Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.095exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
15.312 exploits
GitHub PoC
Clarification Regarding the Rejection Arguments
CVE-2025-56005CRITICAL28 jan 2026
An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the
53RISCO
abrir
GitHub PoC1
GNU Inetutils telnet远程认证绕过漏洞(CVE-2026-24061),该漏洞源于 GNU Inetutils telnetd 组件中对环境变量处理不当,攻击者可利用该漏洞,通过构造恶意的 USER 环境变量并发送至受影响的 telnet 服务,触发认证绕过机制,进而实现无需密码直接获取root权限。
CVE-2026-24061CRITICALsob ataque28 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC1
Checks for CVE-2026-24061 Telnetd exploit
CVE-2026-24061CRITICALsob ataque28 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
Lab to show the CVE-2026-24061
CVE-2026-24061CRITICALsob ataque28 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
22imer/CVE-2014-0160
CVE-2014-0160HIGHsob ataque28 jan 2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC
Heartbleed (CVE-2014-0160) was devastating because it leaked adjacent memory. CTT-Heartbleed goes further—it uses 33-layer temporal resonance to map, reconstruct, and extract specific memory regions across time, not just adjacent buffers.
CVE-2014-0160HIGHsob ataque28 jan 2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC
WordPress Theme Workreap 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
CVE-2021-2449928 jan 2026
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
50RISCO
abrir
GitHub PoC
CVE-2026-24061 Telnet RCE Exploit For Linux MacOS Windows
CVE-2026-24061CRITICALsob ataque28 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC1
CTT-Enhanced iOS Safari Exploit (based on CVE-2025-43529)
CVE-2025-43529HIGHsob ataque28 jan 2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
71RISCO
abrir
GitHub PoC
Very rough PoC for detecting/reproducing CVE-2022-0847 (dirty pipe) through random generation of syscalls and differential fuzzing against a model.
CVE-2022-0847HIGHsob ataque28 jan 2026
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC5
用于借助FOFA快速测试海康威视的CVE-2017-7921漏洞,并且给出登陆账号和密码,并输出json文件。
CVE-2017-7921CRITICALsob ataque28 jan 2026
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISCO
abrir
GitHub PoC1
CTT-enhanced version of the Microsoft Exchange Server SSRF to RCE exploit (ProxyShell/ProxyLogon), another CVSS 10.0 critical vulnerability that affected hundreds of thousands of organizations worldwide.
CVE-2021-26855CRITICALsob ataqueransomware28 jan 2026
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
Looking at current high-impact vulnerabilities, let's use the VMware vCenter Server CVE-2021-21972 (CVSS 9.8) as our base. This is a publicly known RCE with patches available, perfect for demonstrating CTT enhancements.
CVE-2021-21972CRITICALsob ataqueransomware27 jan 2026
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir
GitHub PoC
Sn0wBaall/CVE-2024-23334-PoC
CVE-2024-23334MEDIUM27 jan 2026
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISCO
abrir
GitHub PoC4
This is a security exploit tool targeting CVE-2025-55182. It exploits a Remote Code Execution (RCE) vulnerability in React Server Components
CVE-2025-55182CRITICALsob ataqueransomware27 jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
androidteacher/CVE-2024-50498-wpquery
CVE-2024-50498CRITICAL27 jan 2026
WordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability
75RISCO
abrir
GitHub PoC1
0xLittleSpidy/CVE-2025-54309
CVE-2025-54309CRITICALsob ataque27 jan 2026
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RISCO
abrir
GitHub PoC1
FurkanKAYAPINAR/CVE-2026-24061-telnet2root
CVE-2026-24061CRITICALsob ataque27 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC1
Telnetd Auth Bypass Scanner (CVE-2026-24061) A Python-based scanner for detecting and exploiting the CVE-2026-24061 vulnerability in GNU Inetutils telnetd services. This tool scans IP addresses or networks for vulnerable telnetd services that allow authentication bypass leading to root shell access.
CVE-2026-24061CRITICALsob ataque27 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
Arguments to reject CVE-2025-56005
CVE-2025-56005CRITICAL27 jan 2026
An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the
53RISCO
abrir
GitHub PoC
Payload CVE-2026-24061
CVE-2026-24061CRITICALsob ataque27 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
androidteacher/CVE-2026-24061-PoC-Telnetd
CVE-2026-24061CRITICALsob ataque27 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
Simple and effective PoC for CVE-2021-43798 Grafana Path Traversal
CVE-2021-43798HIGHsob ataque27 jan 2026
Grafana path traversal
100RISCO
abrir
GitHub PoC
An advanced exploit for Microsoft Exchange Server (CVE-2021-26855, CVE-2021-27065) enhanced with Convergent Time Theory principles, achieving near-perfect theoretical rating through quantum temporal resonance and α-dispersion techniques.
CVE-2021-26855CRITICALsob ataqueransomware27 jan 2026
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
Spring Cloud Gateway SpEL RCE Vulnerability Environment
CVE-2025-41243CRITICAL26 jan 2026
Spring Expression Language property modification using Spring Cloud Gateway Server WebFlux
63RISCO
abrir
GitHub PoC
afifudinmtop/CVE-2009-3103
CVE-2009-310326 jan 2026
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RISCO
abrir
GitHub PoC17
CVE-2026-24061 GNU Inetutils telnetd 身份验证绕过漏洞检测与利用 GUI 工具
CVE-2026-24061CRITICALsob ataque26 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
Vulnerability in GNU InetUtils telnetd Enables Remote Root Access
CVE-2026-24061CRITICALsob ataque26 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
🔍 Analyze WebKit and ANGLE vulnerabilities with this repository for CVE-2025-43529 and CVE-2025-14174, focusing on verified components and ongoing efforts.
CVE-2025-43529HIGHsob ataque26 jan 2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
71RISCO
abrir
GitHub PoC1
A Proof of Concept for CVE-2025-29927 demonstrating a middleware bypass in Next.js versions prior to 13.5.9
CVE-2025-29927CRITICAL26 jan 2026
Authorization Bypass in Next.js Middleware
85RISCO
abrir
anteriorpágina 134 / 511próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.