Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.409exploits catalogados
37.196CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.478Referência 23.664GitHub PoC 15.347VulnCheck XDB 9.003Nuclei 4.415Metasploit 3.502✓ só verificadosrecentespopularesrisco
80.409 exploits
GitHub PoC
A PoC demonstrating a RCE in Hoverfly (versions ≤ 1.11.3) by abusing the /api/v2/hoverfly/middleware endpoint and injecting a malicious middleware script
Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation
68RISCO
abrir ↗GitHub PoC
BOLA/IDOR vulnerability in osTicket ajax.tickets.php | Responsible Disclosure
osTicket v1.18.3 - v1.17.7 - BOLA/IDOR in ticket field viewing allows cross-department data disclosure
41RISCO
abrir ↗GitHub PoC
Explota vulnerabilidad
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISCO
abrir ↗GitHub PoC★ 7
CVE-2025-54123 Hoverfly Authenticated Middleware Command Injection RCE
Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation
68RISCO
abrir ↗GitHub PoC★ 4
Chrome extension that uses vulnerabilities CVE-2021-33044 and CVE-2021-33045 to log in to Dahua cameras without authentication.
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISCO
abrir ↗VulnCheck XDB
initial-access
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISCO
abrir ↗VulnCheck XDB
info-leak
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiC
100RISCO
abrir ↗GitHub PoC★ 7
CVE-2022-46364-Poc Apache CXF SSRF via MTOM XOP:Include
Apache CXF SSRF Vulnerability
48RISCO
abrir ↗GitHub PoC
Python PoC for CVE-2026-23744, unauthenticated RCE in MCP servers via the /api/mcp/connect serverConfig command field (default port 6274)
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir ↗GitHub PoC
CVE-2026-25099 — Bludit CMS API Unrestricted File Upload to Remote Code Execution
Remote Code Execution via Unrestricted File Upload in Bludit
41RISCO
abrir ↗GitHub PoC
Drupal 7 CMS vulnerable to CVE-2018-7600 (Drupalgeddon2), allowing unauthenticated remote code execution.
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir ↗GitHub PoC
Conducted a full SOC investigation into a Conti ransomware compromise of an Exchange server using Splunk 8.2.2. Analysed 28,145 events across Windows Security, Sysmon, and IIS log sources to reconstruct the complete attack chain. Identified three exploited CVEs (CVE-2020-0796, CVE-2018-13374, CVE-2018-13379), located a trojanised cmd.exe
A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 al
75RISCO
abrir ↗VulnCheck XDB
info-leak
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiC
100RISCO
abrir ↗GitHub PoC★ 3
CVE-2026-33017: Unauthenticated RCE in Langflow
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir ↗VulnCheck XDB
initial-access
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir ↗GitHub PoC
Static analysis of the DarkSword iOS WebKit exploit chain — delivery, staging, and CVE breakdown (CVE-2025-31277, CVE-2025-43529)
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, mac
71RISCO
abrir ↗GitHub PoC★ 6
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RISCO
abrir ↗GitHub PoC
SentinelStream AI: A professional SIEM and SOAR platform featuring real-time threat correlation for CVE-2024-21410 and automated incident response logic.
Microsoft Exchange Server Elevation of Privilege Vulnerability
83RISCO
abrir ↗VulnCheck XDB
initial-access
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISCO
abrir ↗GitHub PoC
Conducted a full SOC investigation into a Conti ransomware compromise of an Exchange server using Splunk 8.2.2. Analysed 28,145 events across Windows Security, Sysmon, and IIS log sources to reconstruct the complete attack chain. Identified three exploited CVEs (CVE-2020-0796, CVE-2018-13374, CVE-2018-13379), located a trojanised cmd.exe
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir ↗VulnCheck XDB
initial-access
User Profile Builder < 3.15.2 - Unauthenticated Arbitrary Password Reset
48RISCO
abrir ↗GitHub PoC
Proof of Concept (PoC) exploit for CVE-2026-23744, a vulnerability affecting MCPJam Inspector that allows remote command execution (RCE) through exposed internal debugging endpoints
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir ↗GitHub PoC
BastianXploited/CVE-2025-6440
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISCO
abrir ↗GitHub PoC★ 1
Exploit script for CVE-2026-23744
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.