Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
15.250 exploits
GitHub PoC4
CVE-2026-41940 cPanel/WHM auth bypass IOC scanner — fixes false positives in upstream detection script, adds log cross-correlation
CVE-2026-41940CRITICALsob ataqueransomware30 abr 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC13
This repository contains a Proof-of-Concept (PoC) exploit for CVE-2026-41940, a critical authentication bypass vulnerability in cPanel & WHM. The vulnerability allows unauthenticated remote attackers to gain unauthorized access to the control panel by abusing flaws in the login flow.
CVE-2026-41940CRITICALsob ataqueransomware30 abr 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC1
CVE-2026-41940利用工具(go并发检测,python利用)
CVE-2026-41940CRITICALsob ataqueransomware30 abr 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC11
CVE-2026-41940
CVE-2026-41940CRITICALsob ataqueransomware30 abr 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC28
adriyansyah-mf/cve-2026-41940-poc
CVE-2026-41940CRITICALsob ataqueransomware30 abr 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC
My first hands-on Intel 471 threat hunting workshop experience investigating CVE-2023-46604 using Elastic SIEM, vulnerability intelligence, and post-exploitation detection.
CVE-2023-46604CRITICALsob ataqueransomware30 abr 2026
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISCO
abrir
GitHub PoC
HackTheBox — CCTV (Easy/Linux) | CVE-2024-51482 + SqlMap+ SSH Key + Root
CVE-2024-51482CRITICAL30 abr 2026
Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64
75RISCO
abrir
GitHub PoC
Razielx64/CVE-2025-69606-GSVoIP-XSS
CVE-2025-69606MEDIUM30 abr 2026
Cross-Site Scripting (XSS) vulnerability was discovered in the GSVoIP web panel version 2.0.90. The `msg` parameter in t
33RISCO
abrir
GitHub PoC92
High fidelity scanner for CVE-2026-41940 (cPanel & WHM authentication bypass)
CVE-2026-41940CRITICALsob ataqueransomware30 abr 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC
Winrar Exploit CVE-2023-38831
CVE-2023-38831HIGHsob ataqueransomware30 abr 2026
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir
GitHub PoC
vesjolyjd/Kaspersky_CVE-2024-3094
CVE-2024-3094CRITICAL30 abr 2026
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC
TheMursalin/CVE-2025-32432
CVE-2025-32432CRITICALsob ataque30 abr 2026
Craft CMS Allows Remote Code Execution
100RISCO
abrir
GitHub PoC
Gogs CVE-2025-8110 RCE Exploit
CVE-2025-8110HIGHsob ataque30 abr 2026
File overwrite in file update API in Gogs
100RISCO
abrir
GitHub PoC
Remediation report for MegaQuagga Publishing validating the mitigation of CVE-2019-9978 through progressive defensive layering. Documents reverse proxy insertion, ModSecurity WAF deployment, Graylog SIEM integration, and SSL/TLS enforcement using multi-stage Wireshark PCAP analysis across pfSense WAN and LAN interfaces.
CVE-2019-9978MEDIUMsob ataque30 abr 2026
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir
GitHub PoC
MDJM Event Management <= 1.7.8.3 - Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' Parameter
CVE-2026-7537HIGH30 abr 2026
MDJM Event Management <= 1.7.8.3 - Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' Parameter
41RISCO
abrir
GitHub PoC
Escaneo de vulnerabilidades, análisis de tráfico con Wireshark y explotación controlada del CVE-2011-2523 (vsftpd 2.3.4) en entorno de red segura.
CVE-2011-252329 abr 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
GitHub PoC
Wise-Security/CVE-2026-38945
CVE-2026-38945HIGH29 abr 2026
Command injection in Raynet rvia version 12.6 Update 8 and previous versions allows adversaries to execute arbitrary cod
41RISCO
abrir
GitHub PoC26
CVE-2026-41940 latest cPanel & WHM 0day - 70 million websites are possible to expose by Chirag Artani
CVE-2026-41940CRITICALsob ataqueransomware29 abr 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC7
Post-Exploitation Session Validation Tool for CVE-2026-41940
CVE-2026-41940CRITICALsob ataqueransomware29 abr 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC1
Automated detection & exploitation of critical PHP vulnerabilities (CVE-2024-4577 bypass, CVE-2025-14177, CVE-2025-14180, CVE-2025-14178)
CVE-2024-4577CRITICALsob ataqueransomware29 abr 2026
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC434
Cross-platform C port of the Copy Fail Linux LPE (CVE-2026-31431). Disclosed 2026-04-29 by Theori / Xint.
CVE-2026-31431HIGHsob ataque29 abr 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC3
Independent reproduction, code-level root-cause analysis, and realistic-exposure write-up for CVE-2026-42167 (ProFTPD mod_sql is_escaped_text() bypass).
CVE-2026-42167HIGH29 abr 2026
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where th
56RISCO
abrir
GitHub PoC
dinhthihanhle1989-max/CVE-2024-29988
CVE-2024-29988HIGHsob ataque29 abr 2026
SmartScreen Prompt Security Feature Bypass Vulnerability
83RISCO
abrir
GitHub PoC
Unauthenticated time-based blind SQL injection PoC for VICIdial CVE-2024-8503, with metadata extraction, resumable scans, and strict safety limits.
CVE-2024-8503CRITICAL29 abr 2026
VICIdial Unauthenticated SQL Injection
85RISCO
abrir
GitHub PoC
B1gN0Se/PwnKit_CVE-2021-4034
CVE-2021-4034HIGHsob ataqueransomware28 abr 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
Esta falla permite a un atacante remoto y sin ningún tipo de autenticación acceder directamente a los tickets de soporte, casos internos y a todos sus archivos adjuntos confidenciales. Al iterar y descargar de forma automatizada los registros de Aranda, dejando la información sensible expuesta a una exfiltración masiva.
CVE-2025-67223HIGH28 abr 2026
The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs w
41RISCO
abrir
GitHub PoC
MarkArtamonov/OpenNebula-CVE-2025-56536
CVE-2025-56536MEDIUM28 abr 2026
A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scri
33RISCO
abrir
GitHub PoC7
Time-based SQL injection PoC for CVE-2024-51482 in ZoneMinder, with reproducible Docker lab and automated data extraction.
CVE-2024-51482CRITICAL28 abr 2026
Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64
75RISCO
abrir
GitHub PoC24
POCs to demonstrate CVE-2026-42167 in ProFTPD
CVE-2026-42167HIGH28 abr 2026
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where th
56RISCO
abrir
GitHub PoC
MarkArtamonov/OpenNebula-CVE-2025-56534
CVE-2025-56534MEDIUM28 abr 2026
A cross-site scripting (XSS) vulnerability in the custom authenticator driver of opennebula v6.10.0.1 allows attackers t
33RISCO
abrir
anteriorpágina 105 / 509próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.