Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.557exploits catalogados
37.313CVEs com exploração pública
24.695testados em laboratório
80.557 exploits
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALsob ataque22 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALsob ataque22 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
CVE-2026-2395: Tar race file collision
CVE-2026-2395CRITICAL22 jan 2026
SQLi in Xpoda Türkiye Informatics Technology's No Code Platform
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALsob ataque22 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
Self-contained exploit for CVE-2021-4034 - Pkexec Local Privilege Escalation
CVE-2021-4034HIGHsob ataqueransomware22 jan 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC208
Exploitation of CVE-2026-24061
CVE-2026-24061CRITICALsob ataque22 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC8
CVE-2026-24061 - Exploit
CVE-2026-24061CRITICALsob ataque22 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC12
Chocapikk/CVE-2026-24061
CVE-2026-24061CRITICALsob ataque22 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC10
CVE-2026-24061 Batch Scanning Tool
CVE-2026-24061CRITICALsob ataque22 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC1
Unauthenticated 0-click RCE exploit for CVE-2024-51793. Exploits an arbitrary file upload vulnerability via admin-ajax.php to upload a PHP payload and achieve remote command execution on vulnerable WordPress installations, including OS detection and an interactive command shell.
CVE-2024-51793CRITICAL22 jan 2026
WordPress RepairBuddy plugin <= 3.8115 - Arbitrary File Upload vulnerability
48RISCO
abrir
GitHub PoC67
JayGLXR/CVE-2026-24061-POC
CVE-2026-24061CRITICALsob ataque22 jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC2
CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware22 jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-0920CRITICAL22 jan 2026
LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter
48RISCO
abrir
GitHub PoC2
Unauthenticated 0-click RCE exploit for CVE-2024-9932. Exploits an arbitrary file upload vulnerability in the Wux Blog Editor WordPress plugin to upload a remote PHP payload, detect the target operating system, and achieve remote command execution through an interactive web shell.
CVE-2024-9932CRITICAL22 jan 2026
Wux Blog Editor <= 3.0.0 - Unauthenticated Arbitrary File Upload
60RISCO
abrir
GitHub PoC
Dirty Cow exploit - CVE-2016-5195
CVE-2016-5195HIGHsob ataque22 jan 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC
SMBv1: CVE-2017-0143, gravedad 8.8, de ejecucion remota de codigo (RCE), en Windows con SMBv1 (ms17-010)
CVE-2017-0143HIGHsob ataqueransomware21 jan 2026
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
GitHub PoC
nimesh895/Malware-Analysis-Follina-CVE-2022-30190
CVE-2022-30190HIGHsob ataqueransomware21 jan 2026
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-10149CRITICALsob ataque21 jan 2026
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISCO
abrir
GitHub PoC
CybersRMUTL/CVE-2019-9193-Postgresql-RCE
CVE-2019-919321 jan 2026
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISCO
abrir
GitHub PoC
abanop22333/Apache-Authentication-Flaw-Research-CVE-2024-38476-
CVE-2024-38476CRITICAL21 jan 2026
Apache HTTP Server may use exploitable/malicious backend application output to run local handlers via internal redirect
60RISCO
abrir
GitHub PoC3
海康威视RCE漏洞 批量检测和利用工具
CVE-2021-36260CRITICALsob ataque21 jan 2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISCO
abrir
GitHub PoC1
CVE-2017-7921, CVE-2021-36260 updated 21/01/2026
CVE-2021-36260CRITICALsob ataque21 jan 2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISCO
abrir
GitHub PoC
afifudinmtop/CVE-2021-21425
CVE-2021-21425CRITICAL21 jan 2026
Unauthenticated Arbitrary YAML Write/Update leads to Code Execution
85RISCO
abrir
VulnCheck XDB
local
CVE-2023-52271MEDIUM21 jan 2026
The wsftprm.sys kernel driver 2.0.0.0 in Topaz Antifraud allows low-privileged attackers to kill any (Protected Process
33RISCO
abrir
GitHub PoC1
CVE-2017-7921, CVE-2021-36260 updated 21/01/2026
CVE-2017-7921CRITICALsob ataque21 jan 2026
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISCO
abrir
GitHub PoC
CybersRMUTL/CVE-2019-10149-Exim4-RCE
CVE-2019-10149CRITICALsob ataque21 jan 2026
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISCO
abrir
GitHub PoC
React Router's createFileSessionStorage() in certain versions allows unsigned cookies to be manipulated, enabling file system access outside the session directory.
CVE-2025-61686CRITICAL21 jan 2026
React Router has Path Traversal in File Session Storage
53RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-60021CRITICAL21 jan 2026
Apache bRPC: Remote command injection vulnerability in heap builtin service
53RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALsob ataque21 jan 2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-919321 jan 2026
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISCO
abrir
anteriorpágina 202 / 2.686próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.