Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
15.250 exploits
GitHub PoC
Majdae/CVE-2025-47812-Research
CVE-2025-47812CRITICALsob ataque09 abr 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir
GitHub PoC
kaleth4/-CVE-2014-6271
CVE-2014-6271CRITICALsob ataque09 abr 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC
doaso/CVE-2023-42115
CVE-2023-42115CRITICAL08 abr 2026
Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability
48RISCO
abrir
GitHub PoC
CVE-2020-1938-Tomcat-AJP(Ghostcat)-Analysis
CVE-2020-1938CRITICALsob ataque08 abr 2026
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
GitHub PoC
Security review уязвимости CVE-2024-3094 с открытым исходным кодом
CVE-2024-3094CRITICAL08 abr 2026
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC
HackTheBox — Pterodactyl (Medium/Linux) walkthrough. CVE-2025-49132 LFI → pearcmd RCE → bcrypt crack → SSH. Privesc via CVE-2025-6018 (PAM pam_environment bypass) + CVE-2025-6019 (udisks2 XFS resize race condition, nosuid bypass) → root. Full notes and steps included.
CVE-2025-49132CRITICAL08 abr 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISCO
abrir
GitHub PoC3
POC
CVE-2026-0740CRITICAL08 abr 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RISCO
abrir
GitHub PoC
cyb3rk0ala/THM-MagnusBilling-CVE-2023-30258-Exploit
CVE-2023-30258CRITICAL08 abr 2026
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISCO
abrir
GitHub PoC
CVE-2026-32662: Active Debug Code in Production — Gardyn Home Kit (ICSA-26-055-03)
CVE-2026-32662MEDIUM07 abr 2026
Gardyn Cloud API Active Debug Code
33RISCO
abrir
GitHub PoC
Project: vsFTPd 2.3.4 backdoor exploitation (CVE-2011-2523) on Metasploitable 2.
CVE-2011-252307 abr 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
GitHub PoC
CVE-2025-8088 is a critical path traversal vulnerability in WinRAR 7.12
CVE-2025-8088HIGHsob ataqueransomware07 abr 2026
Path traversal vulnerability in WinRAR
93RISCO
abrir
GitHub PoC
CVE-2026-28766: Missing Authentication on User Account Endpoint — Gardyn Home Kit (ICSA-26-055-03)
CVE-2026-28766CRITICAL07 abr 2026
Gardyn Cloud API Missing Authentication for Critical Function
48RISCO
abrir
GitHub PoC2
PJSIP cve-2026-25994 BUFFER OVERFLOW POC
CVE-2026-25994HIGH07 abr 2026
PJSIP has a heap buffer overflow in ICE with long username
41RISCO
abrir
GitHub PoC
CVE-2026-28767: Missing Authentication on Admin Notifications Endpoint — Gardyn Home Kit (ICSA-26-055-03)
CVE-2026-28767MEDIUM07 abr 2026
Gardyn Cloud API Missing Authentication for Critical Function
33RISCO
abrir
GitHub PoC
CVE-2026-32646: Missing Authentication on Admin Device Endpoint — Gardyn Home Kit (ICSA-26-055-03)
CVE-2026-32646HIGH07 abr 2026
Gardyn Cloud API Missing Authentication for Critical Function
41RISCO
abrir
GitHub PoC1
Ninja Forms File Uploads <= 3.3.26 - Unauthenticated Arbitrary File Upload to RCE (CVE-2026-0740)
CVE-2026-0740CRITICAL07 abr 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RISCO
abrir
GitHub PoC
CVE-2026-25197: Authorization Bypass via IDOR — Gardyn Home Kit (ICSA-26-055-03)
CVE-2026-25197CRITICAL07 abr 2026
Gardyn Cloud API Authorization Bypass Through User-Controlled Key
48RISCO
abrir
GitHub PoC6
PoC for CVE-2026-13585
CVE-2026-13585HIGH07 abr 2026
Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in
41RISCO
abrir
GitHub PoC
Este script es para uso educativo y en entornos autorizados como HackTheBox. El uso contra sistemas sin permiso explícito es ilegal.
CVE-2025-9074CRITICAL07 abr 2026
Docker Desktop allows unauthenticated access to Docker Engine API from containers
48RISCO
abrir
GitHub PoC
CVE-2025-10681: Hardcoded Azure Blob Storage Account Key — Gardyn Home Kit (ICSA-26-055-03)
CVE-2025-10681HIGH07 abr 2026
Gardyn Mobile Application and Device Firmware Use Hard-coded Credentials
41RISCO
abrir
GitHub PoC
sathish46-lab/CVE-2025-48384-submodule
CVE-2025-48384HIGHsob ataque07 abr 2026
Git allows arbitrary code execution through broken config quoting
71RISCO
abrir
GitHub PoC
Proof-of-concept exploit for CVE-2026-33017 (Langflow <= 1.8.1).
CVE-2026-33017CRITICALsob ataque07 abr 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir
GitHub PoC
Python Exploit for CVE: 2018-9276
CVE-2018-9276HIGHsob ataque07 abr 2026
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RISCO
abrir
GitHub PoC
CVE-2025-13315
CVE-2025-13315CRITICAL07 abr 2026
Unauthenticated log access in Twonky Server
75RISCO
abrir
GitHub PoC
thorat-shubham/JXL_Infotainment_CVE-2025-69515
CVE-2025-69515CRITICAL07 abr 2026
An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system int
48RISCO
abrir
GitHub PoC1
Apache Tomcat(CVE-2020-1938)漏洞验证脚本
CVE-2020-1938CRITICALsob ataque07 abr 2026
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
GitHub PoC
e1st/CVE-2025-56015
CVE-2025-56015HIGH07 abr 2026
In GenieACS 1.2.13, an unauthenticated access vulnerability exists in the NBI API endpoint.
41RISCO
abrir
GitHub PoC
zsxen/cve-2025-1974-lab
CVE-2025-1974CRITICAL06 abr 2026
ingress-nginx admission controller RCE escalation
85RISCO
abrir
GitHub PoC
zsxen/CVE-2025-1974
CVE-2025-1974CRITICAL06 abr 2026
ingress-nginx admission controller RCE escalation
85RISCO
abrir
GitHub PoC1
Exploit for CVE-2023-32749 affecting Pydio Cells 4.1.2 and earlier
CVE-2023-32749HIGH06 abr 2026
Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying t
46RISCO
abrir
anteriorpágina 112 / 509próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.