Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
15.031 exploits
GitHub PoC
morzelowski/CVE-2026-12243-NLTK-PoC
CVE-2026-1224329 ago 2026
23RISCO
abrir
GitHub PoC
joaovicdev/EXPLOIT-CVE-2026-9198
CVE-2026-9198CRITICALsob ataque29 ago 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISCO
abrir
GitHub PoC
CVE-2026-65643 - Draft or TODO
CVE-2026-65643HIGH28 ago 2026
Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
41RISCO
abrir
GitHub PoC
IKEv1 VPN scanners, attempts a Check Point authentication-bypass exploit, and includes internal network scanning and reverse-shell features.
CVE-2026-50751CRITICALsob ataqueransomware28 ago 2026
User Authentication Bypass in VPN Remote Access and Mobile Access
100RISCO
abrir
GitHub PoC
Hari-v542/CVE-2026-52923
CVE-2026-52923HIGH28 ago 2026
ipc: limit next_id allocation to the valid ID range
41RISCO
abrir
GitHub PoC
A specialized Python framework that executes unauthenticated remote code execution via the 9Router Model Context Protocol (MCP) bridge by deploying a 33-layer temporal phase cascade, Riemann-Hadamard dispersion, and an 11 ns wedge filter to bypass traditional proxy and process-monitoring defenses.
CVE-2026-46339CRITICAL28 ago 2026
9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
63RISCO
abrir
GitHub PoC
fastjson-cve-2026-16723
CVE-2026-16723CRITICAL28 ago 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISCO
abrir
GitHub PoC
rmhowe425/POC-CVE-2026-19295
CVE-2026-19295CRITICAL28 ago 2026
Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement
48RISCO
abrir
GitHub PoC
I know you are probably here from Hack the Box, if so, yes this one actually works.
CVE-2025-55182CRITICALsob ataqueransomware28 ago 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC1
poc and yara rules
CVE-2025-59528CRITICAL28 ago 2026
Flowise has Remote Code Execution vulnerability
85RISCO
abrir
GitHub PoC
CVE-2026-33017 - Langflow Unauthenticated RCE Exploit
CVE-2026-33017CRITICALsob ataque28 ago 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir
GitHub PoC
Testing CVE-2026-70463 by Fyyre
CVE-2026-70463HIGH28 ago 2026
rsync 3.1.0 < 3.5.0 Authorization Bypass via auth users Directive Parsing
41RISCO
abrir
GitHub PoC
CVE-2026-33017 PoC Reverse Shell
CVE-2026-33017CRITICALsob ataque28 ago 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir
GitHub PoC
Cacti 1.2.22 unauthenticated command injection
CVE-2022-46169CRITICALsob ataque28 ago 2026
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC
Jenkins CVE-2024-23897 — CSRF-crumb aware PoC
CVE-2024-23897CRITICALsob ataqueransomware28 ago 2026
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
GitHub PoC
Wazuh Rules for Detection Zimbra (CVE-2026-73570).
CVE-2026-73570HIGHsob ataque28 ago 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
91RISCO
abrir
GitHub PoC
CVE-2026-66384 - Draft or TODO
CVE-2026-66384MEDIUMsob ataque28 ago 2026
Authenticated users may write data outside the intended Docker cache path
63RISCO
abrir
GitHub PoC
A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass
CVE-2026-24061CRITICALsob ataque28 ago 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC1
hideki233/CVE-2025-3248-Langflow-RCE
CVE-2025-3248CRITICALsob ataqueransomware28 ago 2026
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
GitHub PoC
CVE-2023-27350, CVE-2023-27351 - PaperCut - Draft or TODO
CVE-2023-27350CRITICALsob ataqueransomware28 ago 2026
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir
GitHub PoC
Writeup + CVE analysis + countermeasures for the Hacktivity 'Vulnerabilities, Exploits, and Remote Access Payloads' lab (netcat shells, Metasploit, CVE-2010-1240, CVE-2004-2687).
CVE-2010-124027 ago 2026
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RISCO
abrir
GitHub PoC
CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, CVE-2026-20313
CVE-2026-20303CRITICAL27 ago 2026
Cisco Catalyst SD-WAN Security Hardening Release - Input Validation Vulnerabilities
48RISCO
abrir
GitHub PoC
For educational purposes
CVE-2026-65351MEDIUM27 ago 2026
This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS
33RISCO
abrir
GitHub PoC
CVE-2015-5287
CVE-2015-5287HIGHsob ataque27 ago 2026
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain perm
86RISCO
abrir
GitHub PoC
A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.
CVE-2026-55040CRITICALsob ataque27 ago 2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISCO
abrir
GitHub PoC
CVE-2015-3246
CVE-2015-3246MEDIUMsob ataque27 ago 2026
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly mod
78RISCO
abrir
GitHub PoC1
A Python-based exploitation framework for CVE-2026-75604 that enables authorized penetration testers to validate Next.js Windows cache traversal vulnerabilities. Deploys reverse shells and webshells via path traversal, with built-in target verification and proxy support for seamless integration into standard pentest workflows.
CVE-2026-75604CRITICAL27 ago 2026
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
48RISCO
abrir
GitHub PoC
Minimal reproduction for Spring AI ParagraphManager sibling self-loop OOM (incomplete fix of CVE-2026-47851)
CVE-2026-47851HIGH27 ago 2026
Unbounded recursion over attacker-controlled PDF outline tree in Spring AI PDF Document Reader
41RISCO
abrir
GitHub PoC19
Metabase SQLi
CVE-2026-72898CRITICALsob ataque27 ago 2026
Metabase SQL injection via password reset endpoint
100RISCO
abrir
GitHub PoC1
CVE-2026-18431 - Draft or TODO
CVE-2026-18431CRITICAL27 ago 2026
Avada <= 7.16 and Fusion Builder <= 3.16 - Unauthenticated Remote Code Execution via Arbitrary File Write
48RISCO
abrir

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.