Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8.829Nuclei 4.350Metasploit 3.489✓ só verificadosrecentespopularesrisco
3.489 exploits
Metasploit600
SPIP X-Spip-Filtre Unauthenticated RCE
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August
43RISCO
abrir ↗Metasploit600
Tenable Security Center SCAP Audit File Command Injection
Command Injection
63RISCO
abrir ↗Metasploit300
Ruby on Rails Active Storage Vips Arbitrary File Read and Remote Code Execution
# Active Storage allowed transformation methods potentially unsafe
Active Storage attempts to prevent the use of pote
63RISCO
abrir ↗Metasploit300
Ruby on Rails Active Storage Vips Arbitrary File Read and Remote Code Execution
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RISCO
abrir ↗Metasploit600
JetBrains TeamCity Agent Polling Unauthenticated Remote Code Execution
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
100RISCO
abrir ↗Metasploit600
Check Point SmartConsole Authentication Bypass Run Script RCE
Authentication Bypass in the SmartConsole Login Process Using an Application Token
100RISCO
abrir ↗Metasploit300
WordPress Core wp2shell Unauthenticated SQL Injection via REST Batch Route Confusion
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISCO
abrir ↗Metasploit600
WordPress WP2Shell REST API Batch Route Confusion SQLi to RCE
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISCO
abrir ↗Metasploit600
WordPress WP2Shell REST API Batch Route Confusion SQLi to RCE
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir ↗Metasploit600
Langflow AI auto_login RCE
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISCO
abrir ↗Metasploit300
WordPress Core wp2shell Unauthenticated SQL Injection via REST Batch Route Confusion
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir ↗Metasploit600
SonicWall SMA1000 WorkPlace wsproxy SSRF Remote Command Execution
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RISCO
abrir ↗Metasploit300
Wordpress Planyo Online Reservation System Arbitrary File Read (CVE-2026-3576)
Planyo online reservation system <= 3.0 - Unauthenticated Server-Side Request Forgery via 'ulap_url' Parameter
61RISCO
abrir ↗Metasploit600
Flowise MCP Server Remote Code Execution
Flowise - Remote Code Execution via MCP Security Bypass in validateCommandFlags and validateArgsForLocalFileAccess
36RISCO
abrir ↗Metasploit600
Joomla Content Editor Unauthenticated File Upload RCE
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISCO
abrir ↗Metasploit500
HP Poly Voice Unauthenticated Remote Code Execution
Poly Voice – Possible Remote Control of Certain Poly Devices
55RISCO
abrir ↗Metasploit300
Concrete CMS Unauthenticated File Usage Disclosure
Concrete 9.5.0 and below has file usage disclosure via missing permission check in Usage controller
28RISCO
abrir ↗Metasploit300
PAN-OS GlobalProtect CAS CVE-2026-0265 Vulnerability Checker
PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled
56RISCO
abrir ↗Metasploit300
Drupal Core PostgreSQL EntityQuery SQL Injection
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISCO
abrir ↗Metasploit300
Linux Kernel __ptrace_may_access() Exit Race chage File Disclosure
ptrace: slightly saner 'get_dumpable()' logic
56RISCO
abrir ↗Metasploit500
Fragnesia LPE (CVE-2026-46300)
net: skbuff: preserve shared-frag marker during coalescing
56RISCO
abrir ↗Metasploit400
xfrm-ESP Page-Cache Write via CVE-2026-43284
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISCO
abrir ↗Metasploit400
rxkad Page-Cache Write via CVE-2026-43500
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
78RISCO
abrir ↗Metasploit600
Dalfox Found-Action Deserialization RCE
Dalfox: Unauthenticated Remote Code Execution via `found-action` in Dalfox Server Mode
48RISCO
abrir ↗Metasploit300
Cisco Catalyst SD-WAN Controller vHub Authentication Bypass
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
100RISCO
abrir ↗Metasploit600
Copy Fail AF_ALG + authencesn Page-Cache Write
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir ↗Metasploit600
Apache ActiveMQ RCE via Jolokia addNetworkConnector
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
100RISCO
abrir ↗Metasploit600
cPanel/WHM CRLF Injection Authentication Bypass RCE
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir ↗Metasploit600
OpenCATS Installer PHP Code Injection
OpenCATS PHP Code Injection via installer AJAX endpoint
75RISCO
abrir ↗página 1 / 117próximo →
Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.