Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.095exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
80.095 exploits
GitHub PoC
CVE-2024-38475 exploitation & scanning tool with Mullvad VPN rotation
CVE-2024-38475CRITICALsob ataque31 mai 2026
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
100RISCO
abrir
GitHub PoC
kavin-jindal/CVE-2026-48800-PoC
CVE-2026-48800HIGH31 mai 2026
Notepad++: Arbitrary Code Execution via shortcuts.xml UserCommand Injection
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL31 mai 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
GitHub PoC1
Interactive Ruby shell for authorized CVE-2025-55182 (react2shell) testing
CVE-2025-55182CRITICALsob ataqueransomware31 mai 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
local
CVE-2024-1086HIGHsob ataqueransomware31 mai 2026
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISCO
abrir
GitHub PoC1
An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and compliance reporting for CVE-2021-44228 (Log4Shell).
CVE-2021-44228CRITICALsob ataqueransomware31 mai 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware31 mai 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Remote Code Execution in MCPJam 1.4.2 and older
CVE-2026-23744CRITICAL31 mai 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL31 mai 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
GitHub PoC2
⚡ This tool exploits CVE-2026-3891, a critical unauthenticated arbitrary file upload vulnerability found in the Pix for WooCommerce WordPress plugin (versions ≤ 1.5.0).
CVE-2026-3891CRITICAL31 mai 2026
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL31 mai 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL31 mai 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL31 mai 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
GitHub PoC
This exploit is based on CVE-2023-27350 and was built upon the original exploit by horizon3ai and the Metasploit module.
CVE-2023-27350CRITICALsob ataqueransomware30 mai 2026
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir
VulnCheck XDB
local
CVE-2025-38352HIGHsob ataque30 mai 2026
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
71RISCO
abrir
GitHub PoC
Dhananjayasj/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability
CVE-2024-21413CRITICALsob ataque30 mai 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-5947CRITICAL30 mai 2026
Service Finder Bookings <= 6.0 - Authentication Bypass via User Switch Cookie
63RISCO
abrir
GitHub PoC7
CVE-2025-38352 kernel exploit for LG webOS Smart TVs (ARM64). Achieves persistent root on real consumer hardware with novel exploitation techniques. Responsibly disclosed to LG.
CVE-2025-38352HIGHsob ataque30 mai 2026
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
71RISCO
abrir
GitHub PoC
Testing a List of IP address incase they are vulnerable to CVE-2024-3400
CVE-2024-3400CRITICALsob ataqueransomware30 mai 2026
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-8732CRITICAL30 mai 2026
WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action
68RISCO
abrir
GitHub PoC
Dungsocool/CVE-2018-7600
CVE-2018-7600CRITICALsob ataqueransomware30 mai 2026
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC
Python POC, Exploit for CVE-2026-29000
CVE-2026-29000CRITICAL30 mai 2026
pac4j-jwt JwtAuthenticator Authentication Bypass
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-8732CRITICAL30 mai 2026
WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action
68RISCO
abrir
GitHub PoC
CVE-2025-10162 Exploit
CVE-2025-10162HIGH30 mai 2026
OrderConvo < 14 - Unauthenticated Arbitrary File Read
56RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-8732CRITICAL30 mai 2026
WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action
68RISCO
abrir
GitHub PoC
Delt-A/CVE-2024-36401-poc
CVE-2024-36401CRITICALsob ataque30 mai 2026
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir
GitHub PoC
SourceCodester Pharmacy Sales and Inventory System 1.0 - Vulnerable source code for CVE-2026-7392 SQL Injection
CVE-2026-7392MEDIUM30 mai 2026
SourceCodester Pharmacy Sales and Inventory System ajax.php delete_supplier sql injection
33RISCO
abrir
GitHub PoC1
letsr00t/CVE-2026-43494-PinTheft-PoC
CVE-2026-43494HIGH30 mai 2026
net/rds: reset op_nents when zerocopy page pin fails
41RISCO
abrir
GitHub PoC
CVE-2025-5947 WordPress Service Finder Bookings ≤ 6.0 Exploit
CVE-2025-5947CRITICAL30 mai 2026
Service Finder Bookings <= 6.0 - Authentication Bypass via User Switch Cookie
63RISCO
abrir
Exploit-DB
YAMCS yamcs-core 5.12.7 - User Enumeration
CVE-2026-44595MEDIUMwebappsmultiple30 mai 2026
Yamcs: Unauthorized user enumeration via IAM API endpoints
33RISCO
abrir
anteriorpágina 110 / 2.670próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.