Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
14.946 exploits
GitHub PoC
CVE-2026-34348 - Draft or TODO
CVE-2026-34348MEDIUM10 ago 2026
Windows Event Logging Service Information Disclosure Vulnerability
33RISCO
abrir
GitHub PoC1
CVE-2026-43499 (GhostLock) research on HUAWEI MatePad Pro 11 GOT-W29
CVE-2026-43499HIGH10 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC2
独立 APK:CVE-2026-43499 GhostLock 提权 + Shizuku shell 身份执行
CVE-2026-43499HIGH10 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC4
GhostLock-X200 v1.0 - temporary root toolchain for vivo X200 (PD2415 / b57 kernel) based on CVE-2026-43499. For authorized security research only.
CVE-2026-43499HIGH10 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
CVE-2026-43499 GhostLock APK 骨架 — 仅验证空项目能编译通过
CVE-2026-43499HIGH10 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC1
CVE-2026-64824 — Home Assistant backup-restore symlink path traversal → root RCE. First working PoC, verified on real HA 2026.5.4 (sitecustomize.py overwrite). GHSA-cwh8-w64c-4j5h
CVE-2026-64824CRITICAL10 ago 2026
Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore
48RISCO
abrir
GitHub PoC1
IamDremig/CVE-2026-14802
CVE-2026-14802MEDIUM10 ago 2026
react create-react-app react-dev-utils openBrowser.js startBrowserProcess os command injection
33RISCO
abrir
GitHub PoC
Procjevt/CVE-2026-9198
CVE-2026-9198CRITICALsob ataque10 ago 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISCO
abrir
GitHub PoC26
CVE-2026-53361 AF_UNIX GC vs MSG_PEEK use-after-free container escape
CVE-2026-53361HIGH10 ago 2026
af_unix: Set gc_in_progress to true in unix_gc().
41RISCO
abrir
GitHub PoC
CVE-2026-65891 PoC — Joomla Content Editor file rename vulnerability (auth required, fixed in JCE 2.20.2)
CVE-2026-65891MEDIUM10 ago 2026
Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.9.99.10
33RISCO
abrir
GitHub PoC1
Saku0512/CVE-2026-9086-poc
CVE-2026-9086HIGH10 ago 2026
Keycloak: keycloak: cross-site scripting (xss) via case-insensitive uri validation bypass
41RISCO
abrir
GitHub PoC
my poc for CVE-2026-53787
CVE-2026-53787CRITICAL10 ago 2026
Amasty Order Attributes for Magento 2 < 4.0.0 Unauthenticated Arbitrary File Upload
63RISCO
abrir
GitHub PoC5
Community-maintained fork of image-size with fixes for CVE-2025-71329 and CVE-2025-71330
CVE-2025-71329HIGH10 ago 2026
image-size 2.0.2 Denial of Service via Infinite Loop in JXL/HEIF Parser
41RISCO
abrir
GitHub PoC
spring retry 1.3.x fix with niche toolkit for CVE-2026-41710
CVE-2026-41710MEDIUM10 ago 2026
Cache Exhaustion in Stateful Retries leads to Denial of Service
33RISCO
abrir
GitHub PoC2
CVE-2026-23744 is an unauthenticated command injection in MCPJam Inspector ≤1.4.2 via /api/mcp/connect. This POC exploits it by sending a crafted JSON payload to execute arbitrary commands, granting a reverse shell with PTY.
CVE-2026-23744CRITICAL10 ago 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
GitHub PoC1
Tracking SCTPhantom (CVE-2026-64564), the Linux kernel SCTP ASCONF transport use-after-free
CVE-2026-64564CRITICAL10 ago 2026
sctp: don't free the ASCONF's own transport in DEL-IP processing
48RISCO
abrir
GitHub PoC
CVE-2026-43499 GhostLock APK 骨架 — 从零开始,仅空项目编译验证
CVE-2026-43499HIGH10 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC1
IamDremig/CVE-2026-65591
CVE-2026-65591HIGH10 ago 2026
n8n before 1.123.64 Sanitizer Bypass Remote Code Execution
41RISCO
abrir
GitHub PoC1
CVE-2026-64747 AGXG14P count-bitmask OOB trigger probe (A15/iOS 26.5.2)
CVE-2026-64747HIGH10 ago 2026
A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iO
41RISCO
abrir
GitHub PoC
CVE-2026-19264 - Critical unauthenticated path traversal to full instance takeover in Postiz (< 2.22.1). Technical writeup: decode-order bypass, JWT_SECRET escalation, and analysis of the upstream fix.
CVE-2026-19264CRITICAL10 ago 2026
Unauthenticated arbitrary file read via /uploads path traversal (URL-encoded separators) leading to instance takeover
48RISCO
abrir
GitHub PoC
CVE-2026-20685 - Draft or TODO
CVE-2026-20685MEDIUM10 ago 2026
An attacker in a privileged network position may be able to leak sensitive information. A path handling issue was addres
33RISCO
abrir
GitHub PoC2
A rewritten Proof-of-Concept / Local Privilege Escalation (LPE) exploit targeting CVE-2019-2215, a Use-After-Free vulnerability in the Android Binder driver.
CVE-2019-2215HIGHsob ataque10 ago 2026
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir
GitHub PoC
Authorized Kali–Metasploitable2 lab using Python and Nmap NSE to validate CVE-2011-2523 in vsFTPd 2.3.4.
CVE-2011-252310 ago 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
GitHub PoC1
A Proof-Of-Concept for the CVE-2021-44228 vulnerability.
CVE-2021-44228CRITICALsob ataqueransomware09 ago 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Emaar1x/CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware09 ago 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
PoC for CVE-2025-59528 used to achieve remote code execution on the Silentium machine at HTB
CVE-2025-59528CRITICAL09 ago 2026
Flowise has Remote Code Execution vulnerability
85RISCO
abrir
GitHub PoC1
POC 4 CVE-2026-15038
CVE-2026-15038CRITICAL09 ago 2026
InfiniteWP Client < 1.13.6 - Unauthenticated Administrator Account Takeover on Multisite
48RISCO
abrir
GitHub PoC
Technical vulnerability analysis and CVE briefing for CVE-2026-9645 affecting ScadaBR.
CVE-2026-9645CRITICAL09 ago 2026
ScadaBR Authenticated Remote Code Execution
48RISCO
abrir
GitHub PoC3
🔥 XSS2Shell — CVE-2026-64638 Scanner & PoC Toolkit
CVE-2026-64638HIGH09 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RISCO
abrir
GitHub PoC3
eh-amish/CVE-2026-64638-XSS-to-Shell-PoC
CVE-2026-64638HIGH09 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RISCO
abrir
anteriorpágina 13 / 499próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.