Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.409exploits catalogados
37.196CVEs com exploração pública
24.695testados em laboratório
80.409 exploits
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALsob ataque03 mar 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
CVE-2024-23897: Jenkins Arbitrary File Read Lead to RCE
CVE-2024-23897CRITICALsob ataqueransomware03 mar 2026
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
GitHub PoC1
Demonstrate a proof-of-concept exploit for CVE-2026-2441, a high-risk Chrome use-after-free vulnerability in the Blink CSS engine.
CVE-2026-2441HIGHsob ataque03 mar 2026
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside
76RISCO
abrir
GitHub PoC
CVE-2023-3452 exploit for WordPress Canto plugin RCE, HTTPS support included
CVE-2023-3452CRITICAL03 mar 2026
Canto <= 3.0.4 - Unauthenticated Remote File Inclusion
63RISCO
abrir
GitHub PoC
CVE-2025-68613 — n8n RCE via Expression Injection
CVE-2025-68613CRITICALsob ataque03 mar 2026
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISCO
abrir
VulnCheck XDB
info-leak
CVE-2024-23897CRITICALsob ataqueransomware03 mar 2026
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
Exploit-DB
mailcow 2025-01a - Host Header Password Reset Poisoning
CVE-2025-25198HIGHwebappsmultiple03 mar 2026
mailcow: dockerized vulnerable to password reset poisoning
41RISCO
abrir
Exploit-DB
WeGIA 3.5.0 - SQL Injection
CVE-2025-62360CRITICALwebappsphp03 mar 2026
WeGIA SQL Injection via 'id_dependente' param at endpoint `/html/funcionario/dependente_documento.php`
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-71257MEDIUM03 mar 2026
BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypass
60RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2024-2961HIGH03 mar 2026
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALsob ataque03 mar 2026
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
Exploit-DB
WordPress Backup Migration 1.3.7 - Remote Command Execution
CVE-2023-6553CRITICALwebappsmultiple03 mar 2026
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RISCO
abrir
GitHub PoC
CVE-2025-32463
CVE-2025-32463CRITICALsob ataque03 mar 2026
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir
GitHub PoC19
Dahua IP camera CVE research toolkit (CVE-2021-33044/33045, CVE-2025-31700/31701)
CVE-2021-33044CRITICALsob ataque03 mar 2026
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISCO
abrir
GitHub PoC1
Idk what to do here, ill edit soon, but its for the telnetd CVE-2026-24061
CVE-2026-24061CRITICALsob ataque03 mar 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataqueransomware02 mar 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
PoC of CVE-2021-4034 (PwnKit) for personal training purposes.
CVE-2021-4034HIGHsob ataqueransomware02 mar 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
Aryan20057/CVE-2023-4911
CVE-2023-4911HIGHsob ataque02 mar 2026
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISCO
abrir
Metasploit600
Ghost CMS Remote Code Execution
CVE-2026-22594HIGH02 mar 2026
Ghost has Staff 2FA bypass
36RISCO
abrir
Metasploit600
Ghost CMS Remote Code Execution
CVE-2026-29053HIGH02 mar 2026
Ghost Vulnerable to Remote Code Execution via Malicious Themes
56RISCO
abrir
VulnCheck XDB
local
CVE-2023-4911HIGHsob ataque02 mar 2026
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISCO
abrir
GitHub PoC11
gowonisgood/CVE-2025-62215-POC
CVE-2025-62215HIGHsob ataque02 mar 2026
Windows Kernel Elevation of Privilege Vulnerability
71RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2025-62215HIGHsob ataque02 mar 2026
Windows Kernel Elevation of Privilege Vulnerability
71RISCO
abrir
GitHub PoC1
CVE-2025-43529 Test
CVE-2025-43529HIGHsob ataque02 mar 2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
71RISCO
abrir
GitHub PoC
e1arth/CVE-2025-6018
CVE-2025-6018HIGH02 mar 2026
Pam-config: lpe from unprivileged to allow_active in pam
41RISCO
abrir
GitHub PoC
Metasploit module to exploit CVE-2024-46987 - an authenticated path traversal vulnerability in Camaleon CMS versions 2.8.0 through 2.8.2 and 2.9.0
CVE-2024-46987HIGH02 mar 2026
Arbitrary path traversal in Camaleon CMS
61RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-1357CRITICAL02 mar 2026
Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-3395MEDIUM02 mar 2026
MaxSite CMS MarkItUp Preview AJAX Endpoint preview-ajax.php eval code injection
48RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-58034MEDIUMsob ataque02 mar 2026
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vul
90RISCO
abrir
GitHub PoC
CVE-2025-5777
CVE-2025-5777CRITICALsob ataqueransomware02 mar 2026
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
anteriorpágina 181 / 2.681próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.