Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
15.250 exploits
GitHub PoC
CVE-2026-7270 FreeBSD local privilege escalation via exec_args_adjust_args OOB memmove
CVE-2026-7270HIGH09 mai 2026
Local privilege escalation via execve()
21RISCO
abrir
GitHub PoC1
This repository provides a reproduction environment for CVE-2026-44656.
CVE-2026-44656MEDIUM09 mai 2026
Vim: OS Command Injection via 'path' completion
13RISCO
abrir
GitHub PoC
PoC and advisory for CVE-2026-44648
CVE-2026-44648HIGH08 mai 2026
SillyTavern: Existing sessions are not invalidated after password change, allowing session reuse and account takeover
41RISCO
abrir
GitHub PoC
Xmyronn/CVE-2026-10243-AUTH
CVE-2026-10243MEDIUM08 mai 2026
code-projects Smart Parking System Admin Endpoint missing authentication
33RISCO
abrir
GitHub PoC
Kernel LPE PoC & Mitigation Toolkit - ROSN-LR5-Full (CVE-2026-31431)
CVE-2026-31431HIGHsob ataque08 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC
HiteshGorana/susvibes-jupyter-server-cve-2026-35397
CVE-2026-35397HIGH08 mai 2026
jupyter-server path traversal allows access to sibling directories sharing root_dir name prefix
21RISCO
abrir
GitHub PoC
branixsolutions/Security-CVE-2026-41940-cPanel-WHM-WP2
CVE-2026-41940CRITICALsob ataqueransomware08 mai 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC
Paranoid disable Linux IPsec ESP support (esp4/esp6) and RxRPC support.
CVE-2026-43284HIGH08 mai 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISCO
abrir
GitHub PoC
Sidjaz/CrushFTP-CVE-2024-4040-Proof-of-Concept
CVE-2024-4040CRITICALsob ataque08 mai 2026
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISCO
abrir
GitHub PoC
Full exploit chain lab and Suricata IDS detection for CVE-2022-30190 (Follina) - MSDT RCE
CVE-2022-30190HIGHsob ataqueransomware08 mai 2026
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC1
Full-chain exploit for CVE-2025-2783 (Ipcz Sandbox Escape & RCE).
CVE-2025-2783HIGHsob ataque08 mai 2026
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
71RISCO
abrir
GitHub PoC1
CVE-2026-31431 in C for aarch64 and amd64
CVE-2026-31431HIGHsob ataque08 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC
Linux Kernel Local Privilege Escalation
CVE-2026-31431HIGHsob ataque08 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC
CVE-2025-58434 Proof of Concept
CVE-2025-58434CRITICAL08 mai 2026
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
75RISCO
abrir
GitHub PoC
A Rust honeypot that simulates a vulnerable cPanel/WHM instance for CVE-2026-41940
CVE-2026-41940CRITICALsob ataqueransomware08 mai 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC
CVE-2026-31431 ("Copy Fail") vulnerability detector & exploit on Astra linux 1.7.6 with 3.7+ python
CVE-2026-31431HIGHsob ataque08 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC1
kyukazamiqq/cve-2026-5718
CVE-2026-5718HIGH08 mai 2026
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Unauthenticated Arbitrary File Upload via Non-ASCII Filename Blacklist Bypass
56RISCO
abrir
GitHub PoC
Exploiting Parsec for Windows to gain SYSTEM privileges
CVE-2026-54424HIGH08 mai 2026
An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Pri
41RISCO
abrir
GitHub PoC
EspoCRM 9.3.3 - Authenticated SSRF via Alternative IPv4 Notation
CVE-2026-33534MEDIUM08 mai 2026
EspoCRM has authenticated SSRF via internal-host validation bypass using alternative IPv4 notation
48RISCO
abrir
GitHub PoC
Desc "Fix Redis CVE ultil 20260508-10h51 GMT+7"
CVE-2026-25589HIGH08 mai 2026
RedisBloom RESTORE invalid memory access may allow remote code execution
21RISCO
abrir
GitHub PoC18
A proof-of-concept demonstrating how a default, unprivileged Kubernetes Pod can achieve node-level code execution on Amazon EKS by exploiting the Dirty Frag (CVE-2026-43284) Linux kernel page-cache corruption vulnerability through shared container image layers.
CVE-2026-43284HIGH08 mai 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISCO
abrir
GitHub PoC
A fully refactored, Python 3 compatible exploit script for Tomcat Ghostcat (CVE-2020-1938 / CNVD-2020-10487) AJP Local File Inclusion
CVE-2020-1938CRITICALsob ataque08 mai 2026
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
GitHub PoC
Morton-Li/copy-fail-CVE-2026-31431
CVE-2026-31431HIGHsob ataque08 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC6
Simple Ansible Playbook to mitigate against CopyFail (CVE-2026-31431) and DirtyFrag (CVE-2026-43284) vulnerabilities.
CVE-2026-31431HIGHsob ataque08 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC
rootdirective-sec/CVE-2026-34197-Lab
CVE-2026-34197HIGHsob ataque08 mai 2026
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
100RISCO
abrir
GitHub PoC
CTT-Enhanced Apache mod_auth_digest Timing Attack — CVE-2026-33006 Remote Digest Authentication Bypass → 33-Layer Temporal Timing Attack Original vulnerability: Apache HTTP Server 2.4.66 (mod_auth_digest timing leak) CTVSS (Original): 4.8 (Medium) CTT-Enhanced CVSS: 7.5 (High) — Network, low complexity, temporal wedge evasion
CVE-2026-33006MEDIUM08 mai 2026
Apache HTTP Server: mod_auth_digest timing attack
13RISCO
abrir
GitHub PoC3
Wazuh 4.14.4 detection rules for CVE-2026-43284 / CVE-2026-43500 (Dirty Frag) - Linux Local Privilege Escalation via page cache write
CVE-2026-43284HIGH08 mai 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISCO
abrir
GitHub PoC19
CVE-2026-43284
CVE-2026-43284HIGH08 mai 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISCO
abrir
GitHub PoC1
Remote Code Execution in Alexantr filemanager v1.0 via unrestricted file upload
CVE-2026-37637CRITICAL08 mai 2026
An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php compon
48RISCO
abrir
GitHub PoC23
Detector + PoC for Linux page-cache write vulnerabilities: Copy Fail (CVE-2026-31431) and Dirty Frag (CVE-2026-43284/43500). Authorized security research only.
CVE-2026-31431HIGHsob ataque08 mai 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
anteriorpágina 98 / 509próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.