Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.760exploits catalogados
32.083CVEs com exploração pública
1.932testados em laboratório
71.760 exploits
GitHub PoC
Morton-Li/copy-fail-CVE-2026-31431
CVE-2026-31431HIGHsob ataque08 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-4040CRITICALsob ataque08 mai 2026
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISCO
abrir
GitHub PoC
Exploiting Parsec for Windows to gain SYSTEM privileges
CVE-2026-54424HIGH08 mai 2026
An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Pri
41RISCO
abrir
GitHub PoC23
Detector + PoC for Linux page-cache write vulnerabilities: Copy Fail (CVE-2026-31431) and Dirty Frag (CVE-2026-43284/43500). Authorized security research only.
CVE-2026-31431HIGHsob ataque08 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC2
Vulnerability detection and mitigation tool for Copy Fail and Dirty Frag bugs (CVE-2026-31431, CVE-2026-43284, CVE-2026-43500)
CVE-2026-31431HIGHsob ataque08 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC
ameerhamza-malik/CVE-2026-42796
CVE-2026-42796CRITICAL08 mai 2026
Arelle < 2.39.10 Unauthenticated RCE via /rest/configure
28RISCO
abrir
GitHub PoC
Paranoid disable Linux IPsec ESP support (esp4/esp6) and RxRPC support.
CVE-2026-43284HIGH08 mai 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISCO
abrir
GitHub PoC
HiteshGorana/susvibes-jupyter-server-cve-2026-35397
CVE-2026-35397HIGH08 mai 2026
jupyter-server path traversal allows access to sibling directories sharing root_dir name prefix
21RISCO
abrir
GitHub PoC3
Wazuh 4.14.4 detection rules for CVE-2026-43284 / CVE-2026-43500 (Dirty Frag) - Linux Local Privilege Escalation via page cache write
CVE-2026-43284HIGH08 mai 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISCO
abrir
GitHub PoC
Full exploit chain lab and Suricata IDS detection for CVE-2022-30190 (Follina) - MSDT RCE
CVE-2022-30190HIGHsob ataqueransomware08 mai 2026
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
Sidjaz/CrushFTP-CVE-2024-4040-Proof-of-Concept
CVE-2024-4040CRITICALsob ataque08 mai 2026
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISCO
abrir
Exploit-DB
ThingsBoard IoT Platform 4.2.0 - Server-Side Request Forgery (SSRF)
CVE-2025-34282MEDIUM07 mai 2026
ThingsBoard < v4.2.1 SVG Image SSRF
33RISCO
abrir
GitHub PoC
CVE-2026-44590 - Sherlock <= v0.16.0 - RCE via pull_request_target Injection → Supply Chain Compromise
CVE-2026-44590CRITICAL07 mai 2026
Sherlock: Command Injection via pull_request_target in validate_modified_targets.yml
28RISCO
abrir
Exploit-DB
telnetd 2.7 - Buffer Overflow
CVE-2026-32746CRITICAL07 mai 2026
telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption
53RISCO
abrir
Exploit-DB
Bludit CMS 3.18.4 - RCE
CVE-2026-25099HIGH07 mai 2026
Remote Code Execution via Unrestricted File Upload in Bludit
41RISCO
abrir
GitHub PoC2
Math.js Expression Parser RCE
CVE-2026-40897HIGH07 mai 2026
Math.js: Unsafe object property setter in mathjs
41RISCO
abrir
GitHub PoC1
FlowiseAI CVE-2025-58434 & CVE-2025-59528 exploit PoC, demonstrating unauthenticated ATO via reset token leakage, followed by authenticated RCE. Includes a reproductible Docker lab environment.
CVE-2025-58434CRITICAL07 mai 2026
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
75RISCO
abrir
GitHub PoC
CVE-2025-6440
CVE-2025-6440CRITICAL07 mai 2026
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISCO
abrir
GitHub PoC2
Advisory: CVE-2026-38360 path traversal (CWE-22) in dash-uploader (Python/PyPI)
CVE-2026-38360CRITICAL07 mai 2026
Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execut
43RISCO
abrir
GitHub PoC
Vulnerability Research and Exploit for CVE-2019-10149
CVE-2019-10149CRITICALsob ataque07 mai 2026
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISCO
abrir
GitHub PoC
Advisory: CVE-2026-38361 multiple DoS vulnerabilities (CWE-400/CWE-670) in dash-uploader (Python/PyPI)
CVE-2026-38361HIGH07 mai 2026
Multiple unauthenticated denial-of-service (DoS) issues in fohrloop dash-uploader v0.1.0 through v0.7.0a2. The chunked-u
36RISCO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHsob ataque07 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC1
HTB Snapped — Hard Linux machine writeup. CVE-2026-27944 (Nginx UI unauthenticated backup disclosure) chained with CVE-2026-3888 (snapd race condition LPE) to achieve full system compromise.
CVE-2026-27944CRITICAL07 mai 2026
Nginx UI: Unauthenticated Backup Download with Encryption Key Disclosure
68RISCO
abrir
GitHub PoC
Caliburn9/CVE-2023-21716-Analysis-ICT287
CVE-2023-21716CRITICAL07 mai 2026
Microsoft Word Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC
Discovery and original disclosure of CVE-2026-31431: Theori / Xint. Public writeup: https://copy.fail/.
CVE-2026-31431HIGHsob ataque07 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
VulnCheck XDB
info-leak
CVE-2026-7482HIGH07 mai 2026
Ollama heap out-of-bounds read in GGUF tensor parsing leaks server process memory to unauthenticated remote attackers
21RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-59528CRITICAL07 mai 2026
Flowise has Remote Code Execution vulnerability
85RISCO
abrir
GitHub PoC
CVE-2026-31431 (Copy Fail) novel exploit: live code corruption via page cache. Overwrites libc exit() code through MAP_PRIVATE page sharing — affects ALL running processes.
CVE-2026-31431HIGHsob ataque07 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC1
Automatic script written in python for CVE-2009-3999
CVE-2009-399907 mai 2026
Stack-based buffer overflow in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to ex
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-6440CRITICAL07 mai 2026
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISCO
abrir
anteriorpágina 71 / 2.392próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.