Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.858exploits catalogados
36.825CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.346GitHub PoC 15.209VulnCheck XDB 8.944Nuclei 4.383Metasploit 3.501✓ só verificadosrecentespopularesrisco
79.858 exploits
VulnCheck XDB
initial-access
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
48RISCO
abrir ↗GitHub PoC
wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir ↗GitHub PoC★ 15
Hunt for CVE-2026-18963 exploitation traces (Keycloak unauthenticated account takeover) in the Keycloak database
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISCO
abrir ↗GitHub PoC
aarch64 race condition checker
eventpoll: fix ep_remove struct eventpoll / struct file UAF
41RISCO
abrir ↗GitHub PoC
CVE-2026-19478: GitLab GraphQL Vulnerability PoC
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir ↗VulnCheck XDB
initial-access
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISCO
abrir ↗GitHub PoC
Controlled PenTest lab report for UnrealIRCd 3.2.8.1 backdoor (CVE-2010-2075) on Metasploitable3 with remediation steps.
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RISCO
abrir ↗GitHub PoC
This python script exploit the vulnerable marimo /terminal/ws endpoint and returns a interactive shell.
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISCO
abrir ↗GitHub PoC★ 1
halo cms plugin 1-request rce from a url, PoC + exploit chain
An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri m
48RISCO
abrir ↗GitHub PoC★ 1
4gaBoards < 3.3.9 - User Information Disclosure
4gaBoards: Mass Information Disclosure (Internal PII Leakage) on /api/users to any authenticated user
33RISCO
abrir ↗GitHub PoC★ 1
CVE-2026-39987 — Marimo Pre-Authentication RCE
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISCO
abrir ↗GitHub PoC★ 1
VsockDrop (CVE-2026-53365) Linux kernel io_uring zerocopy vsock LPE exploit mirror — MaherAzzouzi, MIT; for authorized security testing
vsock/virtio: fix zerocopy completion for multi-skb sends
41RISCO
abrir ↗GitHub PoC
JetBrains TeamCity On-Premises CVE-2026-63077 Emergency Hardening & Patch Runbook Package
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
100RISCO
abrir ↗GitHub PoC★ 1
0xdeadroot/SCTPhantom-CVE-2026-64564
sctp: don't free the ASCONF's own transport in DEL-IP processing
48RISCO
abrir ↗GitHub PoC★ 1
Ring0-level process killer leveraging CVE-2026-0828 (BYOVD). Designed to demonstrate kernel-level process termination via a vulnerable signed driver, highlighting the security risks of Bring Your Own Vulnerable Driver attacks and the importance of driver trust, monitoring, and endpoint protection.
Kernel driver vulnerability in Safetica Endpoint Client
41RISCO
abrir ↗GitHub PoC
Proof of Concept for CVE-2026-19598 affecting Pods <= 3.3.9.
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
63RISCO
abrir ↗GitHub PoC
TranDongA3/POC-CVE-2026-63030-CVE-2026-60137-
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir ↗GitHub PoC★ 1
Begitdj/cve-2019-2215-markw
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir ↗GitHub PoC
CVE-2026-18504, CVE-2026-16732 - Draft or TODO
fastify vulnerable to schema validation bypass via root primitive coercion mismatch
33RISCO
abrir ↗GitHub PoC
CVE-2026-64849 PoC
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
98RISCO
abrir ↗GitHub PoC
CVE-2026-47858
live information startup mode is vulnerable for remote code execution
41RISCO
abrir ↗GitHub PoC
andreamammano89-maker/CVE-2021-42013_821311
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir ↗GitHub PoC
MattiaCervelli/CVE-2025-24893_Analysis
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir ↗GitHub PoC★ 532
A cPanel and WHM authentication bypassing tool
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir ↗GitHub PoC
fork and edits from https://github.com/aniqfakhrul/CVE-2026-54121
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISCO
abrir ↗GitHub PoC
CVE-2026-73072 - Draft or TODO
Vim: Heap Buffer Overflow when Loading a Spell File
41RISCO
abrir ↗VulnCheck XDB
initial-access
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir ↗GitHub PoC
Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration
Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration
48RISCO
abrir ↗GitHub PoC
zavisco/CVE-2026-64849.yaml
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
98RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.