Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.886exploits catalogados
32.153CVEs com exploração pública
1.932testados em laboratório
71.886 exploits
GitHub PoC
CVE-2014-6271 Exploit | by infrar3d
CVE-2014-6271CRITICALsob ataque19 fev 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-1281CRITICALsob ataque19 fev 2026
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-47812CRITICALsob ataque19 fev 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-1340CRITICALsob ataque19 fev 2026
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
100RISCO
abrir
GitHub PoC4
CVE-2025-71243 - SPIP Saisies Plugin RCE (Unauthenticated PHP Code Injection)
CVE-2025-71243CRITICAL19 fev 2026
SPIP Saisies Plugin < 5.11.1 Remote Code Execution
63RISCO
abrir
Metasploit600
MajorDoMo Remote Command Injection via cycle_execs Race Condition
CVE-2026-27175CRITICAL18 fev 2026
MajorDoMo Command Injection in rc/index.php via Race Condition
43RISCO
abrir
GitHub PoC
Exploit for CVE-2024-6232 - Python Tarfile Realpath Overflow
CVE-2025-4517CRITICAL18 fev 2026
Arbitrary writes via tarfile realpath overflow
48RISCO
abrir
Metasploit600
MajorDoMo Console Eval Unauthenticated RCE
CVE-2026-27174CRITICAL18 fev 2026
MajorDoMo Unauthenticated Remote Code Execution via Admin Console Eval
63RISCO
abrir
Metasploit600
MajorDoMo Supply Chain RCE via Update Poisoning
CVE-2026-27180CRITICAL18 fev 2026
MajorDoMo Supply Chain Remote Code Execution via Update URL Poisoning
43RISCO
abrir
VulnCheck XDB
info-leak
CVE-2023-31059HIGH18 fev 2026
Repetier Server through 1.4.10 allows ..%5c directory traversal for reading files that contain credentials, as demonstra
56RISCO
abrir
GitHub PoC
Unauthenticated remote code execution vulnerability in WordPress Bricks Builder <= 1.9.6. The template render endpoint accepts PHP code without authentication, allowing arbitrary command execution as the web server user.
CVE-2024-25600CRITICAL18 fev 2026
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir
GitHub PoC1
Command injection vulnerability in elFinder <= 2.1.47 via the PHP connector component. Allows unauthenticated remote code execution as the web server user.
CVE-2019-919418 fev 2026
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RISCO
abrir
GitHub PoC
havbay/CVE-2025-47812-PoC
CVE-2025-47812CRITICALsob ataque18 fev 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir
GitHub PoC
ross-ns/WSUS-CVE-2025-59287
CVE-2025-59287CRITICALsob ataque18 fev 2026
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC1
orgito1015/CVE-2025-55182-Researching-process
CVE-2025-55182CRITICALsob ataqueransomware18 fev 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
A deep-dive security analysis into the 2020 Virgin Mobile KSA data breach. This study dissects the exploitation of CVE-2020-0688, evaluates the impact of delayed patch management, and proposes a robust multi-layered defense architecture to prevent sophisticated exfiltration tactics.
CVE-2020-0688HIGHsob ataqueransomware18 fev 2026
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-59287CRITICALsob ataque18 fev 2026
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-1731CRITICALsob ataqueransomware18 fev 2026
Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
100RISCO
abrir
Metasploit500
GrandStream GXP1600 Unauthenticated Remote Code Execution
CVE-2026-2329CRITICAL18 fev 2026
Grandstream GXP1600 VoIP Phones - Unauthenticated stack buffer overflow
75RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-47812CRITICALsob ataque18 fev 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-919418 fev 2026
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2024-25600CRITICAL18 fev 2026
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir
GitHub PoC
Proof-of-concept exploit for CVE-2023-20198, an authentication bypass vulnerability affecting Cisco IOS XE Web UI
CVE-2023-20198CRITICALsob ataque17 fev 2026
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-55182CRITICALsob ataqueransomware17 fev 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-7609CRITICALsob ataque17 fev 2026
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISCO
abrir
GitHub PoC
andres101c/Shellshock-CVE-2014-6271
CVE-2014-6271CRITICALsob ataque17 fev 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-20198CRITICALsob ataque17 fev 2026
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISCO
abrir
GitHub PoC
Interactive shell client for React Server Components RCE exploitation via __proto__ pollution (CVE-2025-55182)
CVE-2025-55182CRITICALsob ataqueransomware17 fev 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-47812CRITICALsob ataque17 fev 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir
GitHub PoC
PoC and explanation for CVE-2025-4517 used in a CTF I was playing.
CVE-2025-4517CRITICAL17 fev 2026
Arbitrary writes via tarfile realpath overflow
48RISCO
abrir
anteriorpágina 114 / 2.397próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.