Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.385exploits catalogados
36.532CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.466Referência 23.104GitHub PoC 15.074VulnCheck XDB 8.883Nuclei 4.365Metasploit 3.493✓ só verificadosrecentespopularesrisco
14.946 exploits
GitHub PoC
Reproducer for CVE-2026-64640 — Apache Polaris Iceberg REST register/register-view vends storage credentials and reads an attacker-chosen metadata location before validating allowedLocations (confused-deputy cross-tenant read). Affected ≤ 1.6.0, fixed in 1.7.0.
Apache Polaris: register endpoint reads attacker-controlled storage location before allowed-locations validation
33RISCO
abrir ↗GitHub PoC★ 5
LPE on Deb
sctp: don't free the ASCONF's own transport in DEL-IP processing
48RISCO
abrir ↗GitHub PoC
Maintained Python 3 port of the original FUEL CMS CVE-2018-16763 proof-of-concept.
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir ↗GitHub PoC
Hands-on homelab simulating the Log4Shell (CVE-2021-44228) vulnerability. Deploy Docker containers to build a vulnerable target and attacker machine, execute the exploit, and implement security mitigations. Perfect for learning offensive security and application hardening.
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗GitHub PoC
A simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go
Craft CMS Allows Remote Code Execution
100RISCO
abrir ↗GitHub PoC★ 1
CVE-2026-0163 Exploit
In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to rem
48RISCO
abrir ↗GitHub PoC★ 1
Joomla RSFiles 未授权文件上传CVE-2026-57827检测&利用脚本
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12
63RISCO
abrir ↗GitHub PoC
The Joomla extension PhocaCommander is vulnerable to Path Traversal in the file upload action - CVSS 6.1
Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3
33RISCO
abrir ↗GitHub PoC
The Joomla extension PhocaCommander is vulnerable to Path Traversal in delete, copy, move actions - CVSS 6.4
Joomla Extension - phoca.cz - Path traversal vulnerability in Phoca Commander 1.0.0-6.1.3
33RISCO
abrir ↗GitHub PoC★ 4
Proof of concept for CVE-2026-18649, a remote denial of service vulnerability in GStreamer's H.264 RTP depayloader (rtph264depay).
Gst-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay rtp depayloaders
41RISCO
abrir ↗GitHub PoC★ 1
woshidashabi1126/CVE-2026-70553-PoC
MaxSite CMS Unauthenticated RCE via Install Endpoint
48RISCO
abrir ↗GitHub PoC★ 2
CVE-2026-56164 is a critical missing-authentication vulnerability affecting on-premises Microsoft SharePoint Server. It allows unauthenticated, remote attackers to elevate privileges over a network.
Microsoft SharePoint Server Elevation of Privilege Vulnerability
68RISCO
abrir ↗GitHub PoC★ 5
👾 CVE-2026-58048 – cPanel Root SQL Execution Toolkit (CVSS 9.4) | Full Red/Blue Team Toolkit suite for unpatched cPanel & WHM 11.x. 2 tools: Safe Checker (audit/reporting), Weaponized (reverse shell, persistence, UDF RCE, deployment, file read/write, database operations, mass scan). w/Python. 🦾 Use Ethically, Stay Legal <3
Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
48RISCO
abrir ↗GitHub PoC
tfawnies/CVE-2026-64633
A vulnerability allowing remote unauthenticated code execution on the agent host.
48RISCO
abrir ↗GitHub PoC
Notepad++ CVE-2026-52886 — session.xml backupFilePath starts_with() path traversal (GHSA-rqfm-pw34-r7j6)
Notepad++: session.xml backupFilePath starts_with Bypass
33RISCO
abrir ↗GitHub PoC
0xdak/CVE-2026-69098_exploit
kotaemon 0.12.0 Unauthenticated Remote Code Execution via Insecure Deserialization
48RISCO
abrir ↗GitHub PoC
hasan8babiker/CVE-2024-6387
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir ↗GitHub PoC
扫出你实际装的 Apache Shiro 模块与版本,逐条判定官方 26 条 CVE 里哪些真的落在你身上。按「CVE × 模块」判定,零依赖单 jar。 CVE-2026-49268
Apache Shiro: LDAP DN Injection in DefaultLdapRealm
41RISCO
abrir ↗GitHub PoC
查出 Spring Boot 内嵌 Tomcat 的真实版本(pom 里没有),并对每条 2026 年 CVE 同时给出 ASF 官方评级与 GitHub 评级、触发条件、以及这条会不会进 Dependabot 告警 CVE-2026-41293
Apache Tomcat: HTTP/2 request headers not validated
48RISCO
abrir ↗GitHub PoC
Read-only N-able N-central CVE-2026-18556/CVE-2026-18577 post-exploitation IoC hunter for Windows endpoints
Unauthenticated administrative account takeover
83RISCO
abrir ↗GitHub PoC
CVE-2026-67598 — Emlog Pro: disabled TLS certificate validation in AI assistant (MITM → API-key theft). CWE-295, CVSS 9.1. Reported by @IlhomjonR.
Emlog Pro 2.6.23 TLS Certificate Validation Disabled in ai.php
48RISCO
abrir ↗GitHub PoC
Shams-Ul-Mehmood/CVE-2018-7600-Drupalgeddon2-RCE
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir ↗GitHub PoC
CVE-2022-31626, CVE-2024-2961, CVE-2019-6977, PHP security research
gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch funct
35RISCO
abrir ↗GitHub PoC
The Joomla extension PhocaCommander is vulnerable to Path Traversal in the getSource function - CVSS 8.2
Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3
41RISCO
abrir ↗GitHub PoC★ 1
Hunt-Benito/e-is-for-exploit-cve-2026-17543-php-pgsql-sql-injection-backslash-breakout
SQL injection in ext-pgsql via E'...' backslash breakout
41RISCO
abrir ↗GitHub PoC★ 1
Security research: Trezor Safe calldata confirmation-binding bypass vulnerability analysis. Educational proof-of-concept for hardware wallet transaction display verification.
Trezor Safe improper security check in on-device display
13RISCO
abrir ↗GitHub PoC★ 58
Microsoft SharePoint JWT Authentication Bypass (CVE-2026-55040)
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISCO
abrir ↗GitHub PoC
CVE-2026-71211 exploit
mlflow - Unvalidated Gateway Secret api_base Enables SSRF via Gateway Proxy Endpoint
41RISCO
abrir ↗GitHub PoC
CVE-2026-33017 Langflow RCE PoC
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir ↗GitHub PoC
xuwu-xuwu/CVE-2026-68004
An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP pub
48RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.