Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.324exploits catalogados
37.130CVEs com exploração pública
24.695testados em laboratório
80.324 exploits
VulnCheck XDB
local
CVE-2026-31431HIGHsob ataque04 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHsob ataque04 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHsob ataque04 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHsob ataque04 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC
CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection
CVE-2026-41940CRITICALsob ataqueransomware04 mai 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC
Exploit CVE-2026-41940 auto exploit
CVE-2026-41940CRITICALsob ataqueransomware04 mai 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALsob ataqueransomware04 mai 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALsob ataqueransomware04 mai 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC
cPanel-WHM-CVE-2026-41940-AuthBypass
CVE-2026-41940CRITICALsob ataqueransomware04 mai 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC
kaleth4/CVE-2025-68930
CVE-2025-68930HIGH04 mai 2026
Traccar Missing Origin Validation in WebSockets
41RISCO
abrir
Exploit-DB
Traccar GPS Tracking System 6.11.1 - Cross-Site WebSocket Hijacking (CSWSH)
CVE-2025-68930HIGHwebappsmultiple04 mai 2026
Traccar Missing Origin Validation in WebSockets
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-69985CRITICAL04 mai 2026
FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnera
48RISCO
abrir
VulnCheck XDB
local
CVE-2026-33825HIGHsob ataqueransomware04 mai 2026
Microsoft Defender Elevation of Privilege Vulnerability
71RISCO
abrir
GitHub PoC
LetsDefend SOC336 case study on CVE-2025-21298
CVE-2025-21298CRITICAL04 mai 2026
Windows OLE Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC
kaleth4/CVE-2025-60751
CVE-2025-60751HIGH04 mai 2026
GeographicLib 2.5 is vulnerable to Buffer Overflow in GeoConvert DMS::InternalDecode.
41RISCO
abrir
GitHub PoC1
CVE-2026-41940: detect and exploit cpanel vuln
CVE-2026-41940CRITICALsob ataqueransomware04 mai 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
Exploit-DB
Linksys E1200 2.0.04 - Authenticated Stack Buffer Overflow (RCE)
CVE-2025-60690HIGHhardwaremultiple04 mai 2026
A stack-based buffer overflow exists in the get_merge_ipaddr function of the httpd binary on Linksys E1200 v2 routers (F
41RISCO
abrir
GitHub PoC
kaleth4/CVE-2025-40271
CVE-2025-40271HIGH04 mai 2026
fs/proc: fix uaf in proc_readdir_de()
41RISCO
abrir
GitHub PoC
Controlled virtual attack & defense lab — CVE-2011-2523 exploitation, Nmap recon, Nikto scanning, UFW hardening on Metasploitable 2
CVE-2011-252304 mai 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-42167HIGH04 mai 2026
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where th
56RISCO
abrir
Exploit-DB
Windows 11 24H2 - Local Privilege Escalation
CVE-2026-21250HIGHlocalwindows04 mai 2026
Windows HTTP.sys Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC5
Sorry ransomware (.sorry) IOCs, YARA rules and forensic analysis - CVE-2026-41940 cPanel campaign
CVE-2026-41940CRITICALsob ataqueransomware04 mai 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC4
Read-only Bash checker for the Copy Fail Linux kernel vulnerability (CVE-2026-31431)
CVE-2026-31431HIGHsob ataque04 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC
This repository contains a Python verification script for `CVE-2026-41940`, a critical authentication bypass vulnerability disclosed in cPanel & WHM. > This project is intended for authorized defensive validation only. It is not intended for exploit development, unauthorized access, or misuse against systems you do not own or administer.
CVE-2026-41940CRITICALsob ataqueransomware04 mai 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC1
rootdirective-sec/CVE-2026-39987-Lab
CVE-2026-39987CRITICALsob ataque04 mai 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISCO
abrir
GitHub PoC
Mrhudson69/cve-2026-31431
CVE-2026-31431HIGHsob ataque04 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC
kaleth4/CVE-2025-47987
CVE-2025-47987HIGH04 mai 2026
Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC10
Safe detection tooling for CVE-2026-31431 "Copy Fail" and CVE-2026-43284 "Dirty Frag" — a local privilege escalation in the Linux kernel's algif_aead module affecting all major distributions since 2017.
CVE-2026-31431HIGHsob ataque04 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC1
CVE-2026-36356: MeiG Smart FORGE_SLT711 GoAhead - Unauthenticated OS Command Injection (RCE as root)
CVE-2026-36356CRITICAL03 mai 2026
The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthentica
53RISCO
abrir
GitHub PoC1
CVE-2020-11022
CVE-2020-11022MEDIUM03 mai 2026
jQuery has a potential XSS vulnerability
55RISCO
abrir
anteriorpágina 144 / 2.678próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.