Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.279exploits catalogados
36.463CVEs com exploração pública
24.695testados em laboratório
79.279 exploits
GitHub PoC
Writeup + CVE analysis + countermeasures for the Hacktivity 'Vulnerabilities, Exploits, and Remote Access Payloads' lab (netcat shells, Metasploit, CVE-2010-1240, CVE-2004-2687).
CVE-2004-268727 ago 2026
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote at
60RISCO
abrir
GitHub PoC
CVE-2015-3246
CVE-2015-3246MEDIUMsob ataque27 ago 2026
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly mod
78RISCO
abrir
GitHub PoC
CVE-2026-55040
CVE-2026-55040CRITICALsob ataque27 ago 2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-19478CRITICAL27 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir
VulnCheck XDB
local
CVE-2015-5287HIGHsob ataque27 ago 2026
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain perm
86RISCO
abrir
GitHub PoC
CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, CVE-2026-20313
CVE-2026-20303CRITICAL27 ago 2026
Cisco Catalyst SD-WAN Security Hardening Release - Input Validation Vulnerabilities
48RISCO
abrir
VulnCheck XDB
info-leak
CVE-2026-21962CRITICALsob ataque27 ago 2026
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (compo
90RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-27876HIGHsob ataqueransomware27 ago 2026
An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires suc
91RISCO
abrir
GitHub PoC1
A Python-based exploitation framework for CVE-2026-75604 that enables authorized penetration testers to validate Next.js Windows cache traversal vulnerabilities. Deploys reverse shells and webshells via path traversal, with built-in target verification and proxy support for seamless integration into standard pentest workflows.
CVE-2026-75604CRITICAL27 ago 2026
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-18963CRITICAL27 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISCO
abrir
GitHub PoC
Minimal reproduction for Spring AI ParagraphManager sibling self-loop OOM (incomplete fix of CVE-2026-47851)
CVE-2026-47851HIGH27 ago 2026
Unbounded recursion over attacker-controlled PDF outline tree in Spring AI PDF Document Reader
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-14750CRITICALsob ataque27 ago 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
VulnCheck XDB
info-leak
CVE-2026-72898CRITICALsob ataque27 ago 2026
Metabase SQL injection via password reset endpoint
100RISCO
abrir
GitHub PoC
A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.
CVE-2026-55040CRITICALsob ataque27 ago 2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISCO
abrir
GitHub PoC19
Metabase SQLi
CVE-2026-72898CRITICALsob ataque27 ago 2026
Metabase SQL injection via password reset endpoint
100RISCO
abrir
GitHub PoC1
sahmsec/CVE-2026-32475
CVE-2026-32475CRITICAL27 ago 2026
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RISCO
abrir
GitHub PoC
CVE-2026-77542, CVE-2026-77543, CVE-2026-77545, CVE-2026-77550, CVE-2026-77551, CVE-2026-77552, CVE-2026-77553, CVE-2026-77554, CVE-2026-77557 - Draft or TODO
CVE-2026-77542CRITICAL27 ago 2026
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit
48RISCO
abrir
GitHub PoC4
GitLab Code injection
CVE-2026-19478CRITICAL27 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-1676326 ago 2026
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir
GitHub PoC
t3bik/CVE-2026-75898
CVE-2026-75898HIGH26 ago 2026
RAGFlow < 0.26.3 - Server-Side Request Forgery via Agent Invoke Component
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-19632CRITICAL26 ago 2026
TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
48RISCO
abrir
GitHub PoC
Detector + root-cause analysis for CVE-2026-72898 (Metabase unauthenticated SQLi via reset_password)
CVE-2026-72898CRITICALsob ataque26 ago 2026
Metabase SQL injection via password reset endpoint
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-19632CRITICAL26 ago 2026
TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
48RISCO
abrir
GitHub PoC2
CVE-2026-19632 - TranslatePress One-Day PoC
CVE-2026-19632CRITICAL26 ago 2026
TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-63520HIGH26 ago 2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-73570HIGHsob ataque26 ago 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RISCO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHsob ataque26 ago 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC4
Zimbra SNMP Notification OS Command Injection — Unauthenticated RCE via SMTP exploit (Poc)
CVE-2026-73570HIGHsob ataque26 ago 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RISCO
abrir
VulnCheck XDB
info-leak
CVE-2026-72898CRITICALsob ataque26 ago 2026
Metabase SQL injection via password reset endpoint
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-73570HIGHsob ataque26 ago 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RISCO
abrir
anteriorpágina 6 / 2.643próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.