Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.836exploits catalogados
32.133CVEs com exploração pública
1.932testados em laboratório
71.836 exploits
GitHub PoC1
First CTF successfully completed! This repo documents my walkthrough of TryHackMe's Simple CTF. It covers network reconnaissance (Nmap), web exploitation (CVE-2019-9053), and credential cracking. As a dev, it was great to pivot from SQLi to a Root shell by leveraging Sudo misconfigurations. Educational purposes only.
CVE-2019-905313 mai 2026
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
GitHub PoC
CVE-2026-0001. Do with your own risk
CVE-2026-23760CRITICALsob ataqueransomware13 mai 2026
SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API
100RISCO
abrir
GitHub PoC
copy-fail-CVE-2026-31431
CVE-2026-31431HIGHsob ataque13 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
Exploit-DB
coreruleset 4.21.0 - Firewall Bypass
CVE-2026-21876CRITICAL13 mai 2026
OWASP CRS has multipart bypass using multiple content-type parts
53RISCO
abrir
GitHub PoC
Controlled reproduction of CVE-2017-0144 (EternalBlue) in an isolated AWS EC2 lab — exploit analysis, Wireshark traffic capture, and MITRE ATT&CK mapping
CVE-2017-0144HIGHsob ataqueransomware13 mai 2026
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
GitHub PoC
vutiendat323/CVE-2021-44228_Log4Shell
CVE-2021-44228CRITICALsob ataqueransomware12 mai 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.
CVE-2025-29927CRITICAL12 mai 2026
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC2
CVE-2026-29000 – pac4j-jwt Authentication Bypass (🔥 CVSS 10.0). One-click admin forge via public key JWE wrapping. Leaks configs, users, secrets. Keep-alive, proxy, custom JWKS.⚙️ Educational PoC Exploit tool.
CVE-2026-29000CRITICAL12 mai 2026
pac4j-jwt JwtAuthenticator Authentication Bypass
48RISCO
abrir
GitHub PoC
y0naldez/CVE-2024-28397-Js2Py-RCE
CVE-2024-28397MEDIUM12 mai 2026
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISCO
abrir
GitHub PoC
lamaper/CVE-2026-52200
CVE-2026-52200CRITICAL12 mai 2026
An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the /ajax
28RISCO
abrir
VulnCheck XDB
info-leak
CVE-2023-27163MEDIUM12 mai 2026
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALsob ataqueransomware12 mai 2026
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
GitHub PoC
cve-2024-21413
CVE-2024-21413CRITICALsob ataque12 mai 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC1
oen liner CVE-2026-31431 test. Created 'sandbox' on sudo user and tests if ir can escape to root
CVE-2026-31431HIGHsob ataque12 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC
CVE-2023-4220 — Unauthenticated file upload RCE in Chamilo LMS ≤ 1.11.24. OSCP-style and auto exploit.
CVE-2023-4220HIGH12 mai 2026
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2026-6664HIGH12 mai 2026
PgBouncer integer overflow in PgBouncer network packet parsing
21RISCO
abrir
GitHub PoC20
azefzafyoussef/CVE-2026-34621
CVE-2026-34621HIGHsob ataque12 mai 2026
Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
71RISCO
abrir
VulnCheck XDB
local
CVE-2024-0582HIGH12 mai 2026
Kernel: io_uring: page use-after-free vulnerability via buffer ring mmap
46RISCO
abrir
VulnCheck XDB
client-side
CVE-2026-34621HIGHsob ataque12 mai 2026
Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
71RISCO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHsob ataque12 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC
SystemVll/CVE-2026-31431-copyfail-aarch64
CVE-2026-31431HIGHsob ataque12 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC
Quick mitigation and patch script for CVE-2026-31431 (Copy Fail) on Ubuntu/Debian VPS
CVE-2026-31431HIGHsob ataque12 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC
sh4den/CVE-2026-31431-copyfail-aarch64
CVE-2026-31431HIGHsob ataque12 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC6
🚀 CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - Best Flow 💥 CRLF injection leads to auth bypass, session hijacking & account leak. ✅ Proxy, custom UA, keep-alive, retries, SSL verify, colored output, file save support. ⚡ Advanced PoC for pentesters.
CVE-2026-41940CRITICALsob ataqueransomware12 mai 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC887
exploit for CVE-2026-42945
CVE-2026-42945CRITICAL12 mai 2026
NGINX ngx_http_rewrite_module vulnerability
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALsob ataqueransomware12 mai 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2026-42945CRITICAL12 mai 2026
NGINX ngx_http_rewrite_module vulnerability
60RISCO
abrir
GitHub PoC1
rootdirective-sec/CVE-2026-5718-Lab
CVE-2026-5718HIGH12 mai 2026
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Unauthenticated Arbitrary File Upload via Non-ASCII Filename Blacklist Bypass
56RISCO
abrir
GitHub PoC
Cybersecurity demo exploiting CVE-2026-35455 with automatic API key generation and exfiltration
CVE-2026-35455HIGH12 mai 2026
immich has Stored XSS via OCR Text in 360° Panorama Viewer
41RISCO
abrir
GitHub PoC1
Claude Code skill to scan machines for Mini Shai-Hulud (CVE-2026-45321) supply chain worm IOCs
CVE-2026-45321CRITICALsob ataqueransomware12 mai 2026
Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
78RISCO
abrir
anteriorpágina 67 / 2.395próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.