Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.095exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
15.312 exploits
GitHub PoC2
CVE-2018-13379 fortiOS vulnerability POC
CVE-2018-13379CRITICALsob ataqueransomware05 fev 2026
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISCO
abrir
GitHub PoC
Log4Shell (CVE-2021-44228) security remediation demo - Showcasing Antigravity's ability to identify and fix critical security vulnerabilities in Java applications
CVE-2021-44228CRITICALsob ataqueransomware05 fev 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
CVE-2024-46987 - Camaleon CMS LFI Exploit
CVE-2024-46987HIGH05 fev 2026
Arbitrary path traversal in Camaleon CMS
61RISCO
abrir
GitHub PoC
CVE-2025-32463
CVE-2025-32463CRITICALsob ataque05 fev 2026
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC3
jduardo2704/CVE-2026-25643-Frigate-RCE
CVE-2026-25643CRITICAL05 fev 2026
Frigate Affected by Authenticated Remote Command Execution (RCE) and Container Escape
48RISCO
abrir
GitHub PoC
Exploit for CVE-2024-46987
CVE-2024-46987HIGH05 fev 2026
Arbitrary path traversal in Camaleon CMS
61RISCO
abrir
GitHub PoC1
Exploit created using Python
CVE-2024-46987HIGH05 fev 2026
Arbitrary path traversal in Camaleon CMS
61RISCO
abrir
GitHub PoC
killsystema/scan-cve-2026-24061
CVE-2026-24061CRITICALsob ataque05 fev 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC1
RedTeamBlueTeam/CVE-2024-5084-Red-Team
CVE-2024-5084CRITICAL05 fev 2026
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
75RISCO
abrir
GitHub PoC
Evillm/CVE-2025-27520-PoC
CVE-2025-27520CRITICAL04 fev 2026
BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
75RISCO
abrir
GitHub PoC
Ik0nw/CVE-2024-46987
CVE-2024-46987HIGH04 fev 2026
Arbitrary path traversal in Camaleon CMS
61RISCO
abrir
GitHub PoC
lavabyte/telnet-CVE-2026-24061
CVE-2026-24061CRITICALsob ataque04 fev 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
canpilayda/inetutils-telnetd-cve-2026-24061
CVE-2026-24061CRITICALsob ataque04 fev 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
thai1012/cve-2020-0796
CVE-2020-0796CRITICALsob ataqueransomware04 fev 2026
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC54
Advanced PoC & Research for CVE-2026-0828 (Safetica) and CVE-2025-7771 (ThrottleStop). Analysis of BYOVD (Bring Your Own Vulnerable Driver) TTPs for Ring 0 process termination and physical memory R/W. Researching EDR-Killer patterns, PPL bypasses, and kernel-mode primitives used by MedusaLocker and other threat actors.
CVE-2025-7771HIGH04 fev 2026
Code Execution / Escalation of Privileges in ThrottleStop
41RISCO
abrir
GitHub PoC54
Advanced PoC & Research for CVE-2026-0828 (Safetica) and CVE-2025-7771 (ThrottleStop). Analysis of BYOVD (Bring Your Own Vulnerable Driver) TTPs for Ring 0 process termination and physical memory R/W. Researching EDR-Killer patterns, PPL bypasses, and kernel-mode primitives used by MedusaLocker and other threat actors.
CVE-2026-0828HIGH04 fev 2026
Kernel driver vulnerability in Safetica Endpoint Client
41RISCO
abrir
GitHub PoC
Evillm/CVE-2023-4634-PoC
CVE-2023-4634CRITICAL04 fev 2026
Media Library Assistant <= 3.09 - Unauthenticated Local/Remote File Inclusion & Remote Code Execution
85RISCO
abrir
GitHub PoC
Evillm/CVE-2025-49113-PoC
CVE-2025-49113CRITICALsob ataque04 fev 2026
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISCO
abrir
GitHub PoC
Evillm/CVE-2024-8856-PoC
CVE-2024-8856CRITICAL04 fev 2026
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RISCO
abrir
GitHub PoC
Evillm/CVE-2025-55182-PoC
CVE-2025-55182CRITICALsob ataqueransomware04 fev 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
CVE-2025-65791 — Command Injection in ZoneMinder
CVE-2025-65791CRITICAL03 fev 2026
ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user i
48RISCO
abrir
GitHub PoC
aditidutta696-dev/Spring4Shell-CVE-2022-22965-Exploitation-Attempt
CVE-2022-22965CRITICALsob ataque03 fev 2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
GitHub PoC
🚨 Exploit CVE-2026-24061, a critical remote authentication bypass in GNU inetutils-telnetd, for instant root shell access without authentication.
CVE-2026-24061CRITICALsob ataque03 fev 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
Path Traversal vulnerability
CVE-2024-46987HIGH03 fev 2026
Arbitrary path traversal in Camaleon CMS
61RISCO
abrir
GitHub PoC2
A Firefox extension for detecting React2Shell vulnerabilities (CVE-2025-55182 & CVE-2025-66478) in web applications.
CVE-2025-55182CRITICALsob ataqueransomware03 fev 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC2
Professional exploit for CVE-2024-28397: Js2Py Sandbox Escape leading to Remote Code Execution (RCE). Includes modular payload generation.
CVE-2024-28397MEDIUM03 fev 2026
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISCO
abrir
GitHub PoC5
GNU InetUtils telnetd - Unauthenticated Remote Root via NEW-ENVIRON Variable Injection.
CVE-2026-24061CRITICALsob ataque02 fev 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC1
Spydomain/CVE-2017-1000112-PoC
CVE-2017-100011202 fev 2026
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE
43RISCO
abrir
GitHub PoC1
thomas-osgood/cve-2025-58360
CVE-2025-58360HIGHsob ataque02 fev 2026
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RISCO
abrir
GitHub PoC1
[우리 FISA] 기술 세미나 우승 - 클라우드 서비스 개발 6기 3팀 - React2Shell (CVE-2025-55182) 분석 및 연구
CVE-2025-55182CRITICALsob ataqueransomware02 fev 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
anteriorpágina 132 / 511próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.