Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
80.095exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.442GitHub PoC 15.312VulnCheck XDB 8.970Nuclei 4.393Metasploit 3.502✓ só verificadosrecentespopularesrisco
80.095 exploits
GitHub PoC★ 1
horrister/log4shell-cve-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗GitHub PoC★ 2
Proof of Concept (PoC) exploit for CVE-2026-6815: Authenticated Path Traversal & Arbitrary File Write in Casdoor (< 3.54.1) leading to RCE/DoS.
CVE-2026-6815
33RISCO
abrir ↗GitHub PoC★ 10
strivepan/ActiveMQ-cve-2026-42588-scanner-gui
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnector
41RISCO
abrir ↗GitHub PoC
Dhananjayasj/CVE-2024-1698-NotificationX-WordPress-Plugin-SQL-Injection-to-Admin-Credential-Extraction
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RISCO
abrir ↗GitHub PoC
CVE-2026-45247 - Draft
Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection
83RISCO
abrir ↗GitHub PoC
CVE-2026-23631-Draft
redis-server Lua use-after-free may allow remote code execution
33RISCO
abrir ↗GitHub PoC
CVE-2026-35904 / CVE-2026-35905 / CVE-2026-35906 — Unauth RCE, Hardcoded Root Creds & Telnet Enable in T3 Technology CPE
Incorrect access control in the web management interface of T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, an
48RISCO
abrir ↗GitHub PoC
PoC of CVE-2026-49943
CZ.NIC BIRD Internet Routing Daemon through 2.19.0 contains a stack-based buffer overflow in the BGP AS_PATH mask matchi
33RISCO
abrir ↗GitHub PoC
Detection script for CIFSwitch - CVE-2026-46243
smb: client: reject userspace cifs.spnego descriptions
41RISCO
abrir ↗GitHub PoC★ 13
CVE-2026-41089 checker: unauthenticated, non-destructive detection for the Netlogon CLDAP stack buffer overflow (CVSS 9.8). Reports whether a domain controller's domain is long enough to crash, without sending the overflow. The binary-verified analysis the public PoCs got wrong.
Windows Netlogon Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC★ 2
Shcesama/cve-2023-4863-analysis
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RISCO
abrir ↗GitHub PoC
这是一个用于防御巡检的 CVE-2026-41089 检测脚本。该漏洞是 Microsoft 在 2026 年 5 月安全更新中披露的 Windows Netlogon 远程代码执行漏洞。
Windows Netlogon Remote Code Execution Vulnerability
70RISCO
abrir ↗GitHub PoC★ 1
Add go CVE-2026-46300 (Fragnesia) local privilege escalation exploit
net: skbuff: preserve shared-frag marker during coalescing
56RISCO
abrir ↗VulnCheck XDB
initial-access
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir ↗GitHub PoC
DanieleGiovanardi2408/cve-2024-36401-geoserver-rce
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISCO
abrir ↗GitHub PoC★ 3
Palo Alto Networks PAN-OS contains an authentication bypass caused by flaws in the GlobalProtect portal and gateway, letting attackers establish unauthorized VPN connections, exploit requires network access to the portal or gateway.
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
100RISCO
abrir ↗VulnCheck XDB
local
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
78RISCO
abrir ↗GitHub PoC★ 1
Rocket.Chat OAuth2 NoSQL Injection
In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability c
48RISCO
abrir ↗GitHub PoC
Galaxy-sc/CVE-2026-47423-dompurify-xss-detector
DOMPurify XSS via `selectedcontent` re-clone
41RISCO
abrir ↗GitHub PoC★ 1
Real-World Simulation: FTP Service Exploitation (ProFTPD CVE-2015-3306)
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISCO
abrir ↗GitHub PoC★ 1
Saku0512/CVE-2026-54088-poc
File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)
48RISCO
abrir ↗GitHub PoC★ 6
PoC de CVE-2026-49975 (HTTP/2 Bomb): DoS remoto contra servidores web con HTTP/2 por defecto.
Apache HTTP Server: mod_http2 denial of service
53RISCO
abrir ↗GitHub PoC★ 1
CVE-2025-48595 - Draft
In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to
71RISCO
abrir ↗GitHub PoC
leehunkoo/hk_CVE-2025-32433
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.