Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.409exploits catalogados
37.196CVEs com exploração pública
24.695testados em laboratório
80.409 exploits
VulnCheck XDB
local
CVE-2025-8088HIGHsob ataqueransomware25 mar 2026
Path traversal vulnerability in WinRAR
93RISCO
abrir
GitHub PoC
Master's Thesis research on CVE-2024-30051 (Windows DWM Heap Overflow). Features a high-reliability exploit with automated heap spray optimization, real-time logging, and empirical success-rate analysis. Portfolio piece demonstrating advanced Windows binary exploitation, heap layout manipulation, and LPE via Desktop Window Manager.
CVE-2024-30051HIGHsob ataqueransomware25 mar 2026
Windows DWM Core Library Elevation of Privilege Vulnerability
71RISCO
abrir
GitHub PoC
If you've been grinding through HackTheBox machines, Mailing is one of those boxes that genuinely teaches you something. It's rated Easy, runs on Windows, and chains together a few real-world vulnerabilities — a directory traversal, a credential leak, CVE-2024-21413, and a LibreOffice macro exploit. Let's walk through it step by step.
CVE-2024-21413CRITICALsob ataque25 mar 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
PoC for CVE-2025-49596 on linux targets
CVE-2025-49596CRITICAL25 mar 2026
MCP Inspector proxy server lacks authentication between the Inspector client and proxy
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-49596CRITICAL25 mar 2026
MCP Inspector proxy server lacks authentication between the Inspector client and proxy
75RISCO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALsob ataque25 mar 2026
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
VulnCheck XDB
local
CVE-2024-51324LOW25 mar 2026
An issue in the BdApiUtil driver of Baidu Antivirus v5.2.3.116083 allows attackers to terminate arbitrary process via ex
28RISCO
abrir
GitHub PoC5
WinRAR < 7.13 path traversal for persistency
CVE-2025-8088HIGHsob ataqueransomware25 mar 2026
Path traversal vulnerability in WinRAR
93RISCO
abrir
GitHub PoC
NeoArtemis37/OverlayFS-PrivEsc-CVE-2022-0944
CVE-2022-0944CRITICAL25 mar 2026
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISCO
abrir
GitHub PoC
pream-totaram/CVE-2024-52302-reproduction
CVE-2024-52302HIGH25 mar 2026
common-user-management Unrestricted File Upload Leading to Remote Code Execution (RCE)
41RISCO
abrir
GitHub PoC
Intentionally vulnerable Next.js RSC Docker lab for CVE-2025-55182 (React2Shell) local testing
CVE-2025-55182CRITICALsob ataqueransomware25 mar 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
CVE write-up for Active Directory credential exposure vulnerability in Suprema BioStar 2
CVE-2026-31278HIGH25 mar 2026
An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0
41RISCO
abrir
GitHub PoC
Technical investigation and host containment of a Critical-severity Zero-Click RCE exploit (CVE-2025-21298) using EDR telemetry and static malware analysis.
CVE-2025-21298CRITICAL24 mar 2026
Windows OLE Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC1
Camera Dahua Research lỗ hổng CVE-2021-33044
CVE-2021-33044CRITICALsob ataque24 mar 2026
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-4220HIGH24 mar 2026
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir
GitHub PoC
RandyNin/CVE-2023-4220
CVE-2023-4220HIGH24 mar 2026
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISCO
abrir
GitHub PoC
CVE-2025-55182 — React2Shell
CVE-2025-55182CRITICALsob ataqueransomware24 mar 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Investigating CVE-2022-36804
CVE-2022-36804HIGHsob ataque24 mar 2026
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL24 mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
GitHub PoC1
Exploit to MCPJam Inspector <=1.4.2
CVE-2026-23744CRITICAL24 mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
VulnCheck XDB
local
CVE-2023-32784HIGH24 mar 2026
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a work
41RISCO
abrir
GitHub PoC
Khai thác lỗ hổng bảo mật CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware24 mar 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware24 mar 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
info-leak
CVE-2021-33044CRITICALsob ataque24 mar 2026
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISCO
abrir
GitHub PoC
CVE-2026-32794: TLS Certificate Verification Bypass in Apache Airflow Databricks Provider
CVE-2026-32794MEDIUM24 mar 2026
Apache Airflow Provider for Databricks: TLS Certificate Verification Disabled in Databricks Provider K8s Token Exchange
13RISCO
abrir
GitHub PoC
CVE-2018-7422
CVE-2018-742223 mar 2026
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RISCO
abrir
VulnCheck XDB
info-leak
CVE-2018-742223 mar 2026
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RISCO
abrir
VulnCheck XDB
info-leak
CVE-2024-2473MEDIUM23 mar 2026
WPS Hide Login <= 1.9.15.2 - Login Page Disclosure
48RISCO
abrir
Metasploit300
Citrix ADC (NetScaler) CVE-2026-3055 Scanner
CVE-2026-3055CRITICALsob ataque23 mar 2026
Insufficient input validation leading to memory overread
95RISCO
abrir
GitHub PoC
Research-driven UPnP vulnerability scanner focusing on libupnp 1.6.19 and CVE-2012-5958.
CVE-2012-595823 mar 2026
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
60RISCO
abrir
anteriorpágina 172 / 2.681próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.