Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.557exploits catalogados
37.313CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.478Referência 23.776GitHub PoC 15.367VulnCheck XDB 9.019Nuclei 4.415Metasploit 3.502✓ só verificadosrecentespopularesrisco
80.557 exploits
VulnCheck XDB
initial-access
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir ↗VulnCheck XDB
initial-access
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir ↗GitHub PoC
CVE-2026-2395: Tar race file collision
SQLi in Xpoda Türkiye Informatics Technology's No Code Platform
48RISCO
abrir ↗VulnCheck XDB
initial-access
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir ↗GitHub PoC
Self-contained exploit for CVE-2021-4034 - Pkexec Local Privilege Escalation
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir ↗GitHub PoC★ 208
Exploitation of CVE-2026-24061
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir ↗GitHub PoC★ 8
CVE-2026-24061 - Exploit
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir ↗GitHub PoC★ 12
Chocapikk/CVE-2026-24061
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir ↗GitHub PoC★ 10
CVE-2026-24061 Batch Scanning Tool
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir ↗GitHub PoC★ 1
Unauthenticated 0-click RCE exploit for CVE-2024-51793. Exploits an arbitrary file upload vulnerability via admin-ajax.php to upload a PHP payload and achieve remote command execution on vulnerable WordPress installations, including OS detection and an interactive command shell.
WordPress RepairBuddy plugin <= 3.8115 - Arbitrary File Upload vulnerability
48RISCO
abrir ↗GitHub PoC★ 67
JayGLXR/CVE-2026-24061-POC
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir ↗GitHub PoC★ 2
CVE-2025-55182
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗VulnCheck XDB
initial-access
LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter
48RISCO
abrir ↗GitHub PoC★ 2
Unauthenticated 0-click RCE exploit for CVE-2024-9932. Exploits an arbitrary file upload vulnerability in the Wux Blog Editor WordPress plugin to upload a remote PHP payload, detect the target operating system, and achieve remote command execution through an interactive web shell.
Wux Blog Editor <= 3.0.0 - Unauthenticated Arbitrary File Upload
60RISCO
abrir ↗GitHub PoC
Dirty Cow exploit - CVE-2016-5195
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir ↗GitHub PoC
SMBv1: CVE-2017-0143, gravedad 8.8, de ejecucion remota de codigo (RCE), en Windows con SMBv1 (ms17-010)
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir ↗GitHub PoC
nimesh895/Malware-Analysis-Follina-CVE-2022-30190
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir ↗VulnCheck XDB
initial-access
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISCO
abrir ↗GitHub PoC
CybersRMUTL/CVE-2019-9193-Postgresql-RCE
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISCO
abrir ↗GitHub PoC
abanop22333/Apache-Authentication-Flaw-Research-CVE-2024-38476-
Apache HTTP Server may use exploitable/malicious backend application output to run local handlers via internal redirect
60RISCO
abrir ↗GitHub PoC★ 3
海康威视RCE漏洞 批量检测和利用工具
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISCO
abrir ↗GitHub PoC★ 1
CVE-2017-7921, CVE-2021-36260 updated 21/01/2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISCO
abrir ↗GitHub PoC
afifudinmtop/CVE-2021-21425
Unauthenticated Arbitrary YAML Write/Update leads to Code Execution
85RISCO
abrir ↗VulnCheck XDB
local
The wsftprm.sys kernel driver 2.0.0.0 in Topaz Antifraud allows low-privileged attackers to kill any (Protected Process
33RISCO
abrir ↗GitHub PoC★ 1
CVE-2017-7921, CVE-2021-36260 updated 21/01/2026
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISCO
abrir ↗GitHub PoC
CybersRMUTL/CVE-2019-10149-Exim4-RCE
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISCO
abrir ↗GitHub PoC
React Router's createFileSessionStorage() in certain versions allows unsigned cookies to be manipulated, enabling file system access outside the session directory.
React Router has Path Traversal in File Session Storage
53RISCO
abrir ↗VulnCheck XDB
initial-access
Apache bRPC: Remote command injection vulnerability in heap builtin service
53RISCO
abrir ↗VulnCheck XDB
initial-access
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.