Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.386exploits catalogados
36.533CVEs com exploração pública
24.695testados em laboratório
14.984 exploits
GitHub PoC
lucastran05/CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware05 ago 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC914
CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept
CVE-2026-63030CRITICALsob ataque05 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC
Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything cross tenant.
CVE-2025-66390CRITICAL05 ago 2026
In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication)
48RISCO
abrir
GitHub PoC
CVE-2026-0092- Possible device lock controller bypass due to a missing permission check.
CVE-2026-0092CRITICAL05 ago 2026
In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead
48RISCO
abrir
GitHub PoC
CVE-2026-71211 exploit
CVE-2026-71211HIGH05 ago 2026
mlflow - Unvalidated Gateway Secret api_base Enables SSRF via Gateway Proxy Endpoint
41RISCO
abrir
GitHub PoC1
WordPress Core Pre-Auth RCE — Batch Route Confusion + SQL Injection
CVE-2026-63030CRITICALsob ataque05 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC1
rmhowe425/PoC-CVE-2026-9198
CVE-2026-9198CRITICALsob ataque05 ago 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISCO
abrir
GitHub PoC
ICS-Park Smart Park Management System v2.0
CVE-2026-67687HIGH05 ago 2026
Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/rol
41RISCO
abrir
GitHub PoC
qflksheep/CVE-2026-67689-FineAdmin.Mvc-vulnerability
CVE-2026-67689CRITICAL05 ago 2026
SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `or
48RISCO
abrir
GitHub PoC
CVE-2026-33017 Langflow RCE PoC
CVE-2026-33017CRITICALsob ataque05 ago 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir
GitHub PoC
Detection rules and analysis for Dirty Frag (CVE-2026-43284/CVE-2026-43500) Linux kernel LPE vulnerability. Based on community research and health probe configurations.
CVE-2026-43284HIGH05 ago 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISCO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-11119-Padding-Oracle-Attack-on-CBC-Mode-Encryption
CVE-2026-11119CRITICAL04 ago 2026
Inappropriate implementation in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had
48RISCO
abrir
GitHub PoC1
pgAdmin 4 Import/Export RCE (CVE-2026-17566) PoC - TO PROGRAM injection via backslash-escape mismatch
CVE-2026-17566CRITICAL04 ago 2026
pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)
48RISCO
abrir
GitHub PoC1
JVBotelho/cve-2026-69243-poc-aiohttp-smuggling
CVE-2026-69243MEDIUM04 ago 2026
AIOHTTP: HTTP request smuggling via WebSocket upgrade
33RISCO
abrir
GitHub PoC
CVE-2026-45033 PoC for Claude Code, not Github Copilot. Worked for Haiku 4.5.
CVE-2026-45033HIGH04 ago 2026
GitHub Copilot CLI: Nested Bare Repository Can Execute Arbitrary Commands via core.fsmonitor
41RISCO
abrir
GitHub PoC
x-znn/CVE-2026-63030
CVE-2026-63030CRITICALsob ataque04 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC2
CVE-2026-63223 — CI4RCE: CodeIgniter 4 is_image/mime_in File Upload RCE. Magic bytes bypass (getExtension vs getClientExtension). CVSS 9.8 | CWE-434 | CI4 < 4.7.4
CVE-2026-63223CRITICAL04 ago 2026
CodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules
48RISCO
abrir
GitHub PoC
python code use to check for user in ssh
CVE-2018-15473MEDIUM04 ago 2026
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC
0xdak/CVE-2026-52680_exploit
CVE-2026-52680CRITICAL04 ago 2026
Apache Kyuubi: REST batch multipart upload path traversal allows controlled file write
48RISCO
abrir
GitHub PoC5
WordPress All-in-One Exploit Framework — detector, scanner, enumerator, exploit, escalation. 10 CVEs from the 2026-08 wave incl. CVE-2026-63030 (wp2shell).
CVE-2026-63030CRITICALsob ataque04 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-11111-TOCTOU-in-File-Permission-Check-Before-Open
CVE-2026-11111HIGH04 ago 2026
Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bound
41RISCO
abrir
GitHub PoC
0xdak/CVE-2026-59243_exploit
CVE-2026-59243CRITICAL04 ago 2026
Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)
48RISCO
abrir
GitHub PoC1
Gitea diffpatch RCE (CVE-2026-60004) PoC - repo-write to RCE as Gitea service account
CVE-2026-60004CRITICAL04 ago 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISCO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-11118-HTTP-2-Rapid-Reset-DDoS
CVE-2026-11118HIGH04 ago 2026
Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code ins
41RISCO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-11109-Bluetooth-Classic-KNOB-Attack-Key-Negotiation-of-Bluetooth-
CVE-2026-11109MEDIUM04 ago 2026
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data v
33RISCO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-11108-Integer-Overflow-in-Memory-Allocator-kmalloc-Sim-
CVE-2026-11108HIGH04 ago 2026
Inappropriate implementation in NFC in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perf
41RISCO
abrir
GitHub PoC
Safe PowerShell validator for PHP CVE-2026-17543 exposure via HTTP headers and non-destructive login-form probes.
CVE-2026-17543HIGH04 ago 2026
SQL injection in ext-pgsql via E'...' backslash breakout
41RISCO
abrir
GitHub PoC
CVE-2026-60004 — Gitea <= 1.27.0 Pre-Auth RCE
CVE-2026-60004CRITICAL04 ago 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISCO
abrir
GitHub PoC3
GhostLock (CVE-2026-43499) kernel exploit for samsung devices with locked bootloader
CVE-2026-43499HIGH04 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-11110-AES-GCM-Nonce-Reuse-Leading-to-Key-Recovery
CVE-2026-11110MEDIUM04 ago 2026
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data v
33RISCO
abrir
anteriorpágina 18 / 500próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.