Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.184exploits catalogados
37.029CVEs com exploração pública
24.695testados em laboratório
80.184 exploits
GitHub PoC
yangh-beep/CVE-2026-31431-C
CVE-2026-31431HIGHsob ataque21 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC1
More portable POC of copyfail LPE (CVE-2026-31431) that works on Alpine Linux
CVE-2026-31431HIGHsob ataque21 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC
Vulnerability Case Study: CVE-2026-33829 (Windows Snipping Tool NTLM Coercion)
CVE-2026-33829MEDIUM21 mai 2026
Windows Snipping Tool Spoofing Vulnerability
33RISCO
abrir
GitHub PoC2
CVE-2026-9082 | SA-CORE-2026-004
CVE-2026-9082CRITICALsob ataque21 mai 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISCO
abrir
GitHub PoC1
CVE-2026-5118-exp_wordpress_Divi Form Builder
CVE-2026-5118CRITICAL21 mai 2026
Divi Form Builder <= 5.1.2 - Unauthenticated Privilege Escalation via 'role'
48RISCO
abrir
GitHub PoC
CVE-2026-45829
CVE-2026-45829CRITICAL21 mai 2026
A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an un
53RISCO
abrir
GitHub PoC
A Go implementation of dirtydecrypt (CVE-2026-31635)
CVE-2026-31635HIGH21 mai 2026
rxrpc: fix oversized RESPONSE authenticator length check
41RISCO
abrir
GitHub PoC24
Drupal Core PostgreSQL SQL Injection PoC - CVE-2026-9082. Ethical PoC for the Drupal vulnerability allowing anonymous SQL injection through the JSON:API module on PostgreSQL-backed sites.
CVE-2026-9082CRITICALsob ataque21 mai 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISCO
abrir
GitHub PoC1
Scanner para identificação de servidores com softwares SSH possivelmente vulnerável às CVEs CVE-2024-6387 e CVE-2023-48795.
CVE-2024-6387HIGH21 mai 2026
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir
GitHub PoC1
An issue in Unistal Systems Pvt. Ltd. Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service in the kernel.
CVE-2026-38763MEDIUM21 mai 2026
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the
33RISCO
abrir
GitHub PoC1
An issue in Unistal Systems Pvt. Ltd. Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys
CVE-2026-38764HIGH21 mai 2026
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kerne
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHsob ataqueransomware21 mai 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC1
Intune Remediation package for the CVE-2026-45585 YellowKey BitLocker/WinRE bypass mitigation described in the provided procedure. This package removes `autofstx.exe` from the offline WinRE image's `BootExecute` value and refreshes WinRE registration so BitLocker trust is reestablished.
CVE-2026-45585MEDIUM21 mai 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RISCO
abrir
GitHub PoC2
Piotnet Addons for Elementor Pro <= 7.1.70 - Unauthenticated Arbitrary File Upload → RCE
CVE-2026-4885CRITICAL21 mai 2026
Piotnet Addons for Elementor Pro <= 7.1.70 - Unauthenticated Arbitrary File Upload via Form File Upload
48RISCO
abrir
VulnCheck XDB
local
CVE-2026-31635HIGH21 mai 2026
rxrpc: fix oversized RESPONSE authenticator length check
41RISCO
abrir
GitHub PoC
「🪶」PoC (Proof of concept) of Path traversal + RCE in Apache HTTP Server 2.4.49
CVE-2021-41773HIGHsob ataqueransomware21 mai 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC2
An issue in Unistal Systems Pvt. Ltd. Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via a kernel mode driver.
CVE-2026-38766HIGH21 mai 2026
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_1
41RISCO
abrir
GitHub PoC
CVE-2026-46680 exploit
CVE-2026-46680HIGH21 mai 2026
containerd user ID handling bypass allows runAsNonRoot evasion
41RISCO
abrir
GitHub PoC2
An issue in Unistal Systems Pvt. Ltd. Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys
CVE-2026-38765HIGH21 mai 2026
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kerne
41RISCO
abrir
Metasploit300
PAN-OS GlobalProtect CAS CVE-2026-0265 Vulnerability Checker
CVE-2026-0265HIGH21 mai 2026
PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled
56RISCO
abrir
GitHub PoC22
CVE-2026-45250: FreeBSD 14.4 setcred kernel buffer overflow (LPE)
CVE-2026-45250HIGH21 mai 2026
Stack buffer overflow via setcred(2)
41RISCO
abrir
Metasploit300
Concrete CMS Unauthenticated File Usage Disclosure
CVE-2026-6826MEDIUM21 mai 2026
Concrete 9.5.0 and below has file usage disclosure via missing permission check in Usage controller
28RISCO
abrir
GitHub PoC1
PoC for CVE-2026-9082 (Drupal SA-CORE-2026-004) Drupal Core SQLi
CVE-2026-9082CRITICALsob ataque21 mai 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISCO
abrir
Exploit-DB
FUXA 1.2.9 - RCE
CVE-2026-25895CRITICALwebappsmultiple21 mai 2026
FUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload API
68RISCO
abrir
Metasploit300
Drupal Core PostgreSQL EntityQuery SQL Injection
CVE-2026-9082CRITICALsob ataque20 mai 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISCO
abrir
GitHub PoC
Maxime288/Fragnesia-CVE-2026-46300
CVE-2026-46300HIGH20 mai 2026
net: skbuff: preserve shared-frag marker during coalescing
56RISCO
abrir
GitHub PoC
Se realizó una evaluación de vulnerabilidades sobre una máquina virtual con Kali Linux utilizando un script detector para la vulnerabilidad Dirty Frag, asociada a las CVE-2026-43284 y CVE-2026-43500. Posteriormente se ejecutó un Proof of Concept (PoC) público escrito en lenguaje C para validar la posibilidad de realizar una escalada local
CVE-2026-43284HIGH20 mai 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISCO
abrir
GitHub PoC
A Go implementation of dirtyfrag (CVE-2026-43284 / CVE-2026-43500)
CVE-2026-43284HIGH20 mai 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISCO
abrir
GitHub PoC
fevar54/FULL-ANALYSIS---CVE-2026-45829-ChromaDB-
CVE-2026-45829CRITICAL20 mai 2026
A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an un
53RISCO
abrir
GitHub PoC
A small script to apply Yellowkey mitigation based on CVE-2026-45585 instructions
CVE-2026-45585MEDIUM20 mai 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RISCO
abrir
anteriorpágina 122 / 2.673próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.