Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.032exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
15.260 exploits
GitHub PoC
Demonstration of the Heartbleed CVE (CVE-2014-0160), including lab setup instructions and source code to build your own Heartbleed lab for educational purposes
CVE-2014-0160HIGHsob ataque22 mar 2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC
A detailed penetration testing walkthrough and exploitation report for the 'Portal' machine, focusing on CVE-2011-2523 (vsFTPd 2.3.4 Backdoor) to achieve root access.
CVE-2011-252321 mar 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
GitHub PoC
Resonant RCE for CVE-2026-33017 via CTT Phase-Lock. Exploits Langflow build_public_tmp flow_id endpoint. Bypasses auth using 34th-layer negative refraction to inject Python exec() payloads. Calibrated for 16.6fs jitter resonance and g-coupling g \approx 0.733. O(log N) collapse of AI supply chain security.
CVE-2026-33017CRITICALsob ataque21 mar 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir
GitHub PoC10
CVE-2026-33017 - An unauthenticated remote code execution in Langflow <= 1.8.1 via Public Flow Build Endpoint
CVE-2026-33017CRITICALsob ataque21 mar 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir
GitHub PoC
SALMA-ESSAOUD/CVE-CVSS--CVE-2024-38063-IPv6-TCP-IP-Remote-Code-Execution-Analysis
CVE-2024-38063CRITICAL21 mar 2026
Windows TCP/IP Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC1
The vulnerability in Langflow 1.8.1 and earlier allows a remote, unauthenticated attacker to achieve arbitrary command execution on the host.
CVE-2026-33017CRITICALsob ataque21 mar 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir
GitHub PoC11
MCPJam inspector contains a remote code execution
CVE-2026-23744CRITICAL21 mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
GitHub PoC1
Lab & PoC
CVE-2025-53770CRITICALsob ataqueransomware21 mar 2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
Langflow at pre-CVE-2025-3248 fix commit for variant analysis benchmarking
CVE-2025-3248CRITICALsob ataqueransomware20 mar 2026
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
GitHub PoC
chosenonehacks/CVE-2026-32746
CVE-2026-32746CRITICAL20 mar 2026
telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption
53RISCO
abrir
GitHub PoC
danindiana/cve-2026-32746-mitigation
CVE-2026-32746CRITICAL20 mar 2026
telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption
53RISCO
abrir
GitHub PoC
danilo1992-sys/CVE-2021-29447
CVE-2021-29447HIGH20 mar 2026
WordPress Authenticated XXE attack when installation is running PHP 8
63RISCO
abrir
GitHub PoC
CVE-2025-6934 Exploit Tool Unauthenticated Administrator Account Creation in WordPress Plugin Opal Estate Pro
CVE-2025-6934CRITICAL20 mar 2026
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RISCO
abrir
GitHub PoC1
Classic stack-based buffer overflow in War FTP Daemon 1.65 demonstrating old-school remote code execution through malformed FTP commands.
CVE-2007-156719 mar 2026
Stack-based buffer overflow in War FTP Daemon 1.65, and possibly earlier, allows remote attackers to cause a denial of s
35RISCO
abrir
GitHub PoC
Performing multiple time-based blind injections for the same character and selecting the most frequent result significantly reduces errors and improves reliability, through it is time-consuming.
CVE-2024-51482CRITICAL19 mar 2026
Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64
75RISCO
abrir
GitHub PoC
Exploit based in /jaiguptanick/CVE-2019-0232
CVE-2019-023219 mar 2026
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISCO
abrir
GitHub PoC
tayW84/CVE-2019-10945----Python3
CVE-2019-1094519 mar 2026
An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder param
35RISCO
abrir
GitHub PoC
havertz2110/CVE-2024-48510-PoC
CVE-2024-48510CRITICAL19 mar 2026
Directory Traversal vulnerability in DotNetZip v.1.16.0 and before allows a remote attacker to execute arbitrary code vi
48RISCO
abrir
GitHub PoC1
PoC Magento Session Reaper - CVE-2025-54236
CVE-2025-54236CRITICALsob ataque19 mar 2026
Adobe Commerce | Improper Input Validation (CWE-20)
100RISCO
abrir
GitHub PoC
SEH-based buffer overflow in Easy File Sharing Web Server 7.2, reachable through the password recovery endpoint.
CVE-2025-34096CRITICAL19 mar 2026
Easy File Sharing HTTP Server 7.2 Buffer Overflow via POST to /sendemail.ghp
63RISCO
abrir
GitHub PoC
POC for CVE-2021-3156 - Heap-based buffer overflow in sudo
CVE-2021-3156HIGHsob ataque19 mar 2026
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir
GitHub PoC
duduLiu8787/CVE-2026-32746-Exploit
CVE-2026-32746CRITICAL19 mar 2026
telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption
53RISCO
abrir
GitHub PoC
vsftpd 2.3.4 Backdoor Exploit (CVE-2011-2523)
CVE-2011-252319 mar 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
GitHub PoC1
Classic stack-based buffer overflow in SLMail 5.1 showing how early mail servers could be compromised through oversized SMTP and POP3 commands.
CVE-2003-026419 mar 2026
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO arg
60RISCO
abrir
GitHub PoC1
Classic stack-based buffer overflow in Savant Web Server 3.1 demonstrating early-2000s remote memory corruption through a crafted HTTP request.
CVE-2002-112019 mar 2026
Buffer overflow in Savant Web Server 3.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP G
50RISCO
abrir
GitHub PoC
SSH Exploit Tool (Educational Use Only) 📌 Description This tool demonstrates exploitation of: CVE-2008-0166 CVE-2008-1657 It connects to vulnerable SSH services and provides: Persistent interactive shell Command execution logging Automatic PDF & DOCX report generation
CVE-2008-016618 mar 2026
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that ge
45RISCO
abrir
GitHub PoC
Practical lab focused on vulnerability analysis and exploit development, using FreeFloat FTP Server 1.0 as an educational buffer overflow case study and documenting the setup, analysis and exploitation workflow
CVE-2025-5548MEDIUM18 mar 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISCO
abrir
GitHub PoC
Laboratorio para el análisis y explotación del CVE-2025-5548
CVE-2025-5548MEDIUM18 mar 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISCO
abrir
GitHub PoC
A professional Python tool designed for educational penetration testing, demonstrating SSH vulnerabilities (CVE-2008-0166 / CVE-2008-1657) with interactive shell access, command logging, and automated PDF/DOCX reporting.
CVE-2008-016618 mar 2026
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that ge
45RISCO
abrir
GitHub PoC31
CVE-2026-32746 - GNU InetUtils telnetd LINEMODE SLC Buffer Overflow PoC (pre-auth RCE, CVSS 9.8)
CVE-2026-32746CRITICAL18 mar 2026
telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption
53RISCO
abrir
anteriorpágina 118 / 509próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.