Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
71.886 exploits
VulnCheck XDB
local
CVE-2021-22555HIGHsob ataque25 fev 2026
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISCO
abrir
Metasploit300
Cisco Catalyst SD-WAN Controller Authentication Bypass
CVE-2026-20127CRITICALsob ataque25 fev 2026
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
100RISCO
abrir
GitHub PoC
glutton-su/CVE-2021-22555
CVE-2021-22555HIGHsob ataque25 fev 2026
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISCO
abrir
Metasploit600
Langflow RCE
CVE-2026-27966CRITICAL25 fev 2026
Langflow has Remote Code Execution in CSV Agent
55RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-0770CRITICALsob ataque24 fev 2026
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
local
CVE-2026-21858CRITICAL24 fev 2026
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RISCO
abrir
GitHub PoC2
The official Sentinel Edition v7.11 - Hypervisor Detection & Kernel Memory Audit Suite for Honor Magic V2. Investigating CVE-2025-38352 and EL2 RKP defenses.
CVE-2025-38352HIGHsob ataque24 fev 2026
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
71RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2025-47812CRITICALsob ataque24 fev 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALsob ataqueransomware24 fev 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALsob ataqueransomware24 fev 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2023-27372CRITICAL24 fev 2026
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-32433CRITICALsob ataque24 fev 2026
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
GitHub PoC
carlosalbertotuma/CVE-2025-32433
CVE-2025-32433CRITICALsob ataque24 fev 2026
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
GitHub PoC1
0xjuarez/CVE-2025-47812
CVE-2025-47812CRITICALsob ataque24 fev 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir
GitHub PoC3
A proof-of-concept exploit for CVE-2023-43208, a remote code execution vulnerability in Mirth Connect before version 4.4.1.
CVE-2023-43208CRITICALsob ataqueransomware24 fev 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISCO
abrir
GitHub PoC
Unauthenticated remote code execution vulnerability in SPIP before 4.2.1.
CVE-2023-27372CRITICAL24 fev 2026
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISCO
abrir
GitHub PoC
SonicWall security audit toolkit with vulnerable CTF lab (CVE-2021-20038, CVE-2024-53704)
CVE-2021-20038CRITICALsob ataqueransomware23 fev 2026
A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows
100RISCO
abrir
GitHub PoC
CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware23 fev 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC2
tempiltin/CVE-2025-10353-POC
CVE-2025-10353CRITICAL23 fev 2026
Missing Authorization vulnerability in Melis Platform
63RISCO
abrir
GitHub PoC
SonicWall security audit toolkit with vulnerable CTF lab (CVE-2021-20038, CVE-2024-53704)
CVE-2024-53704HIGHsob ataqueransomware23 fev 2026
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-47539CRITICAL23 fev 2026
WordPress Eventin plugin <= 4.0.26 - Privilege Escalation Vulnerability
75RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-31161CRITICALsob ataqueransomware23 fev 2026
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-53704HIGHsob ataqueransomware23 fev 2026
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe
100RISCO
abrir
GitHub PoC
CVE-2025-14847
CVE-2025-14847HIGHsob ataque23 fev 2026
Zlib compressed protocol header length confusion may allow memory read
100RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2026-2441HIGHsob ataque23 fev 2026
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside
76RISCO
abrir
GitHub PoC
Wrote an exploit in Go for CVE-2025-31161 affecting crushFTP.
CVE-2025-31161CRITICALsob ataqueransomware23 fev 2026
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware23 fev 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
local
CVE-2025-6019HIGH22 fev 2026
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALsob ataqueransomware22 fev 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALsob ataqueransomware22 fev 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISCO
abrir
anteriorpágina 112 / 2.397próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.