Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.184exploits catalogados
37.029CVEs com exploração pública
24.695testados em laboratório
80.184 exploits
VulnCheck XDB
initial-access
CVE-2026-8181CRITICAL22 mai 2026
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-894222 mai 2026
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry ca
60RISCO
abrir
GitHub PoC1
Python exploit toolkit for WordPress Crop Image RCE — CVE-2019-8942 & CVE-2019-8943
CVE-2019-894222 mai 2026
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry ca
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-8181CRITICAL22 mai 2026
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-20182CRITICALsob ataque22 mai 2026
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
100RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2026-5281HIGHsob ataque22 mai 2026
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the render
71RISCO
abrir
GitHub PoC
NullByte8080/CVE-2026-36228
CVE-2026-36228HIGH22 mai 2026
Buffer Overflow vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execu
41RISCO
abrir
GitHub PoC
jaf0rk/CVE-2026-5281
CVE-2026-5281HIGHsob ataque22 mai 2026
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the render
71RISCO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHsob ataque22 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2026-42945CRITICAL22 mai 2026
NGINX ngx_http_rewrite_module vulnerability
60RISCO
abrir
GitHub PoC
Portable Python PoC for CVE-2026-31431 (Copy Fail)
CVE-2026-31431HIGHsob ataque22 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHsob ataque21 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC
CVE-2026-45829
CVE-2026-45829CRITICAL21 mai 2026
A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an un
53RISCO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHsob ataque21 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHsob ataque21 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC2
CVE-2026-9082 | SA-CORE-2026-004
CVE-2026-9082CRITICALsob ataque21 mai 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISCO
abrir
GitHub PoC1
PoC for CVE-2026-9082 (Drupal SA-CORE-2026-004) Drupal Core SQLi
CVE-2026-9082CRITICALsob ataque21 mai 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISCO
abrir
GitHub PoC
Synthetic demo target for EXPOSURE — CVE-2018-21268 (traceroute) + CVE-2018-3757 (pdf-image)
CVE-2018-21268CRITICAL21 mai 2026
The traceroute (aka node-traceroute) package through 1.0.0 for Node.js allows remote command injection via the host para
48RISCO
abrir
GitHub PoC3
0xFuffM3/CVE-2026-31635-DirtyDecrypt
CVE-2026-31635HIGH21 mai 2026
rxrpc: fix oversized RESPONSE authenticator length check
41RISCO
abrir
GitHub PoC2
Langflow Arbitrary Directory Deletion
CVE-2026-42048CRITICAL21 mai 2026
Langflow: Path Traversal in Langflow Knowledge Bases API
48RISCO
abrir
Exploit-DB
FUXA 1.2.9 - RCE
CVE-2026-25895CRITICALwebappsmultiple21 mai 2026
FUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload API
68RISCO
abrir
GitHub PoC
ercihan/CVE-2026-40369
CVE-2026-40369HIGH21 mai 2026
Windows Kernel Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC4
PoC for CVE-2024-6678
CVE-2024-6678CRITICAL21 mai 2026
Authentication Bypass by Spoofing in GitLab
48RISCO
abrir
GitHub PoC
EXPOSURE demo target: Tomcat (CVE-2016-0714) + Apache Rave (CVE-2013-1814) + Java filter-padding deps
CVE-2013-181421 mai 2026
The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain s
60RISCO
abrir
GitHub PoC1
More portable POC of copyfail LPE (CVE-2026-31431) that works on Alpine Linux
CVE-2026-31431HIGHsob ataque21 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
Exploit-DB
Cockpit 359 - RCE
CVE-2026-4631CRITICALwebappsmultiple21 mai 2026
Cockpit: cockpit: unauthenticated remote code execution due to ssh command-line argument injection
68RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHsob ataqueransomware21 mai 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC1
Scanner para identificação de servidores com softwares SSH possivelmente vulnerável às CVEs CVE-2024-6387 e CVE-2023-48795.
CVE-2024-6387HIGH21 mai 2026
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir
GitHub PoC1
CVE-2026-9082
CVE-2026-9082CRITICALsob ataque21 mai 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISCO
abrir
Metasploit300
Concrete CMS Unauthenticated File Usage Disclosure
CVE-2026-6826MEDIUM21 mai 2026
Concrete 9.5.0 and below has file usage disclosure via missing permission check in Usage controller
28RISCO
abrir
anteriorpágina 121 / 2.673próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.