Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.095exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
15.312 exploits
GitHub PoC12
UAF and AOP coprocessor panic in IOHIDEventServiceFastPathUserClient. No entitlements, reachable from app sandbox.
CVE-2026-28992MEDIUM14 fev 2026
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7
33RISCO
abrir
GitHub PoC2
Herramienta avanzada de explotación transversal de ruta de WinRAR para CVE-2025-8088
CVE-2025-8088HIGHsob ataqueransomware14 fev 2026
Path traversal vulnerability in WinRAR
93RISCO
abrir
GitHub PoC
A lightweight Docker lab for experimenting with Telnet protocol negotiation, explained in the CVE-2026-24061 exploit, which contains automatic username injection using the NEW-ENVIRON option.
CVE-2026-24061CRITICALsob ataque14 fev 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
nik123-py/CVE-2025-49132_HTB_SEASON10
CVE-2025-49132CRITICAL14 fev 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISCO
abrir
GitHub PoC49
The PoC for CVE-2025-70795 / CVE-2026-0828 and updated driver
CVE-2025-70795MEDIUM14 fev 2026
STProcessMonitor 11.11.4.0, part of the Safetica Application suite, allows an admin-privileged user to send crafted IOCT
33RISCO
abrir
GitHub PoC5
A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to execute arbitrary code via injecting crafted Freemarker template syntax into the SQL script field.
CVE-2025-70830CRITICAL14 fev 2026
A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows aut
48RISCO
abrir
GitHub PoC
mbanyamer/CVE-2026-26335-Calero-VeraSMART-RCE
CVE-2026-26335CRITICAL14 fev 2026
Calero VeraSMART < 2022 R1 Static IIS Machine Keys Enable ViewState RCE
48RISCO
abrir
GitHub PoC
Домашняя работа по Pyton № 10 CVE-2020-11022 Краткое описание CVE-2020-11022 — уязвимость типа Reflected XSS (межсайтовый скриптинг), связанная с некорректной обработкой пользовательского ввода, который отражается в HTML-ответе без экранирования. Атакующий может внедрить JavaScript-код, который выполнится в браузере пользователя.
CVE-2020-11022MEDIUM14 fev 2026
jQuery has a potential XSS vulnerability
55RISCO
abrir
GitHub PoC12
UAF and AOP coprocessor panic in IOHIDEventServiceFastPathUserClient. No entitlements, reachable from app sandbox.
CVE-2026-28992MEDIUM14 fev 2026
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7
33RISCO
abrir
GitHub PoC
CVE-2024-37383 Proof of Concept
CVE-2024-37383MEDIUMsob ataque14 fev 2026
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
85RISCO
abrir
GitHub PoC50
The PoC for CVE-2025-70795 / CVE-2026-0828 and updated driver
CVE-2026-0828HIGH14 fev 2026
Kernel driver vulnerability in Safetica Endpoint Client
41RISCO
abrir
GitHub PoC
Privilege escalation exploit chain (CVE-2025-6018 + CVE-2025-6019) for openSUSE Leap 15.6
CVE-2025-6018HIGH14 fev 2026
Pam-config: lpe from unprivileged to allow_active in pam
41RISCO
abrir
GitHub PoC
Samba 3.0.20 CVE-2007-2447 Exploit
CVE-2007-244714 fev 2026
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir
GitHub PoC1
针对 Next.js 原型污染漏洞 (CVE-2025-55182) 的高效批量检测工具。
CVE-2025-55182CRITICALsob ataqueransomware13 fev 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC1
Vulnerability chaining leads to privilege escalation
CVE-2025-6018HIGH13 fev 2026
Pam-config: lpe from unprivileged to allow_active in pam
41RISCO
abrir
GitHub PoC
BIG02-bot/React2Shell-CVE-2025-55182-An-lise-T-cnica
CVE-2025-55182CRITICALsob ataqueransomware13 fev 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC4
watchtowrlabs/watchTowr-vs-SolarWinds-WebHelpDesk-CVE-2025-40552-CVE-2025-40553
CVE-2025-40552CRITICAL13 fev 2026
SolarWinds Web Help Desk Authentication Bypass Vulnerability
75RISCO
abrir
GitHub PoC1
CVE-2024-34102 exploit for python3
CVE-2024-34102CRITICALsob ataque13 fev 2026
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir
GitHub PoC3
CVE-2025-49132_PHP_PEAR_METHOD
CVE-2025-49132CRITICAL12 fev 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISCO
abrir
GitHub PoC
scroollocker/CVE-2025-49132
CVE-2025-49132CRITICAL12 fev 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISCO
abrir
GitHub PoC5
CVE-2025-6018 CVE-2025-6019 PoC Exploit - Local Privilege Escalation in openSUSE/SUSE Linux Enterprise 15 - PAM bypass + udisks2 XFS race condition LPE to root
CVE-2025-6018HIGH12 fev 2026
Pam-config: lpe from unprivileged to allow_active in pam
41RISCO
abrir
GitHub PoC2
React2Shell (CVE-2025-55182) POC
CVE-2025-55182CRITICALsob ataqueransomware12 fev 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Sn0wBaall/CVE-2023-4220-PoC
CVE-2023-4220HIGH12 fev 2026
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir
GitHub PoC1
Exploit CVE-2025-49132 Pterodactyl Panel RCE
CVE-2025-49132CRITICAL12 fev 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISCO
abrir
GitHub PoC
Real-world information security risk assessment based on the Oracle E-Business Suite zero-day (CVE-2025-61882). Analyses attacker methods, enterprise risks, and mitigation strategies using ISO 27001, NIST CSF, Cyber Essentials and COBIT.
CVE-2025-61882CRITICALsob ataqueransomware12 fev 2026
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integratio
100RISCO
abrir
GitHub PoC
mbanyamer/CVE-2026-26235-JUNG-Smart-Visu-Server-Unauthenticated-Reboot-Shutdown
CVE-2026-26235HIGH12 fev 2026
JUNG Smart Visu Server 1.1.1050 - 'JUNG Smart Visu Server' Missing Authentication
41RISCO
abrir
GitHub PoC1
Ni8mare, n8n RCE
CVE-2026-21858CRITICAL11 fev 2026
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RISCO
abrir
GitHub PoC4
This program Prompts you for the Local File Inclusion information and will automatically search the /etc/passwd and using the users names found will search for and download any SSH key or variation of keys to the local computer. This program also performs the CVE-2021-41773_ apache2.4.49 and 50 traversal path exploit. In addtion to other LFI Vuln
CVE-2021-41773HIGHsob ataqueransomware11 fev 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
A POC chain exploit using the recent Cisco SMP exploit (CVE-2017-6736) to chain into Spectre (CVE-2017-5753 and CVE-2017-5715)
CVE-2017-6736HIGHsob ataque11 fev 2026
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabiliti
93RISCO
abrir
GitHub PoC
ISabbiI/PoC-Apache-CVE-2021-41773-Infrastructure-LAB
CVE-2021-41773HIGHsob ataqueransomware11 fev 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
anteriorpágina 129 / 511próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.