Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.781exploits catalogados
36.771CVEs com exploração pública
24.695testados em laboratório
79.305 exploits
GitHub PoC
aarch64 race condition checker
CVE-2026-46242HIGH20 ago 2026
eventpoll: fix ep_remove struct eventpoll / struct file UAF
41RISCO
abrir
GitHub PoC
Analyze and reproduce CVE-2025-55182.
CVE-2025-55182CRITICALsob ataqueransomware20 ago 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
CVE-2026-63030CRITICALsob ataque20 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC1
Safely detect Citrix NetScaler CVE-2026-8452
CVE-2026-8452HIGHsob ataque20 ago 2026
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
71RISCO
abrir
GitHub PoC38
Exploit for KeyCloak CVE-2026-18963
CVE-2026-18963CRITICAL20 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-19478CRITICAL20 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir
GitHub PoC15
Hunt for CVE-2026-18963 exploitation traces (Keycloak unauthenticated account takeover) in the Keycloak database
CVE-2026-18963CRITICAL20 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISCO
abrir
GitHub PoC
Deterministic memory-poisoning / prompt-injection measurement axis — CoSnitch (CVE-2026-24301) anchored. Inspect scorer, signed receipts. Measurement, not certification.
CVE-2026-24301HIGH20 ago 2026
Microsoft Copilot Information Disclosure Vulnerability
41RISCO
abrir
Metasploit600
SPIP X-Spip-Filtre Unauthenticated RCE
CVE-2026-77647CRITICAL20 ago 2026
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August
43RISCO
abrir
GitHub PoC1
Begitdj/cve-2019-2215-markw
CVE-2019-2215HIGHsob ataque19 ago 2026
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir
GitHub PoC
fastjson jsontype利用
CVE-2026-16723CRITICAL19 ago 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALsob ataque19 ago 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-39987CRITICALsob ataque19 ago 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISCO
abrir
VulnCheck XDB
local
CVE-2019-2215HIGHsob ataque19 ago 2026
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir
GitHub PoC
Oracle OID LDAP Server Privileges Management Exploit
CVE-2026-61241CRITICAL19 ago 2026
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Suppor
28RISCO
abrir
VulnCheck XDB
local
CVE-2019-2215HIGHsob ataque19 ago 2026
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-16723CRITICAL19 ago 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-34486HIGHsob ataque19 ago 2026
Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
100RISCO
abrir
GitHub PoC
Proof of Concept for CVE-2026-19598 affecting Pods <= 3.3.9.
CVE-2026-19598CRITICAL19 ago 2026
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALsob ataqueransomware19 ago 2026
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISCO
abrir
GitHub PoC1
renzi25031469/CVE-2026-19478
CVE-2026-19478CRITICAL19 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALsob ataqueransomware19 ago 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC
CVE-2026-18504, CVE-2026-16732 - Draft or TODO
CVE-2026-18504MEDIUM19 ago 2026
fastify vulnerable to schema validation bypass via root primitive coercion mismatch
33RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-19598CRITICAL19 ago 2026
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
63RISCO
abrir
GitHub PoC1
Ring0-level process killer leveraging CVE-2026-0828 (BYOVD). Designed to demonstrate kernel-level process termination via a vulnerable signed driver, highlighting the security risks of Bring Your Own Vulnerable Driver attacks and the importance of driver trust, monitoring, and endpoint protection.
CVE-2026-0828HIGH19 ago 2026
Kernel driver vulnerability in Safetica Endpoint Client
41RISCO
abrir
VulnCheck XDB
local
CVE-2025-21479HIGHsob ataque19 ago 2026
Incorrect Authorization in Graphics
71RISCO
abrir
GitHub PoC
open-flaw/CVE-2026-56848
CVE-2026-56848HIGH19 ago 2026
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_m
41RISCO
abrir
GitHub PoC
CVE-2026-64849 PoC
CVE-2026-64849CRITICALsob ataque19 ago 2026
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
98RISCO
abrir
GitHub PoC1
halo cms plugin 1-request rce from a url, PoC + exploit chain
CVE-2026-67919CRITICAL19 ago 2026
An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri m
48RISCO
abrir
GitHub PoC
MattiaCervelli/CVE-2025-24893_Analysis
CVE-2025-24893CRITICALsob ataque19 ago 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
anteriorpágina 13 / 2.644próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.