Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.864exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
71.852 exploits
GitHub PoC
Log4Shell (CVE-2021-44228)
CVE-2021-44228CRITICALsob ataqueransomware02 mai 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Linux Kernel LPE PoC (CVE-2026-31431)
CVE-2026-31431HIGHsob ataque02 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC
Tracking CVE-2026-31431
CVE-2026-31431HIGHsob ataque02 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC
Hunt-Benito/cve-2026-41200-stig-manager-oidc-reflected-xss
CVE-2026-41200HIGH02 mai 2026
STIG Manager has reflected XSS vulnerability in the Web App
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALsob ataqueransomware02 mai 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALsob ataqueransomware02 mai 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
VulnCheck XDB
local
CVE-2026-33825HIGHsob ataqueransomware02 mai 2026
Microsoft Defender Elevation of Privilege Vulnerability
71RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALsob ataqueransomware02 mai 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALsob ataqueransomware02 mai 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
VulnCheck XDB
info-leak
CVE-2026-42167HIGH02 mai 2026
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where th
36RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-42167HIGH02 mai 2026
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where th
36RISCO
abrir
GitHub PoC1
CVE-2026-41940 Direct Shell Acess
CVE-2026-41940CRITICALsob ataqueransomware02 mai 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHsob ataque02 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHsob ataque02 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHsob ataque02 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHsob ataque02 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHsob ataque02 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC
this is a repo who is facing a escalation issue in their linux system and a news regarding problem of "Dirty pipeline"
CVE-2022-0847HIGHsob ataque02 mai 2026
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC
Proof of concept exploit for CVE-2024-53677 - Apache Struts file upload path traversal vulnerability leading to Remote Code Execution
CVE-2024-53677CRITICAL02 mai 2026
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir
GitHub PoC2
CVE-2016-6210/Openssh 7.2p2 side channel info disclosure POC
CVE-2016-6210MEDIUM02 mai 2026
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RISCO
abrir
GitHub PoC1
CVE-2025-59528 Proof of Concept
CVE-2025-59528CRITICAL01 mai 2026
Flowise has Remote Code Execution vulnerability
85RISCO
abrir
GitHub PoC
simantchaudhari/CVE-2025-24054-PoC
CVE-2025-24054MEDIUMsob ataque01 mai 2026
NTLM Hash Disclosure Spoofing Vulnerability
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware01 mai 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC2
george1-adel/CVE-2026-41940_exploit
CVE-2026-41940CRITICALsob ataqueransomware01 mai 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHsob ataque01 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALsob ataqueransomware01 mai 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHsob ataque01 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALsob ataqueransomware01 mai 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALsob ataqueransomware01 mai 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALsob ataqueransomware01 mai 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
anteriorpágina 78 / 2.396próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.