Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
71.886 exploits
GitHub PoC
CVE-2020-1938-Tomcat-AJP(Ghostcat)-Analysis
CVE-2020-1938CRITICALsob ataque08 abr 2026
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
GitHub PoC
Project: vsFTPd 2.3.4 backdoor exploitation (CVE-2011-2523) on Metasploitable 2.
CVE-2011-252307 abr 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
GitHub PoC1
Apache Tomcat(CVE-2020-1938)漏洞验证脚本
CVE-2020-1938CRITICALsob ataque07 abr 2026
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
GitHub PoC
sathish46-lab/CVE-2025-48384-submodule
CVE-2025-48384HIGHsob ataque07 abr 2026
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC5
PoC for CVE-2026-13585
CVE-2026-13585HIGH07 abr 2026
Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in
41RISCO
abrir
GitHub PoC
Python Exploit for CVE: 2018-9276
CVE-2018-9276HIGHsob ataque07 abr 2026
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RISCO
abrir
GitHub PoC
CVE-2025-8088 is a critical path traversal vulnerability in WinRAR 7.12
CVE-2025-8088HIGHsob ataque07 abr 2026
Path traversal vulnerability in WinRAR
93RISCO
abrir
GitHub PoC
CVE-2025-13315
CVE-2025-13315CRITICAL07 abr 2026
Unauthenticated log access in Twonky Server
75RISCO
abrir
GitHub PoC
Este script es para uso educativo y en entornos autorizados como HackTheBox. El uso contra sistemas sin permiso explícito es ilegal.
CVE-2025-9074CRITICAL07 abr 2026
Docker Desktop allows unauthenticated access to Docker Engine API from containers
48RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2018-9276HIGHsob ataque07 abr 2026
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RISCO
abrir
GitHub PoC1
Ninja Forms File Uploads <= 3.3.26 - Unauthenticated Arbitrary File Upload to RCE (CVE-2026-0740)
CVE-2026-0740CRITICAL07 abr 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RISCO
abrir
GitHub PoC
CVE-2026-32662: Active Debug Code in Production — Gardyn Home Kit (ICSA-26-055-03)
CVE-2026-32662MEDIUM07 abr 2026
Gardyn Cloud API Active Debug Code
33RISCO
abrir
GitHub PoC
thorat-shubham/JXL_Infotainment_CVE-2025-69515
CVE-2025-69515CRITICAL07 abr 2026
An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system int
48RISCO
abrir
GitHub PoC
CVE-2025-10681: Hardcoded Azure Blob Storage Account Key — Gardyn Home Kit (ICSA-26-055-03)
CVE-2025-10681HIGH07 abr 2026
Gardyn Mobile Application and Device Firmware Use Hard-coded Credentials
41RISCO
abrir
VulnCheck XDB
info-leak
CVE-2020-1938CRITICALsob ataque07 abr 2026
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
GitHub PoC
CVE-2026-28766: Missing Authentication on User Account Endpoint — Gardyn Home Kit (ICSA-26-055-03)
CVE-2026-28766CRITICAL07 abr 2026
Gardyn Cloud API Missing Authentication for Critical Function
48RISCO
abrir
GitHub PoC
e1st/CVE-2025-56015
CVE-2025-56015HIGH07 abr 2026
In GenieACS 1.2.13, an unauthenticated access vulnerability exists in the NBI API endpoint.
41RISCO
abrir
GitHub PoC
CVE-2026-32646: Missing Authentication on Admin Device Endpoint — Gardyn Home Kit (ICSA-26-055-03)
CVE-2026-32646HIGH07 abr 2026
Gardyn Cloud API Missing Authentication for Critical Function
41RISCO
abrir
GitHub PoC
CVE-2026-28767: Missing Authentication on Admin Notifications Endpoint — Gardyn Home Kit (ICSA-26-055-03)
CVE-2026-28767MEDIUM07 abr 2026
Gardyn Cloud API Missing Authentication for Critical Function
33RISCO
abrir
GitHub PoC
CVE-2026-25197: Authorization Bypass via IDOR — Gardyn Home Kit (ICSA-26-055-03)
CVE-2026-25197CRITICAL07 abr 2026
Gardyn Cloud API Authorization Bypass Through User-Controlled Key
48RISCO
abrir
VulnCheck XDB
info-leak
CVE-2025-13315CRITICAL07 abr 2026
Unauthenticated log access in Twonky Server
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALsob ataque07 abr 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-0740CRITICAL07 abr 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RISCO
abrir
Exploit-DB
Desktop Window Manager Core Library 10.0.10240.0 - Privilege Escalation
CVE-2025-59254HIGH06 abr 2026
Microsoft DWM Core Library Elevation of Privilege Vulnerability
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware06 abr 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC1
Exploit for CVE-2023-32749 affecting Pydio Cells 4.1.2 and earlier
CVE-2023-32749HIGH06 abr 2026
Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying t
46RISCO
abrir
GitHub PoC
avitoriagomes/CVE-2024-29988
CVE-2024-29988HIGHsob ataque06 abr 2026
SmartScreen Prompt Security Feature Bypass Vulnerability
83RISCO
abrir
Exploit-DB
ASP.net 8.0.10 - Bypass
CVE-2025-55315CRITICAL06 abr 2026
ASP.NET Security Feature Bypass Vulnerability
60RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2025-49844CRITICAL06 abr 2026
Redis Lua Use-After-Free may lead to remote code execution
85RISCO
abrir
GitHub PoC
PoC: CVE-2025-30065 incomplete fix bypass in Apache Parquet Java 1.15.1
CVE-2025-30065CRITICAL06 abr 2026
Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
60RISCO
abrir
anteriorpágina 95 / 2.397próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.