Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
71.886 exploits
VulnCheck XDB
info-leak
CVE-2023-2812130 abr 2026
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to s
60RISCO
abrir
GitHub PoC10
DaemonSet для митигации уязвимости CVE-2026-31431 (Copy Fail)
CVE-2026-31431HIGHsob ataque30 abr 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC2
Detection rules for CVE-2026-31431 Linux LPE Vulnerability - Credit: (Copy Fail) https://copy.fail
CVE-2026-31431HIGHsob ataque30 abr 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2023-38831HIGHsob ataqueransomware30 abr 2026
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC2
Temporarily removes the root password using CVE-2026-31431
CVE-2026-31431HIGHsob ataque30 abr 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC14
Copy Fail - CVE-2026-31431
CVE-2026-31431HIGHsob ataque30 abr 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC
DaemonSet с реализацией временной меры для митигации уязвимости Copy Fail (CVE-2026-31431)
CVE-2026-31431HIGHsob ataque30 abr 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC3
根据py版本,升级成了c和rust版本,带加密混淆、0依赖(仅技术学习与分享)
CVE-2026-31431HIGHsob ataque30 abr 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC1
CVE-2026-31431 - Copy Fail PoC (Python 3.10+)
CVE-2026-31431HIGHsob ataque30 abr 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC13
Detection, mitigation, and reverse-engineering tooling for CVE-2026-41940 (SessionScribe): the cPanel/WHM unauthenticated session-forgery vulnerability disclosed 2026-04-28. Defense-in-depth active mitigation shim, ModSec rule pack, remote probe, on-host IOC scanner, and per-tier RE snapshot collector. GPL v2.
CVE-2026-41940CRITICALsob ataqueransomware30 abr 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC
ryan2929/CVE-2026-31431
CVE-2026-31431HIGHsob ataque30 abr 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC
Wazuh SCA Linux hardening policy for Copy Fail (CVE-2026-31431)
CVE-2026-31431HIGHsob ataque30 abr 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
Exploit-DB
Js2Py 0.74 - RCE
CVE-2024-28397MEDIUM30 abr 2026
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISCO
abrir
Exploit-DB
Google Chrome 145.0.7632.75 - CSSFontFeatureValuesMap
CVE-2026-2441HIGHsob ataque30 abr 2026
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside
76RISCO
abrir
GitHub PoC
TheMursalin/CVE-2025-32432
CVE-2025-32432CRITICALsob ataque30 abr 2026
Craft CMS Allows Remote Code Execution
100RISCO
abrir
GitHub PoC
My first hands-on Intel 471 threat hunting workshop experience investigating CVE-2023-46604 using Elastic SIEM, vulnerability intelligence, and post-exploitation detection.
CVE-2023-46604CRITICALsob ataqueransomware30 abr 2026
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISCO
abrir
GitHub PoC
This project explores whether modern OpenSSH reveals valid usernames through subtle response or timing differences. CVE-2016-6210 user enumeration investigation ( Welch's t-test, Cohen's d, and detection engineering ) on a controlled lab on Ubuntu 22.04.5 LTS, it also examines the traces such attempts leave behind and how they can be detected..
CVE-2016-6210MEDIUM30 abr 2026
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RISCO
abrir
Exploit-DB
Frigate NVR 0.16.3 - Remote Code Execution
CVE-2026-25643CRITICAL30 abr 2026
Frigate Affected by Authenticated Remote Command Execution (RCE) and Container Escape
48RISCO
abrir
Exploit-DB
Erugo 0.2.14 - Remote Code Execution (RCE)
CVE-2026-24897CRITICAL30 abr 2026
Authenticated Remote Code Execution via Arbitrary File Upload
48RISCO
abrir
Exploit-DB
SUSE Manager 4.3.15 - Code Execution
CVE-2025-46811CRITICAL30 abr 2026
SUSE Multi Linux Manager allows code execution via unprotected websocket endpoint
53RISCO
abrir
Exploit-DB
Repetier-Server 1.4.10 - Path Traversal
CVE-2026-26335CRITICAL30 abr 2026
Calero VeraSMART < 2022 R1 Static IIS Machine Keys Enable ViewState RCE
48RISCO
abrir
GitHub PoC
Black-box penetration test against HackSudo Thor : CVE-2014-6271 Shellshock RCE through Apache mod_cgi, chained with sudo misconfiguration and bash eval injection for full privilege escalation. Includes custom CSRF-aware brute force tooling and Metasploit RPC automation.
CVE-2014-6271CRITICALsob ataque30 abr 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
Exploit-DB
HUSTOJ Zip-Slip v26.01.24 - RCE
CVE-2026-24479CRITICAL30 abr 2026
HUSTOJ has Arbitrary File Write (Zip Slip) in Problem Import Modules that leads to RCE
63RISCO
abrir
GitHub PoC
Remediation report for MegaQuagga Publishing validating the mitigation of CVE-2019-9978 through progressive defensive layering. Documents reverse proxy insertion, ModSecurity WAF deployment, Graylog SIEM integration, and SSL/TLS enforcement using multi-stage Wireshark PCAP analysis across pfSense WAN and LAN interfaces.
CVE-2019-9978MEDIUMsob ataque30 abr 2026
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir
GitHub PoC
Penetration test report for MegaQuagga Publishing documenting a six-phase engagement that chained CVE-2019-9978 and CVE-2023-4842 to achieve unauthenticated Remote Code Execution and a persistent Meterpreter session. Includes full methodology, exploitation evidence, and prioritized remediation recommendations.
CVE-2019-9978MEDIUMsob ataque30 abr 2026
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir
GitHub PoC
vesjolyjd/Kaspersky_CVE-2024-3094
CVE-2024-3094CRITICAL30 abr 2026
Xz: malicious code in distributed source
70RISCO
abrir
Exploit-DB
Craft CMS 5.6.16 - RCE
CVE-2025-32432CRITICALsob ataque29 abr 2026
Craft CMS Allows Remote Code Execution
100RISCO
abrir
Exploit-DB
LangChain Core 1.2.4 - SSTI/RCE
CVE-2025-68664CRITICAL29 abr 2026
LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
53RISCO
abrir
Exploit-DB
GUnet OpenEclass E-learning platform < 4.2 - Remote Code Execution (RCE)
CVE-2026-22241HIGH29 abr 2026
Open eClass has Unrestricted File Upload that Leads to Remote Code Execution (RCE)
41RISCO
abrir
Exploit-DB
phpMyFAQ 4.0.16 - Improper Authorization
CVE-2026-24421MEDIUM29 abr 2026
phpMyFAQ missing authorization exposes /api/setup/backup to any authenticated user
33RISCO
abrir
anteriorpágina 84 / 2.397próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.