Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.095exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.442GitHub PoC 15.312VulnCheck XDB 8.970Nuclei 4.393Metasploit 3.502✓ só verificadosrecentespopularesrisco
80.095 exploits
GitHub PoC★ 21
TheCyberGeek/CVE-2026-4480-PoC
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RISCO
abrir ↗GitHub PoC
t1ckprivate/CVE-2026-31431-Copy-Fail
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir ↗VulnCheck XDB
initial-access
Everest Forms Pro <= 1.9.12 - Unauthenticated Remote Code Execution via Calculation Field
75RISCO
abrir ↗GitHub PoC
cve-2026-23744 python exploit
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir ↗VulnCheck XDB
initial-access
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RISCO
abrir ↗GitHub PoC
Exploit for Copy-Fail Vulnerability - Python3 Version
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir ↗GitHub PoC
This Python proof-of-concept targets a vulnerable MCP (Model Context Protocol) service exposed by the target application. The vulnerability allows an attacker to supply arbitrary server configuration parameters through the /api/mcp/connect endpoint.
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir ↗GitHub PoC
CVE-2026-23631-Draft
redis-server Lua use-after-free may allow remote code execution
33RISCO
abrir ↗VulnCheck XDB
info-leak
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive informatio
50RISCO
abrir ↗GitHub PoC★ 29
HTTP/2 Bomb PoC — CVE-2026-49975 (HPACK indexed reference bomb + flow-control stall)
Apache HTTP Server: mod_http2 denial of service
53RISCO
abrir ↗GitHub PoC★ 2
Proof of Concept (PoC) exploit for CVE-2026-6815: Authenticated Path Traversal & Arbitrary File Write in Casdoor (< 3.54.1) leading to RCE/DoS.
CVE-2026-6815
33RISCO
abrir ↗GitHub PoC
PoC CVE-2026-8732 (WP Maps Pro <= 6.1.0)
WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action
68RISCO
abrir ↗GitHub PoC
CVE-2026-35904 / CVE-2026-35905 / CVE-2026-35906 — Unauth RCE, Hardcoded Root Creds & Telnet Enable in T3 Technology CPE
Incorrect access control in the web management interface of T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, an
48RISCO
abrir ↗GitHub PoC★ 1
horrister/solarwinds-sunburst-cve-2020-10148
SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
100RISCO
abrir ↗GitHub PoC★ 1
Detect-only scanner for CVE-2026-42945 (NGINX Rift), a heap overflow in ngx_http_rewrite_module. Version detection + nginx.conf pattern analysis. Python 3 stdlib-only, no network calls.
NGINX ngx_http_rewrite_module vulnerability
60RISCO
abrir ↗GitHub PoC
Improved Metasploit module for CVE-2013-6117 (Dahua DVR authentication bypass)
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive informatio
50RISCO
abrir ↗GitHub PoC
CVE-2026-50142 — Heap allocation vulnerability in libheif HEIF sequence parser
libheif: unbounded heap allocation in HEIF sequence parser (stsz fixed-size mode missing bound check)
41RISCO
abrir ↗VulnCheck XDB
info-leak
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RISCO
abrir ↗GitHub PoC
CVE-2026-45247 - Draft
Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection
83RISCO
abrir ↗GitHub PoC
HTB Facts is a Easy Linux box featuring Camaleon CMS and MinIO. Gain admin access via open registration and a mass assignment vulnerability, then extract MinIO credentials from admin settings. Use CVE-2024-46987 path traversal to steal an SSH private key, crack its passphrase, and escalate to root by abusing sudo permissions on facter via GTFOBins.
Arbitrary path traversal in Camaleon CMS
61RISCO
abrir ↗GitHub PoC
rootdirective-sec/CVE-2026-34234-Lab
CtrlPanel: Unauthenticated RCE using installer script
48RISCO
abrir ↗GitHub PoC
Piotnet Forms Pro <= 2.1.40 - Unauthenticated Arbitrary File Upload → RCE
Piotnet Forms <= 2.1.40 - Unauthenticated Arbitrary File Upload via Form File Upload
48RISCO
abrir ↗GitHub PoC★ 13
Attack surface in the real-world environment of CVE-2026-41096
Windows DNS Client Remote Code Execution Vulnerability
48RISCO
abrir ↗GitHub PoC
CVE-2026-5076 — ARMember Premium <= 7.3.1 Insecure Password Reset Mechanism → Full Admin Account Takeover | Proof of Concept
ARMember Premium <= 7.3.1 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation
48RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.