Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.386exploits catalogados
36.533CVEs com exploração pública
24.695testados em laboratório
14.946 exploits
GitHub PoC1
Craft CMS CVE-2025-32432 command runner adapted from Nicolas Bourras and Orange Cyberdefense research
CVE-2025-32432CRITICALsob ataque05 ago 2026
Craft CMS Allows Remote Code Execution
100RISCO
abrir
GitHub PoC
PoC + analysis for CVE-2026-54917 — SeaweedFS S3 gateway cross-bucket path traversal (CVSS 10.0, <4.30). Read/write any bucket via .. in the object key.
CVE-2026-54917HIGH05 ago 2026
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access
56RISCO
abrir
GitHub PoC
Detection rules and analysis for Dirty Frag (CVE-2026-43284/CVE-2026-43500) Linux kernel LPE vulnerability. Based on community research and health probe configurations.
CVE-2026-43284HIGH05 ago 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISCO
abrir
GitHub PoC
Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything cross tenant.
CVE-2025-66390CRITICAL05 ago 2026
In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication)
48RISCO
abrir
GitHub PoC
Dungsocool/CVE-2023-6553
CVE-2023-6553CRITICAL05 ago 2026
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RISCO
abrir
GitHub PoC914
CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept
CVE-2026-63030CRITICALsob ataque05 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC
minwunn/wp2shell-CVE-2026-63030
CVE-2026-63030CRITICALsob ataque05 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC
xuwu-xuwu/CVE-2026-68004
CVE-2026-68004CRITICAL05 ago 2026
An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP pub
48RISCO
abrir
GitHub PoC12
PoCs for Wellbia XIGNCODE3 anti-cheat xhunter driver family - xhunter1.sys v2023.12.7.78 and xhunter2.sys v2026.6.1.192 (CVE-2026-15430, CVE-2026-3609).
CVE-2026-15430MEDIUM05 ago 2026
CVE-2026-15430
33RISCO
abrir
GitHub PoC
lucastran05/CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware05 ago 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
CVE-2026-0092- Possible device lock controller bypass due to a missing permission check.
CVE-2026-0092CRITICAL05 ago 2026
In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead
48RISCO
abrir
GitHub PoC1
rmhowe425/PoC-CVE-2026-9198
CVE-2026-9198CRITICALsob ataque05 ago 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISCO
abrir
GitHub PoC1
CVE-2026-42533: pre-auth nginx heap overflow and info leak from PCRE capture clobbering in the map/script engine, chained to RCE.
CVE-2026-42533CRITICAL05 ago 2026
NGINX Map directive and Regex matching vulnerability
48RISCO
abrir
GitHub PoC1
WordPress Core Pre-Auth RCE — Batch Route Confusion + SQL Injection
CVE-2026-63030CRITICALsob ataque05 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC2
Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting PoC
CVE-2026-17532MEDIUM05 ago 2026
Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting
48RISCO
abrir
GitHub PoC
qflksheep/CVE-2026-67689-FineAdmin.Mvc-vulnerability
CVE-2026-67689CRITICAL05 ago 2026
SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `or
48RISCO
abrir
GitHub PoC
CVE-2026-71211 exploit
CVE-2026-71211HIGH05 ago 2026
mlflow - Unvalidated Gateway Secret api_base Enables SSRF via Gateway Proxy Endpoint
41RISCO
abrir
GitHub PoC
ICS-Park Smart Park Management System v2.0
CVE-2026-67687HIGH05 ago 2026
Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/rol
41RISCO
abrir
GitHub PoC4
learner330/fastjson-cve-2026-16723
CVE-2026-16723CRITICAL05 ago 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISCO
abrir
GitHub PoC
CVE-2026-33017 Langflow RCE PoC
CVE-2026-33017CRITICALsob ataque05 ago 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir
GitHub PoC
🚨 Threat intel & incident response research on SharePoint "ToolShell" RCE zero-day (CVE-2025-53770). 🕵️‍♂️ Covers root-cause deserialization flaws, attack timelines, risk metrics, and defensive EDR validation playbooks. 🛡️
CVE-2025-53770CRITICALsob ataqueransomware04 ago 2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-11110-AES-GCM-Nonce-Reuse-Leading-to-Key-Recovery
CVE-2026-11110MEDIUM04 ago 2026
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data v
33RISCO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-21018-OPC-UA-Authentication-Bypass-via-None-Security-Policy
CVE-2026-21018MEDIUM04 ago 2026
Out-of-bounds write in SveService prior to SMR May-2026 Release 1 allows local privileged attackers to execute arbitrary
33RISCO
abrir
GitHub PoC
CVE-2026-13934
CVE-2026-13934CRITICAL04 ago 2026
Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.47 allowed a remote a
48RISCO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-11117-WPA2-4-Way-Handshake-Reinstallation-KRACK-Sim-
CVE-2026-11117HIGH04 ago 2026
Use after free in Views in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrar
41RISCO
abrir
GitHub PoC3
CVE-2026-43499 x86 Exploit
CVE-2026-43499HIGH04 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC10
GhostLock (CVE-2026-43499) exploit adapted for Honor AAK-AN00 (MagicOS 10, kernel 6.6.89-android15) 声明,由于 AI 过于弱智 导致大量 token 被消耗 这导致资金严重不足在短时间内将不会更新 下次更新最早两天后
CVE-2026-43499HIGH04 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-21019-Kubernetes-CronJob-Suspended-Execution-via-Time-Manipulation
CVE-2026-21019HIGH04 ago 2026
Improper input validation in FacAtFunction in Galaxy Watch prior to SMR May-2026 Release 1 allows local attacker to exec
41RISCO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-21020-Protobuf-Message-Parsing-Polymorphic-Deserialization-Vulnerability
CVE-2026-21020MEDIUM04 ago 2026
Improper export of android application components in OmaCP prior to SMR May-2026 Release 1 allows local attackers to tri
33RISCO
abrir
GitHub PoC1
Gitea diffpatch RCE (CVE-2026-60004) PoC - repo-write to RCE as Gitea service account
CVE-2026-60004CRITICAL04 ago 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISCO
abrir
anteriorpágina 17 / 499próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.