jagg3rsec/CVE-2014-6287
CVE-2014-6287CRITICALsob ataque25 jan 2026
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2014-6287CRITICALsob ataque25 jan 2026
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALsob ataque25 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC4
POC (RCE) -> CVE-2019-9978
CVE-2019-9978MEDIUMsob ataque25 jan 2026
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir
GitHub PoC
Python demo simulating CVE-2024-3094: a supply chain backdoor in XZ Utils with a trigger-based stealth activation.
CVE-2024-3094CRITICAL25 jan 2026
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC
Baza-NATO/CVE-2021-33044
CVE-2021-33044CRITICALsob ataque25 jan 2026
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISCO
abrir
GitHub PoC
dionissh/CVE-2024-21413
CVE-2024-21413CRITICALsob ataque25 jan 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2024-21413CRITICALsob ataque25 jan 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-9978MEDIUMsob ataque25 jan 2026
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-33044CRITICALsob ataque25 jan 2026
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISCO
abrir
VulnCheck XDB
local
CVE-2015-2291HIGHsob ataqueransomware25 jan 2026
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows all
71RISCO
abrir
GitHub PoC
ranasen-rat/cve-2021-42013
CVE-2021-42013CRITICALsob ataqueransomware24 jan 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC1
A secure, zero-trust database management tool for WordPress. Fixes critical SSRF vulnerabilities (CVE-2021-21311) by enforcing local connections only.
CVE-2021-21311HIGHsob ataque24 jan 2026
SSRF in adminer
100RISCO
abrir
GitHub PoC
For HTB practice
CVE-2022-44268MEDIUM24 jan 2026
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISCO
abrir
GitHub PoC
xitexploiter96-dot/CVE-2023-38408
CVE-2023-38408CRITICAL24 jan 2026
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISCO
abrir
VulnCheck XDB
info-leak
CVE-2026-24061CRITICALsob ataque24 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-24061CRITICALsob ataque24 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALsob ataque24 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-24061CRITICALsob ataque24 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2023-38408CRITICAL24 jan 2026
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISCO
abrir
VulnCheck XDB
client-side
CVE-2021-42013CRITICALsob ataqueransomware24 jan 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
anteriorpágina 125 / 2.399próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.