Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
15.250 exploits
GitHub PoC1
rootdirective-sec/CVE-2026-39987-Lab
CVE-2026-39987CRITICALsob ataque04 mai 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISCO
abrir
GitHub PoC4
Read-only Bash checker for the Copy Fail Linux kernel vulnerability (CVE-2026-31431)
CVE-2026-31431HIGHsob ataque04 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC
Controlled virtual attack & defense lab — CVE-2011-2523 exploitation, Nmap recon, Nikto scanning, UFW hardening on Metasploitable 2
CVE-2011-252304 mai 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
GitHub PoC
LetsDefend SOC336 case study on CVE-2025-21298
CVE-2025-21298CRITICAL04 mai 2026
Windows OLE Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC
kaleth4/CVE-2025-47987
CVE-2025-47987HIGH04 mai 2026
Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC
kaleth4/CVE-2026-42167
CVE-2026-42167HIGH04 mai 2026
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where th
56RISCO
abrir
GitHub PoC
imbas007/POC_CVE-2026-41940
CVE-2026-41940CRITICALsob ataqueransomware03 mai 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC2
Fast, auditable Linux mitigation for CVE-2026-31431 Copy Fail: algif_aead block, verification, and AF_ALG seccomp hardening.
CVE-2026-31431HIGHsob ataque03 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC
CVE-2026-31431 merupakan celah keamanan yang terjadi akibat kegagalan dalam proses penyalinan data (copy operation failure). Kerentanan ini muncul ketika sistem tidak melakukan validasi atau penanganan error dengan benar saat melakukan proses copy data dari satu buffer ke buffer lain
CVE-2026-31431HIGHsob ataque03 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC
tfawnies/CVE-2026-41940-next
CVE-2026-41940CRITICALsob ataqueransomware03 mai 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC
Privilege Escalation Vulnerability in PackageKit (TOCTOU Race Condition)
CVE-2026-41651HIGH03 mai 2026
PackageKit vulnerable to TOCTOU Race on Transaction Flags leads to arbitrary package installation as root
41RISCO
abrir
GitHub PoC
Xmyronn/CVE-2026-10110-SQLi
CVE-2026-10110MEDIUM03 mai 2026
code-projects Student Details Management System index.php sql injection
33RISCO
abrir
GitHub PoC
CVE-2026-36355: Realtek rtl819x Jungle SDK - Unauthenticated Kernel Memory Read/Write via Debug ioctls
CVE-2026-36355HIGH03 mai 2026
The rtl8192cd Wi-Fi kernel driver in the Realtek rtl819x Jungle SDK (all known versions through v3.4.14B) does not perfo
41RISCO
abrir
GitHub PoC1
CVE-2026-36356: MeiG Smart FORGE_SLT711 GoAhead - Unauthenticated OS Command Injection (RCE as root)
CVE-2026-36356CRITICAL03 mai 2026
The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthentica
53RISCO
abrir
GitHub PoC1
CVE-2020-11022
CVE-2020-11022MEDIUM03 mai 2026
jQuery has a potential XSS vulnerability
55RISCO
abrir
GitHub PoC
Audit and incident response tool for CVE-2026-41940 vulnerability
CVE-2026-41940CRITICALsob ataqueransomware03 mai 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC2
CVE-2016-6210/Openssh 7.2p2 side channel info disclosure POC
CVE-2016-6210MEDIUM02 mai 2026
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RISCO
abrir
GitHub PoC
IDS/IPS lab for detecting and preventing Apache ActiveMQ RCE (CVE-2023-46604) using GVM, Nmap, Snort, iptables, and UFW.
CVE-2023-46604CRITICALsob ataqueransomware02 mai 2026
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISCO
abrir
GitHub PoC
CVE-2026-41940
CVE-2026-41940CRITICALsob ataqueransomware02 mai 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC
Python exploit for CVE-2026-42167 (ProFTPD mod_sql). Features automated file scanning and timing-based blind data exfiltration.
CVE-2026-42167HIGH02 mai 2026
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where th
56RISCO
abrir
GitHub PoC
CRAReady SBOM test fixture — Java/Maven app with Log4Shell (CVE-2021-44228), Spring4Shell, Text4Shell, and other critical CVEs
CVE-2021-44228CRITICALsob ataqueransomware02 mai 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
amirhosseinjamshidi64/CVE-2026-7567-POC
CVE-2026-7567CRITICAL02 mai 2026
Temporary Login <= 1.0.0 - Authentication Bypass to Account Takeover
48RISCO
abrir
GitHub PoC1
CVE-2026-41940 Direct Shell Acess
CVE-2026-41940CRITICALsob ataqueransomware02 mai 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC2
CVE-2026-41940 Exploit PoC – cPanel & WHM Authentication Bypass via CRLF Injection
CVE-2026-41940CRITICALsob ataqueransomware02 mai 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC
Log4Shell (CVE-2021-44228)
CVE-2021-44228CRITICALsob ataqueransomware02 mai 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Proof of concept exploit for CVE-2024-53677 - Apache Struts file upload path traversal vulnerability leading to Remote Code Execution
CVE-2024-53677CRITICAL02 mai 2026
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISCO
abrir
GitHub PoC
This is the office check script provided by cPanel for all the users who are using cPanel
CVE-2026-41940CRITICALsob ataqueransomware02 mai 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC
Hunt-Benito/cve-2026-41200-stig-manager-oidc-reflected-xss
CVE-2026-41200HIGH02 mai 2026
STIG Manager has reflected XSS vulnerability in the Web App
41RISCO
abrir
GitHub PoC1
ProFTPD SQL injection PoC
CVE-2026-42167HIGH02 mai 2026
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where th
56RISCO
abrir
GitHub PoC
this is a repo who is facing a escalation issue in their linux system and a news regarding problem of "Dirty pipeline"
CVE-2022-0847HIGHsob ataque02 mai 2026
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
anteriorpágina 102 / 509próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.