Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.697exploits catalogados
36.715CVEs com exploração pública
24.695testados em laboratório
79.697 exploits
Exploit-DB
EVerest 2025.9.0 - DoS
CVE-2025-68137HIGHdosmultiple02 set 2026
EVerest's Integer Overflow and Signed to Unsigned conversion lead to either stack buffer overflow or infinite loop
41RISCO
abrir
GitHub PoC1
Python exploit for the vsFTPd 2.3.4 backdoor (CVE-2011-2523).
CVE-2011-252302 set 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
GitHub PoC
rmhowe425/POC-CVE-2026-5027
CVE-2026-5027HIGH02 set 2026
Langflow - Path Traversal Arbitrary File Write via upload_user_file
68RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-0768CRITICAL02 set 2026
Langflow code Code Injection Remote Code Execution Vulnerability
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-82329CRITICALsob ataque02 set 2026
Potential authentication bypass leading to administrative access in Artifactory
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-39987CRITICALsob ataque02 set 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISCO
abrir
GitHub PoC5
CVE-2026-65330 PoC — setxattr PAC bypass via fixed #0x307a diversifier (iOS 26.6 / 23G71)
CVE-2026-65330MEDIUM02 set 2026
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe
33RISCO
abrir
GitHub PoC10
NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC
CVE-2026-19490CRITICAL02 set 2026
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
48RISCO
abrir
GitHub PoC
byt3l0rd/CVE-2026-73570
CVE-2026-73570HIGHsob ataque02 set 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RISCO
abrir
GitHub PoC
SAP-system-update/CVE-2026-58231
CVE-2026-58231CRITICAL02 set 2026
Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
48RISCO
abrir
GitHub PoC
CVE-2026-73296
CVE-2026-73296CRITICAL02 set 2026
Microsoft UFO: Unauthenticated Mobile MCP access allows remote Android device control and screen disclosure
48RISCO
abrir
GitHub PoC
tcollins-hashicorp/vault-cve-2026-5006-audit
CVE-2026-5006MEDIUM02 set 2026
Vault Vulnerable to Privilege Escalation via Slash Injection in Templated Policy Paths
33RISCO
abrir
GitHub PoC6
CVE-2026-82329 — JFrog Artifactory (self-hosted) Auth Bypass
CVE-2026-82329CRITICALsob ataque02 set 2026
Potential authentication bypass leading to administrative access in Artifactory
93RISCO
abrir
GitHub PoC1
CVE-2026-82329 — JFrog Artifactory unauthenticated authentication bypass ("phantom join key" -> forged service admin token)
CVE-2026-82329CRITICALsob ataque02 set 2026
Potential authentication bypass leading to administrative access in Artifactory
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-82329CRITICALsob ataque02 set 2026
Potential authentication bypass leading to administrative access in Artifactory
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-82329CRITICALsob ataque02 set 2026
Potential authentication bypass leading to administrative access in Artifactory
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-55591CRITICALsob ataqueransomware02 set 2026
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-5027HIGH02 set 2026
Langflow - Path Traversal Arbitrary File Write via upload_user_file
68RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-2907802 set 2026
The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[
50RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-14667CRITICALsob ataque02 set 2026
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-0920CRITICAL02 set 2026
LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-18963CRITICAL02 set 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISCO
abrir
GitHub PoC
CVE-2026-9586 - Draft or TODO
CVE-2026-9586CRITICALsob ataque02 set 2026
Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB
98RISCO
abrir
GitHub PoC
CVE-2026-38577
CVE-2026-38577CRITICAL02 set 2026
Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access.
48RISCO
abrir
GitHub PoC
CVE-2026-38577
CVE-2026-38577CRITICAL02 set 2026
Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access.
48RISCO
abrir
GitHub PoC
Saku0512/CVE-2026-84361-poc
CVE-2026-84361HIGH02 set 2026
Composer: Perforce source URL permits P4PORT `rsh:` command execution
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-24423CRITICALsob ataqueransomware02 set 2026
SmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub API
100RISCO
abrir
GitHub PoC
CVE-2026-9335: KerasFileEditor and load_weights follow h5py ExternalLinks, disclosing arbitrary local HDF5 file contents in keras ≤ 3.14.0. Advisory + verified PoCs.
CVE-2026-9335MEDIUM02 set 2026
Improper Handling of HDF5 ExternalLinks in keras-team/keras
33RISCO
abrir
GitHub PoC
Bypassing connect()-based syscall rules using TCP Fast Open (CVE-2026-63828/CVE-2026-72243 PoC)
CVE-2026-63828HIGH02 set 2026
apparmor: mediate the implicit connect of TCP fast open sendmsg
41RISCO
abrir
GitHub PoC
nabeelmkhan/CVE-2026-78839
CVE-2026-7883902 set 2026
An arbitrary file upload vulnerability in AppNitro MachForm v30 allows attackers to execute arbitrary code via uploading
23RISCO
abrir
anteriorpágina 5 / 2.657próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.