Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.095exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
15.312 exploits
GitHub PoC1
A Proof of Concept for CVE-2025-29927 demonstrating a middleware bypass in Next.js versions prior to 13.5.9
CVE-2025-29927CRITICAL26 jan 2026
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
Vulnerability in GNU InetUtils telnetd Enables Remote Root Access
CVE-2026-24061CRITICALsob ataque26 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
Spring Cloud Gateway SpEL RCE Vulnerability Environment
CVE-2025-41243CRITICAL26 jan 2026
Spring Expression Language property modification using Spring Cloud Gateway Server WebFlux
63RISCO
abrir
GitHub PoC4
POC (RCE) -> CVE-2019-9978
CVE-2019-9978MEDIUMsob ataque25 jan 2026
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir
GitHub PoC
CVE-2025-60021
CVE-2025-60021CRITICAL25 jan 2026
Apache bRPC: Remote command injection vulnerability in heap builtin service
53RISCO
abrir
GitHub PoC
dionissh/CVE-2024-21413
CVE-2024-21413CRITICALsob ataque25 jan 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
CVE-2025-64155
CVE-2025-64155CRITICAL25 jan 2026
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
60RISCO
abrir
GitHub PoC
Python demo simulating CVE-2024-3094: a supply chain backdoor in XZ Utils with a trigger-based stealth activation.
CVE-2024-3094CRITICAL25 jan 2026
Xz: malicious code in distributed source
70RISCO
abrir
GitHub PoC1
CVE-2026-24061 PoC
CVE-2026-24061CRITICALsob ataque25 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
CVE-2026-24061
CVE-2026-24061CRITICALsob ataque25 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
GNU telnetd service from GNU InetUtils authentication-bypass
CVE-2026-24061CRITICALsob ataque25 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
Baza-NATO/CVE-2021-33044
CVE-2021-33044CRITICALsob ataque25 jan 2026
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISCO
abrir
GitHub PoC2
This script exploits an SQL Injection vulnerability in WordPress Quiz Maker plugin (≤ 6.7.0.56) by injecting payloads via an HTTP header (default: X-Forwarded-For).
CVE-2025-10042MEDIUM25 jan 2026
Quiz Maker <= 6.7.0.56 - Unauthenticated SQL Injection
33RISCO
abrir
GitHub PoC
ms0x08-dev/CVE-2026-24061-POC
CVE-2026-24061CRITICALsob ataque25 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
jagg3rsec/CVE-2014-6287
CVE-2014-6287CRITICALsob ataque25 jan 2026
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir
GitHub PoC
CVE-2026-21876 OWASP ModSecurity CRS WAF bypass (docker container + minimal PoC).
CVE-2026-21876CRITICAL25 jan 2026
OWASP CRS has multipart bypass using multiple content-type parts
53RISCO
abrir
GitHub PoC2
CVE-2015-2291 Local Privilege Escalation PoC
CVE-2015-2291HIGHsob ataqueransomware25 jan 2026
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows all
71RISCO
abrir
GitHub PoC
xitexploiter96-dot/CVE-2023-38408
CVE-2023-38408CRITICAL24 jan 2026
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISCO
abrir
GitHub PoC1
Nuclei template for CVE-2026-24061
CVE-2026-24061CRITICALsob ataque24 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
For HTB practice
CVE-2022-44268MEDIUM24 jan 2026
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISCO
abrir
GitHub PoC
CVE-2026-24061 - GNU InetUtils telnetd authentication bypass POC + Docker lab environment for testing
CVE-2026-24061CRITICALsob ataque24 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC1
A secure, zero-trust database management tool for WordPress. Fixes critical SSRF vulnerabilities (CVE-2021-21311) by enforcing local connections only.
CVE-2021-21311HIGHsob ataque24 jan 2026
SSRF in adminer
100RISCO
abrir
GitHub PoC
z3n70/CVE-2026-24061
CVE-2026-24061CRITICALsob ataque24 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
ranasen-rat/cve-2021-42013
CVE-2021-42013CRITICALsob ataqueransomware24 jan 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC
BrainBob/Telnet-TestVuln-CVE-2026-24061
CVE-2026-24061CRITICALsob ataque24 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC7
CVE-2026-24061's poc : a critical authentication bypass in telnetd leading to RCE as root Affects systems with telnetd versions containing the vulnerability from 2015 onwards.
CVE-2026-24061CRITICALsob ataque24 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC4
Docker setup for CVE-2026-24061
CVE-2026-24061CRITICALsob ataque24 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
BrainBob/CVE-2026-24061
CVE-2026-24061CRITICALsob ataque24 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC4
CVE-2026-24061 - GNU InetUtils Telnetd Remote Authentication Bypass
CVE-2026-24061CRITICALsob ataque24 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
GNU Inetutils telnetd Remote Authentication Bypass
CVE-2026-24061CRITICALsob ataque24 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
anteriorpágina 135 / 511próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.