Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
71.886 exploits
GitHub PoC1
PoC for Mirth Connect Remote Code Execution (RCE)
CVE-2023-43208CRITICALsob ataqueransomware22 fev 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISCO
abrir
GitHub PoC3
CVE-2023-43208: Mirth Connect Pre-Auth RCE PoC
CVE-2023-43208CRITICALsob ataqueransomware22 fev 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISCO
abrir
VulnCheck XDB
local
CVE-2025-6019HIGH22 fev 2026
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-32463CRITICALsob ataque22 fev 2026
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALsob ataqueransomware22 fev 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALsob ataqueransomware22 fev 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISCO
abrir
GitHub PoC
Stored Cross-Site Scripting in "usememos" via SVG
CVE-2025-50738CRITICAL22 fev 2026
The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a us
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-47812CRITICALsob ataque22 fev 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir
GitHub PoC
danilo1992-sys/CVE-2025-32463
CVE-2025-32463CRITICALsob ataque22 fev 2026
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC
its970/CVE-2025-68645
CVE-2025-68645HIGHsob ataque21 fev 2026
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1
98RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2022-26923HIGHsob ataque21 fev 2026
Active Directory Domain Services Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL21 fev 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISCO
abrir
GitHub PoC
The flaw allows an attacker to execute arbitrary system commands on the server hosting the Pterodactyl Panel without any prior authentication.
CVE-2025-49132CRITICAL21 fev 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISCO
abrir
GitHub PoC1
Exploitation de CVE-2022-26923
CVE-2022-26923HIGHsob ataque21 fev 2026
Active Directory Domain Services Elevation of Privilege Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-68645HIGHsob ataque21 fev 2026
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1
98RISCO
abrir
GitHub PoC
A practical lab demonstrating the exploitation of a critical Remote Code Execution (RCE) vulnerability in Apache Struts2 (CVE-2017-5638) using Vulhub Docker environments. Includes setup instructions and commands to run the vulnerable container.
CVE-2017-5638CRITICALsob ataqueransomware20 fev 2026
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
GitHub PoC
C reimplementation of chwoot PoC
CVE-2025-32463CRITICALsob ataque20 fev 2026
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC
Path traversal vulnerability in Python's tarfile.
CVE-2025-4517CRITICAL20 fev 2026
Arbitrary writes via tarfile realpath overflow
48RISCO
abrir
GitHub PoC
CVE-2022-37969 poc
CVE-2022-37969HIGHsob ataque20 fev 2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALsob ataqueransomware20 fev 2026
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
VulnCheck XDB
local
CVE-2022-37969HIGHsob ataque20 fev 2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-1405CRITICAL20 fev 2026
Slider Future <= 1.0.5 - Unauthenticated Arbitrary File Upload
63RISCO
abrir
GitHub PoC
A proof of concept for CVE-2025-31161, using mangled HTTP header to perform unauthenticated impersonation of any user in Crush FTP server.
CVE-2025-31161CRITICALsob ataqueransomware20 fev 2026
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-1281CRITICALsob ataque19 fev 2026
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALsob ataque19 fev 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
VulnCheck XDB
local
CVE-2022-24521HIGHsob ataqueransomware19 fev 2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
71RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-1340CRITICALsob ataque19 fev 2026
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
100RISCO
abrir
GitHub PoC
CVE-2014-6271 Exploit | by infrar3d
CVE-2014-6271CRITICALsob ataque19 fev 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC1
Unauthenticated remote code execution vulnerability in Wing FTP Server <= 7.4.3.
CVE-2025-47812CRITICALsob ataque19 fev 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-71243CRITICAL19 fev 2026
SPIP Saisies Plugin < 5.11.1 Remote Code Execution
63RISCO
abrir
anteriorpágina 113 / 2.397próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.