Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.557exploits catalogados
37.313CVEs com exploração pública
24.695testados em laboratório
80.557 exploits
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALsob ataque26 jan 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2009-310326 jan 2026
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RISCO
abrir
GitHub PoC
Vulnerability in GNU InetUtils telnetd Enables Remote Root Access
CVE-2026-24061CRITICALsob ataque26 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
CVE-2026-24061-Scanner by XsanLahci
CVE-2026-24061CRITICALsob ataque26 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC1
A Proof of Concept for CVE-2025-29927 demonstrating a middleware bypass in Next.js versions prior to 13.5.9
CVE-2025-29927CRITICAL26 jan 2026
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC17
CVE-2026-24061 GNU Inetutils telnetd 身份验证绕过漏洞检测与利用 GUI 工具
CVE-2026-24061CRITICALsob ataque26 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
Metasploit500
GNU Inetutils Telnet Authentication Bypass Exploit CVE-2026-24061
CVE-2026-24061CRITICALsob ataque26 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
🔍 Analyze WebKit and ANGLE vulnerabilities with this repository for CVE-2025-43529 and CVE-2025-14174, focusing on verified components and ongoing efforts.
CVE-2025-43529HIGHsob ataque26 jan 2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
71RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-24061CRITICALsob ataque26 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
Metasploit500
HUSTOJ Admin users can zip-slip problem_import_qduoj.php, planting PHP files in webroot for RCE
CVE-2026-24479CRITICAL26 jan 2026
HUSTOJ has Arbitrary File Write (Zip Slip) in Problem Import Modules that leads to RCE
63RISCO
abrir
GitHub PoC
Spring Cloud Gateway SpEL RCE Vulnerability Environment
CVE-2025-41243CRITICAL26 jan 2026
Spring Expression Language property modification using Spring Cloud Gateway Server WebFlux
63RISCO
abrir
GitHub PoC
afifudinmtop/CVE-2009-3103
CVE-2009-310326 jan 2026
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RISCO
abrir
VulnCheck XDB
local
CVE-2023-3881726 jan 2026
An issue in Inspect Element Ltd Echo.ac v.5.2.1.0 allows a local attacker to gain privileges via a crafted command to th
23RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-24061CRITICALsob ataque26 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-20045HIGHsob ataque25 jan 2026
Cisco Unified Communications Products Remote Code Execution Vulnerability
71RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-24061CRITICALsob ataque25 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-24061CRITICALsob ataque25 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALsob ataque25 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-0920CRITICAL25 jan 2026
LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2014-6287CRITICALsob ataque25 jan 2026
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-9978MEDIUMsob ataque25 jan 2026
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-60021CRITICAL25 jan 2026
Apache bRPC: Remote command injection vulnerability in heap builtin service
53RISCO
abrir
GitHub PoC
Baza-NATO/CVE-2021-33044
CVE-2021-33044CRITICALsob ataque25 jan 2026
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISCO
abrir
GitHub PoC
CVE-2026-21876 OWASP ModSecurity CRS WAF bypass (docker container + minimal PoC).
CVE-2026-21876CRITICAL25 jan 2026
OWASP CRS has multipart bypass using multiple content-type parts
53RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-33044CRITICALsob ataque25 jan 2026
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISCO
abrir
GitHub PoC1
CVE-2026-24061 PoC
CVE-2026-24061CRITICALsob ataque25 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
CVE-2026-24061
CVE-2026-24061CRITICALsob ataque25 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
GNU telnetd service from GNU InetUtils authentication-bypass
CVE-2026-24061CRITICALsob ataque25 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
Python demo simulating CVE-2024-3094: a supply chain backdoor in XZ Utils with a trigger-based stealth activation.
CVE-2024-3094CRITICAL25 jan 2026
Xz: malicious code in distributed source
70RISCO
abrir
VulnCheck XDB
local
CVE-2015-2291HIGHsob ataqueransomware25 jan 2026
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows all
71RISCO
abrir
anteriorpágina 199 / 2.686próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.