Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8.883Nuclei 4.361Metasploit 3.493✓ só verificadosrecentespopularesrisco
14.946 exploits
GitHub PoC
CVE-2026-17544: PHP bcmath OOB write → universal memory-only RCE & disable_functions/open_basedir bypass. Offset-free runtime resolver. Verified on PHP 8.4.x / 8.5.x.
Out-of-bounds write in bccomp() via crafted operand and scale
41RISCO
abrir ↗GitHub PoC
An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in the Gitea instance.
Gitea Docker image trusts spoofable reverse-proxy headers by default
63RISCO
abrir ↗GitHub PoC
Username Enumeration via Authentication Timing Side-Channel in PaperCut NG
PaperCut NG/MF: User enumeration via timing attack
33RISCO
abrir ↗GitHub PoC
Alixploit22/CVE-2026-53587
libgit2 - Unauthenticated network-reachable heap out-of-bounds read in transports/smart_pkt.c:set_data
41RISCO
abrir ↗GitHub PoC
ghostpels/CVE-2026-13610
KiviCare < 4.5.2 - Unauthenticated Privilege Escalation via Registration
41RISCO
abrir ↗GitHub PoC★ 3
One-command Docker lab reproducing CVE-2026-71362 (Adobe Commerce / Magento Open Source customer-session identity-switch account takeover, APSB26-92, CVSS 9.1) with a PoC and an A/B/A official-patch negative control. For authorized security research and education.
Adobe Commerce | Incorrect Authorization (CWE-863)
68RISCO
abrir ↗GitHub PoC
Responsible disclosure write-ups for CVE-2026-8793 - PaperCut NG 25.0.11
PaperCut NG/MF: Insufficient brute-force protection
33RISCO
abrir ↗GitHub PoC
Python StateMachine 3.0.0 < 3.2.0 RCE via unsafe SCXML <data expr> evaluation and Python eval() injection.
Python StateMachine 3.0.0 < 3.2.0 RCE via SCXML eval() Injection
48RISCO
abrir ↗GitHub PoC★ 1
This repository contains a conceptual patch demonstrating the mitigation for CVE-2026-68820, a critical Use-After-Free (UAF) vulnerability in the Windows Ancillary Function Driver for WinSock (`afd.sys`).
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
71RISCO
abrir ↗GitHub PoC
CVE-2026-54433 Roundcube plain-text email stored XSS PoC
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plai
41RISCO
abrir ↗GitHub PoC
CVE-2026-72550 — Friendica Unauthenticated Stacked-Query SQL Injection PoC (CVSS 9.8 Critical)
Friendica Friendica - SQL Injection
48RISCO
abrir ↗GitHub PoC
CVE-2021-41773 Exploit Lab
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗GitHub PoC
CS50's Introduction to Cybersecurity final project on React2Shell (CVE-2025-55182)
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗GitHub PoC★ 60
CVE-2026-8452 PreAuth RCE
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
71RISCO
abrir ↗GitHub PoC
Mohaimenul370/Perform-an-RDP-exploitation-using-the-BlueKeep-vulnerability-CVE-2019-0708-on-Windows
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir ↗GitHub PoC
jeffmarlonmandela/CVE-2021-4034-PwnKit
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir ↗GitHub PoC
PoC funcional de CVE-2026-52715 (GeoLeak): SQLi no autenticada en GEO my WordPress <= 4.5.5 via swlatlng/nelatlng. Laboratorio Docker + exploit time-based/boolean-based + exfiltracion sin comas en payload.
WordPress GEO my WordPress plugin <= 4.5.5 - SQL Injection vulnerability
48RISCO
abrir ↗GitHub PoC★ 5
KSuRoot 2.2.0 — One-click KernelSU rooting based on CVE-2026-43499. Synced from Root-My-Galaxy v0.2.6 with custom payload (.so) import. Mod by hmascs
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir ↗GitHub PoC
Kentox493/CVE-2026-46300_Fragnesia
net: skbuff: preserve shared-frag marker during coalescing
56RISCO
abrir ↗GitHub PoC★ 1
This package is not a complete root. It flips SELinux to Permissive and holds reclaim long enough for follow-on work. Host `uid=0` is not achieved here.
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir ↗GitHub PoC
KovachVL/CVE-2026-54356
Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`
41RISCO
abrir ↗GitHub PoC
josephfarah-ciso/CVE-2026-9999-exploit
Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execu
41RISCO
abrir ↗GitHub PoC
sonalisarkar-2003/FTP-vsFTPD-CVE-2011-2523-VAPT-Report
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir ↗GitHub PoC
CVE-2026-72898 - Metabase
Metabase SQL injection via password reset endpoint
100RISCO
abrir ↗GitHub PoC
Docker-based lab for reproducing CVE-2021-41773 (Apache HTTP Server 2.4.49) through controlled path traversal and file disclosure using a custom Python PoC.
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗GitHub PoC
The poc of CVE-2026-33017
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir ↗GitHub PoC★ 24
CVE-2026-66804 Windows Cross Device virtual camera EoP - Standard user to SYSTEM
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
41RISCO
abrir ↗GitHub PoC★ 1
CVE-2026-68820 - Draft or TODO
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
71RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.