Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.386exploits catalogados
36.533CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.466Referência 23.104GitHub PoC 15.075VulnCheck XDB 8.883Nuclei 4.365Metasploit 3.493✓ só verificadosrecentespopularesrisco
14.984 exploits
GitHub PoC
lucastran05/CVE-2021-41773
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗GitHub PoC★ 914
CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir ↗GitHub PoC
Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything cross tenant.
In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication)
48RISCO
abrir ↗GitHub PoC
CVE-2026-0092- Possible device lock controller bypass due to a missing permission check.
In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead
48RISCO
abrir ↗GitHub PoC
CVE-2026-71211 exploit
mlflow - Unvalidated Gateway Secret api_base Enables SSRF via Gateway Proxy Endpoint
41RISCO
abrir ↗GitHub PoC★ 1
WordPress Core Pre-Auth RCE — Batch Route Confusion + SQL Injection
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir ↗GitHub PoC★ 1
rmhowe425/PoC-CVE-2026-9198
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISCO
abrir ↗GitHub PoC
ICS-Park Smart Park Management System v2.0
Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/rol
41RISCO
abrir ↗GitHub PoC
qflksheep/CVE-2026-67689-FineAdmin.Mvc-vulnerability
SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `or
48RISCO
abrir ↗GitHub PoC
CVE-2026-33017 Langflow RCE PoC
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir ↗GitHub PoC
Detection rules and analysis for Dirty Frag (CVE-2026-43284/CVE-2026-43500) Linux kernel LPE vulnerability. Based on community research and health probe configurations.
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11119-Padding-Oracle-Attack-on-CBC-Mode-Encryption
Inappropriate implementation in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had
48RISCO
abrir ↗GitHub PoC★ 1
pgAdmin 4 Import/Export RCE (CVE-2026-17566) PoC - TO PROGRAM injection via backslash-escape mismatch
pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)
48RISCO
abrir ↗GitHub PoC★ 1
JVBotelho/cve-2026-69243-poc-aiohttp-smuggling
AIOHTTP: HTTP request smuggling via WebSocket upgrade
33RISCO
abrir ↗GitHub PoC
CVE-2026-45033 PoC for Claude Code, not Github Copilot. Worked for Haiku 4.5.
GitHub Copilot CLI: Nested Bare Repository Can Execute Arbitrary Commands via core.fsmonitor
41RISCO
abrir ↗GitHub PoC
x-znn/CVE-2026-63030
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir ↗GitHub PoC★ 2
CVE-2026-63223 — CI4RCE: CodeIgniter 4 is_image/mime_in File Upload RCE. Magic bytes bypass (getExtension vs getClientExtension). CVSS 9.8 | CWE-434 | CI4 < 4.7.4
CodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules
48RISCO
abrir ↗GitHub PoC
python code use to check for user in ssh
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir ↗GitHub PoC
0xdak/CVE-2026-52680_exploit
Apache Kyuubi: REST batch multipart upload path traversal allows controlled file write
48RISCO
abrir ↗GitHub PoC★ 5
WordPress All-in-One Exploit Framework — detector, scanner, enumerator, exploit, escalation. 10 CVEs from the 2026-08 wave incl. CVE-2026-63030 (wp2shell).
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11111-TOCTOU-in-File-Permission-Check-Before-Open
Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bound
41RISCO
abrir ↗GitHub PoC
0xdak/CVE-2026-59243_exploit
Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)
48RISCO
abrir ↗GitHub PoC★ 1
Gitea diffpatch RCE (CVE-2026-60004) PoC - repo-write to RCE as Gitea service account
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11118-HTTP-2-Rapid-Reset-DDoS
Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code ins
41RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11109-Bluetooth-Classic-KNOB-Attack-Key-Negotiation-of-Bluetooth-
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data v
33RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11108-Integer-Overflow-in-Memory-Allocator-kmalloc-Sim-
Inappropriate implementation in NFC in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perf
41RISCO
abrir ↗GitHub PoC
Safe PowerShell validator for PHP CVE-2026-17543 exposure via HTTP headers and non-destructive login-form probes.
SQL injection in ext-pgsql via E'...' backslash breakout
41RISCO
abrir ↗GitHub PoC
CVE-2026-60004 — Gitea <= 1.27.0 Pre-Auth RCE
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISCO
abrir ↗GitHub PoC★ 3
GhostLock (CVE-2026-43499) kernel exploit for samsung devices with locked bootloader
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11110-AES-GCM-Nonce-Reuse-Leading-to-Key-Recovery
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data v
33RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.