Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.095exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
15.312 exploits
GitHub PoC
ross-ns/WSUS-CVE-2025-59287
CVE-2025-59287CRITICALsob ataque18 fev 2026
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
havbay/CVE-2025-47812-PoC
CVE-2025-47812CRITICALsob ataque18 fev 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir
GitHub PoC136
huseyinstif/CVE-2026-2441-PoC
CVE-2026-2441HIGHsob ataque18 fev 2026
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside
76RISCO
abrir
GitHub PoC1
orgito1015/CVE-2025-55182-Researching-process
CVE-2025-55182CRITICALsob ataqueransomware18 fev 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
A deep-dive security analysis into the 2020 Virgin Mobile KSA data breach. This study dissects the exploitation of CVE-2020-0688, evaluates the impact of delayed patch management, and proposes a robust multi-layered defense architecture to prevent sophisticated exfiltration tactics.
CVE-2020-0688HIGHsob ataqueransomware18 fev 2026
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
GitHub PoC
mbanyamer/CVE-2026-24061-GNU-Inetutils-telnetd-Remote-Authentication-Bypass-Root-Shell-
CVE-2026-24061CRITICALsob ataque18 fev 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
Lab Environment for CVE-2026-22241
CVE-2026-22241HIGH18 fev 2026
Open eClass has Unrestricted File Upload that Leads to Remote Code Execution (RCE)
41RISCO
abrir
GitHub PoC
Exploit for CVE-2024-6232 - Python Tarfile Realpath Overflow
CVE-2025-4517CRITICAL18 fev 2026
Arbitrary writes via tarfile realpath overflow
48RISCO
abrir
GitHub PoC2
Command injection vulnerability in elFinder <= 2.1.47 via the PHP connector component. Allows unauthenticated remote code execution as the web server user.
CVE-2019-919418 fev 2026
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RISCO
abrir
GitHub PoC1
Unauthenticated remote code execution vulnerability in WordPress Bricks Builder <= 1.9.6. The template render endpoint accepts PHP code without authentication, allowing arbitrary command execution as the web server user.
CVE-2024-25600CRITICAL18 fev 2026
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir
GitHub PoC
PoC and explanation for CVE-2025-4517 used in a CTF I was playing.
CVE-2025-4517CRITICAL17 fev 2026
Arbitrary writes via tarfile realpath overflow
48RISCO
abrir
GitHub PoC
Interactive shell client for React Server Components RCE exploitation via __proto__ pollution (CVE-2025-55182)
CVE-2025-55182CRITICALsob ataqueransomware17 fev 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
andres101c/Shellshock-CVE-2014-6271
CVE-2014-6271CRITICALsob ataque17 fev 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC
New CVE-2019-7609 which works with python 13
CVE-2019-7609CRITICALsob ataque17 fev 2026
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISCO
abrir
GitHub PoC
Proof-of-concept exploit for CVE-2023-20198, an authentication bypass vulnerability affecting Cisco IOS XE Web UI
CVE-2023-20198CRITICALsob ataque17 fev 2026
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISCO
abrir
GitHub PoC2
CVE-2025-47812 POC
CVE-2025-47812CRITICALsob ataque17 fev 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir
GitHub PoC
rogerzeferino/Apache-Solr-RCE-CVE-2019-17558
CVE-2019-17558HIGHsob ataque16 fev 2026
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RISCO
abrir
GitHub PoC4
CVE For Pterodactyl (For Study and Education)
CVE-2025-49132CRITICAL16 fev 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISCO
abrir
GitHub PoC
rootdirective-sec/CVE-2026-23744-Lab
CVE-2026-23744CRITICAL16 fev 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
GitHub PoC
A high-performance Python toolkit to automate the CVE-2025-4517 PATH_MAX bypass exploit. Specifically tuned for the WingData HTB challenge to achieve arbitrary file writes and root persistence
CVE-2025-4517CRITICAL16 fev 2026
Arbitrary writes via tarfile realpath overflow
48RISCO
abrir
GitHub PoC
Authenticated RCE in Netgate pfSense CE 2.7.2 and 2.8.0
CVE-2025-69690CRITICAL16 fev 2026
Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP ob
48RISCO
abrir
GitHub PoC1
rogerzeferino/cve-2019-17558-apache-solr-rce
CVE-2019-17558HIGHsob ataque16 fev 2026
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RISCO
abrir
GitHub PoC1
simple CVE-2017-7921 rewrite in python by me. for educational purposes only!
CVE-2017-7921CRITICALsob ataque15 fev 2026
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISCO
abrir
GitHub PoC
[AtHack 2026] Pwn challenge about telnetd CVE-2026-24061
CVE-2026-24061CRITICALsob ataque15 fev 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC2
CVE-2025-4517 (CVSS 9.4 – Critical) A vulnerability in Python's `tarfile`
CVE-2025-4517CRITICAL15 fev 2026
Arbitrary writes via tarfile realpath overflow
48RISCO
abrir
GitHub PoC
Modified Exploit-DB proof-of-concept for CVE-2014-4688 (pfSense status_rrd_graph_img.php command injection)
CVE-2014-468815 fev 2026
pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_
23RISCO
abrir
GitHub PoC
CVE-2025-47812: Wing FTP Server 7.4.3 UnauthN RCE in sh
CVE-2025-47812CRITICALsob ataque15 fev 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir
GitHub PoC8
Python tarfile data filter bypass via PATH_MAX overflow in os.path.realpath() - CVE-2025-4517 / CVE-2025-4330
CVE-2025-4517CRITICAL15 fev 2026
Arbitrary writes via tarfile realpath overflow
48RISCO
abrir
GitHub PoC8
Privilege Escalation script for CVE-2025-4517
CVE-2025-4517CRITICAL15 fev 2026
Arbitrary writes via tarfile realpath overflow
48RISCO
abrir
GitHub PoC2
CVE‑2025‑4517 Proof‑of‑Concept Script
CVE-2025-4517CRITICAL15 fev 2026
Arbitrary writes via tarfile realpath overflow
48RISCO
abrir
anteriorpágina 128 / 511próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.