Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.279exploits catalogados
36.463CVEs com exploração pública
24.695testados em laboratório
79.279 exploits
VulnCheck XDB
initial-access
CVE-2026-32475CRITICAL28 ago 2026
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RISCO
abrir
GitHub PoC1
poc and yara rules
CVE-2025-59528CRITICAL28 ago 2026
Flowise has Remote Code Execution vulnerability
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALsob ataque28 ago 2026
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC
rmhowe425/POC-CVE-2026-19295
CVE-2026-19295CRITICAL28 ago 2026
Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALsob ataque28 ago 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
Cacti 1.2.22 unauthenticated command injection
CVE-2022-46169CRITICALsob ataque28 ago 2026
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC
CVE-2023-27350, CVE-2023-27351 - PaperCut - Draft or TODO
CVE-2023-27350CRITICALsob ataqueransomware28 ago 2026
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir
GitHub PoC
A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass
CVE-2026-24061CRITICALsob ataque28 ago 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
CVE-2026-65643 - Draft or TODO
CVE-2026-65643HIGH28 ago 2026
Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
41RISCO
abrir
GitHub PoC
fastjson-cve-2026-16723
CVE-2026-16723CRITICAL28 ago 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISCO
abrir
GitHub PoC1
hideki233/CVE-2025-3248-Langflow-RCE
CVE-2025-3248CRITICALsob ataqueransomware28 ago 2026
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
GitHub PoC
A specialized Python framework that executes unauthenticated remote code execution via the 9Router Model Context Protocol (MCP) bridge by deploying a 33-layer temporal phase cascade, Riemann-Hadamard dispersion, and an 11 ns wedge filter to bypass traditional proxy and process-monitoring defenses.
CVE-2026-46339CRITICAL28 ago 2026
9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
63RISCO
abrir
GitHub PoC
CVE-2026-33017 - Langflow Unauthenticated RCE Exploit
CVE-2026-33017CRITICALsob ataque28 ago 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir
GitHub PoC
I know you are probably here from Hack the Box, if so, yes this one actually works.
CVE-2025-55182CRITICALsob ataqueransomware28 ago 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
IKEv1 VPN scanners, attempts a Check Point authentication-bypass exploit, and includes internal network scanning and reverse-shell features.
CVE-2026-50751CRITICALsob ataqueransomware28 ago 2026
User Authentication Bypass in VPN Remote Access and Mobile Access
100RISCO
abrir
GitHub PoC
Hari-v542/CVE-2026-52923
CVE-2026-52923HIGH28 ago 2026
ipc: limit next_id allocation to the valid ID range
41RISCO
abrir
GitHub PoC
CVE-2026-33017 PoC Reverse Shell
CVE-2026-33017CRITICALsob ataque28 ago 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir
GitHub PoC
Hack The Box Nexus machine write-up covering reconnaissance, Gitea credential discovery, Krayin CRM exploitation via CVE-2026-38526, initial access, and privilege escalation through a vulnerable Gitea template synchronization service.
CVE-2026-38526CRITICAL27 ago 2026
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RISCO
abrir
GitHub PoC
Minimal reproduction for Spring AI ParagraphManager sibling self-loop OOM (incomplete fix of CVE-2026-47851)
CVE-2026-47851HIGH27 ago 2026
Unbounded recursion over attacker-controlled PDF outline tree in Spring AI PDF Document Reader
41RISCO
abrir
GitHub PoC
CVE-2015-5287
CVE-2015-5287HIGHsob ataque27 ago 2026
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain perm
86RISCO
abrir
GitHub PoC
A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.
CVE-2026-55040CRITICALsob ataque27 ago 2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISCO
abrir
GitHub PoC1
A Python-based exploitation framework for CVE-2026-75604 that enables authorized penetration testers to validate Next.js Windows cache traversal vulnerabilities. Deploys reverse shells and webshells via path traversal, with built-in target verification and proxy support for seamless integration into standard pentest workflows.
CVE-2026-75604CRITICAL27 ago 2026
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
48RISCO
abrir
GitHub PoC
CVE-2015-3246
CVE-2015-3246MEDIUMsob ataque27 ago 2026
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly mod
78RISCO
abrir
GitHub PoC
CVE-2026-55040
CVE-2026-55040CRITICALsob ataque27 ago 2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISCO
abrir
GitHub PoC
Gvln-S/CVE-2011-2523
CVE-2011-252327 ago 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
GitHub PoC
CVE-2026-77542, CVE-2026-77543, CVE-2026-77545, CVE-2026-77550, CVE-2026-77551, CVE-2026-77552, CVE-2026-77553, CVE-2026-77554, CVE-2026-77557 - Draft or TODO
CVE-2026-77542CRITICAL27 ago 2026
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-14750CRITICALsob ataque27 ago 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
VulnCheck XDB
info-leak
CVE-2026-72898CRITICALsob ataque27 ago 2026
Metabase SQL injection via password reset endpoint
100RISCO
abrir
VulnCheck XDB
local
CVE-2015-5287HIGHsob ataque27 ago 2026
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain perm
86RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-19478CRITICAL27 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir
anteriorpágina 5 / 2.643próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.