Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.403exploits catalogados
37.194CVEs com exploração pública
24.695testados em laboratório
80.405 exploits
GitHub PoC4
CVE-2026-5027 - Langflow Path Traversal to Remote Code Execution (CVSS 8.8)
CVE-2026-5027HIGH02 abr 2026
Langflow - Path Traversal Arbitrary File Write via upload_user_file
68RISCO
abrir
GitHub PoC8
POC for CVE-2026-23416 (linux kernel 6.17 – linux kernel 7 rc5) - vulnerability discovered by Antonius
CVE-2026-2341602 abr 2026
mm/mseal: update VMA end correctly on merge
23RISCO
abrir
GitHub PoC
Full penetration test report against `IP` (Ubuntu VM). Attack chain: directory enumeration → backup file discovery → password cracking → CMS file upload → reverse shell → kernel privilege escalation (Dirty Pipe, CVE-2022-0847).
CVE-2022-0847HIGHsob ataque02 abr 2026
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC
CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware02 abr 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
FortiGate CVE-2022-40684 assessment tool for user enumeration, configuration dump, and lab testing.
CVE-2022-40684CRITICALsob ataqueransomware01 abr 2026
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-40684CRITICALsob ataqueransomware01 abr 2026
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir
GitHub PoC11
Full-chain exploit for CVE-2025-2783 (Ipcz Sandbox Escape & RCE).
CVE-2025-2783HIGHsob ataque01 abr 2026
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
71RISCO
abrir
GitHub PoC
Módulo de Metasploit para explotar CVE-2025-24054 (ex 24071). Exploit de filtración NTLM integrado en Metasploit para vectores de ataque basados en bibliotecas de Windows.
CVE-2025-24054MEDIUMsob ataque01 abr 2026
NTLM Hash Disclosure Spoofing Vulnerability
75RISCO
abrir
GitHub PoC3
Detect, assess, and respond to supply chain attacks across npm/yarn and Python (pip/poetry/uv). Claude Code skill + standalone scripts. Built during axios RAT (2026-03-31) and Starlette BadHost CVE-2026-48710 (2026-05-22).
CVE-2026-48710MEDIUMsob ataque01 abr 2026
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
90RISCO
abrir
GitHub PoC
TLevente20/HTTP-2-RapidReset-CVE-2023-44487-Testlab
CVE-2023-44487HIGHsob ataque01 abr 2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISCO
abrir
VulnCheck XDB
local
CVE-2025-24054MEDIUMsob ataque01 abr 2026
NTLM Hash Disclosure Spoofing Vulnerability
75RISCO
abrir
GitHub PoC
kavin71725/CVE-2025-12543-Fix-for-Wildfly
CVE-2025-12543CRITICAL01 abr 2026
Undertow-core: undertow http server fails to reject malformed host headers leading to potential cache poisoning and ssrf
48RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-2783HIGHsob ataque01 abr 2026
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
71RISCO
abrir
GitHub PoC1
Technical analysis of a SharePoint ToolShell (CVE-2025-53770) exploitation attempt involving RCE, webshell deployment, and MachineKey extraction.
CVE-2025-53770CRITICALsob ataqueransomware01 abr 2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
Analisis de CVE relacionada con stack overflow
CVE-2025-5548MEDIUM01 abr 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISCO
abrir
GitHub PoC
CVE-2021-21220 Exploitation infrastructure
CVE-2021-21220HIGHsob ataque01 abr 2026
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to po
100RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2023-44487HIGHsob ataque01 abr 2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISCO
abrir
GitHub PoC
Full penetration testing workflow: credential brute force, SSH access and privilege escalation (CVE-2021-4034)
CVE-2021-4034HIGHsob ataqueransomware01 abr 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2021-21220HIGHsob ataque01 abr 2026
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to po
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-54123CRITICAL31 mar 2026
Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation
68RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-11680CRITICALsob ataque31 mar 2026
ProjectSend Unauthenticated Configuration Modification
100RISCO
abrir
GitHub PoC
wtbacon/cve-2018-15473
CVE-2018-15473MEDIUM31 mar 2026
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALsob ataque31 mar 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir
GitHub PoC7
Chatwoot SQL injection in FilterService
CVE-2026-44706HIGH31 mar 2026
Chatwoot: SQL Injection in Conversation/Contact Filter API via Custom Attribute Values
41RISCO
abrir
GitHub PoC
This repository contains a proof-of-concept (PoC) exploit for CVE-2024-11680, a critical vulnerability in ProjectSend r1605 and earlier versions. The exploit is aimed at incorrect authentication due to problems with incorrect privilege settings and command injection.
CVE-2024-11680CRITICALsob ataque31 mar 2026
ProjectSend Unauthenticated Configuration Modification
100RISCO
abrir
GitHub PoC
kaleth4/CVE-2024-6387
CVE-2024-6387HIGH31 mar 2026
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir
GitHub PoC11
Langflow RCE
CVE-2026-33017CRITICALsob ataque31 mar 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir
GitHub PoC
Hoverfly CVE RCE
CVE-2025-54123CRITICAL31 mar 2026
Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation
68RISCO
abrir
GitHub PoC1
CVE-2022-46364 Apache CXF XOP:Include SSRF / LFI
CVE-2022-46364CRITICAL31 mar 2026
Apache CXF SSRF Vulnerability
48RISCO
abrir
GitHub PoC3
Automating the exploitation of CVE-2026-7299 - Stored XSS via Database Table/Column Names in SQL Autocomplete within Appsmith =>1.99. Initial discovery 30/03/26
CVE-2026-7299MEDIUM31 mar 2026
CVE-2026-7299
33RISCO
abrir
anteriorpágina 168 / 2.681próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.