Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.760exploits catalogados
32.083CVEs com exploração pública
1.932testados em laboratório
71.760 exploits
GitHub PoC
The code for personally reproducing the corresponding vulnerability
CVE-2026-47102HIGH25 mai 2026
LiteLLM < 1.83.10 Privilege Escalation via User Update
41RISCO
abrir
GitHub PoC
This is POC repo for CVE-2026-48208
CVE-2026-48208MEDIUM25 mai 2026
Denial-of-Service via SVG Rendering in Ticket
33RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-42945CRITICAL25 mai 2026
NGINX ngx_http_rewrite_module vulnerability
60RISCO
abrir
GitHub PoC45
PoC for CVE-2026-28990, an ImageIO bug patched in iOS/macOS 26.5
CVE-2026-28990HIGH25 mai 2026
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15
41RISCO
abrir
GitHub PoC
Critical vulnerability in Siemens RuggedCom ROS devices allowing attackers to derive a hidden factory account password from the device MAC address and gain unauthorized administrative access via TELNET, rsh, or serial interfaces. Affects ROS 3.10.x and earlier.
CVE-2012-180325 mai 2026
RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC Ad
50RISCO
abrir
GitHub PoC
Educational laboratory for studying CVE-2014-0160 (Heartbleed) and framing inconsistencies in TLS heartbeat handling.
CVE-2014-0160HIGHsob ataque25 mai 2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC
Complete CosmicSting (CVE-2024-34102) exploit suite for Magento/Adobe Commerce XXE vulnerability
CVE-2024-34102CRITICALsob ataque25 mai 2026
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir
GitHub PoC
Tomcat AJP文件读取/包含漏洞
CVE-2020-1938CRITICALsob ataque25 mai 2026
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHsob ataque24 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC3
CVE-2026-41096: Heap Overflow in the Windows DNS Client
CVE-2026-41096CRITICAL24 mai 2026
Windows DNS Client Remote Code Execution Vulnerability
48RISCO
abrir
GitHub PoC
mein-0/cve-2026-29923
CVE-2026-29923HIGH24 mai 2026
The pstrip64.sys driver in EnTech Taiwan PowerStrip <=3.90.736 allows local users to escalate privileges to SYSTEM via a
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware24 mai 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-20182CRITICALsob ataque24 mai 2026
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
100RISCO
abrir
GitHub PoC
🎓 PoC Educativo para CVE-2026-23520. Laboratorio de análisis de vulnerabilidades y mitigación controlada. 🧪
CVE-2026-23520CRITICAL24 mai 2026
Arcane has a Command Injection in Arcane Updater Lifecycle Labels Enables RCE
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-54236CRITICALsob ataque24 mai 2026
Adobe Commerce | Improper Input Validation (CWE-20)
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware24 mai 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC1
Local Privilege Escalation in Amazon WorkSpaces via TOCTOU and Arbitrary File Write
CVE-2026-7791HIGH24 mai 2026
Improper privilege management in the log rotation mechanism of the Skylight Workspace Config Service in Amazon WorkSpace
41RISCO
abrir
GitHub PoC39
windows api bug
CVE-2026-41096CRITICAL24 mai 2026
Windows DNS Client Remote Code Execution Vulnerability
48RISCO
abrir
GitHub PoC1
Automated scanner & post-exploitation toolkit for CVE-2026-41940 — cPanel & WHM root authentication bypass via session-file CRLF injection
CVE-2026-41940CRITICALsob ataqueransomware24 mai 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC4
BitLocker TPM+PIN Hardening Against CVE-2026-45585 (YellowKey)
CVE-2026-45585MEDIUM24 mai 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RISCO
abrir
GitHub PoC
Tracking the nginx CVE-2026-9256 rewrite-module heap overflow
CVE-2026-9256CRITICAL24 mai 2026
NGINX ngx_http_rewrite_module vulnerability
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-47812CRITICALsob ataque24 mai 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir
GitHub PoC
Lab detection exercise for DirtyFrag (CVE-2026-43284) - Linux kernel privilege escalation via xfrm-ESP page cache corruption. Full write-up covering exploit execution, detection gaps, and corrected EQL rules using Elastic Stack
CVE-2026-43284HIGH24 mai 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISCO
abrir
GitHub PoC2
copy_fail:CVE-2026-31431
CVE-2026-31431HIGHsob ataque24 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC
CVE-2026-20182
CVE-2026-20182CRITICALsob ataque24 mai 2026
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
100RISCO
abrir
GitHub PoC7
Drupal CVE-2026-9082 Blind SQL Injection Checker
CVE-2026-9082CRITICALsob ataque24 mai 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISCO
abrir
GitHub PoC1
CVE-2026-39987 Exploitation Tool - Marimo < 0.23.0 Pre-Auth RCE (WebSocket)
CVE-2026-39987CRITICALsob ataque24 mai 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALsob ataqueransomware24 mai 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-39987CRITICALsob ataque24 mai 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISCO
abrir
GitHub PoC
Ambiente Docker para demonstração prática da CVE-2025-54236 (SessionReaper): PHP Object Deserialization levando a RCE em Magento Open Source 2.4.7
CVE-2025-54236CRITICALsob ataque24 mai 2026
Adobe Commerce | Improper Input Validation (CWE-20)
100RISCO
abrir
anteriorpágina 52 / 2.392próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.