Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.386exploits catalogados
36.533CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.466Referência 23.104GitHub PoC 15.075VulnCheck XDB 8.883Nuclei 4.365Metasploit 3.493✓ só verificadosrecentespopularesrisco
14.987 exploits
GitHub PoC★ 10
GhostLock (CVE-2026-43499) exploit adapted for Honor AAK-AN00 (MagicOS 10, kernel 6.6.89-android15) 声明,由于 AI 过于弱智 导致大量 token 被消耗 这导致资金严重不足在短时间内将不会更新 下次更新最早两天后
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-21017-LDAP-Anonymous-Bind-Privilege-Escalation
Improper handling of insufficient privileges in SecTelephonyProvider prior to SMR Jun-2026 Release 1 allows local attack
33RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11114-Node.js-vm-Sandbox-Escape-via-Proxy
Use after free in Device Trust in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had compromi
48RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11116-SNMPv3-Authentication-Bypass-via-Default-EngineID
Use after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code
41RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11117-WPA2-4-Way-Handshake-Reinstallation-KRACK-Sim-
Use after free in Views in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrar
41RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-21020-Protobuf-Message-Parsing-Polymorphic-Deserialization-Vulnerability
Improper export of android application components in OmaCP prior to SMR May-2026 Release 1 allows local attackers to tri
33RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-21019-Kubernetes-CronJob-Suspended-Execution-via-Time-Manipulation
Improper input validation in FacAtFunction in Galaxy Watch prior to SMR May-2026 Release 1 allows local attacker to exec
41RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11107-Insecure-Direct-Object-Reference-with-Predictable-UUIDv1
Inappropriate implementation in Downloads in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform U
33RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11115-Database-Connection-String-Injection-via-Env-Variable
Use after free in Updater in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform OS-leve
41RISCO
abrir ↗GitHub PoC★ 1
Apache HTTP Server 2.4.x mod_lua Buffer Overflow (CVE-2021-44790) - Advanced exploitation framework with fingerprinting, multi-stage scanning, plugin architecture, professional reporting, screenshot capture, SQLite database, and 95%+ confidence detection. Author: Sudeepa Wanigarathna.
Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier
45RISCO
abrir ↗GitHub PoC★ 1
JVBotelho/cve-2026-69243-poc-aiohttp-smuggling
AIOHTTP: HTTP request smuggling via WebSocket upgrade
33RISCO
abrir ↗GitHub PoC
CVE-2026-45033 PoC for Claude Code, not Github Copilot. Worked for Haiku 4.5.
GitHub Copilot CLI: Nested Bare Repository Can Execute Arbitrary Commands via core.fsmonitor
41RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-21018-OPC-UA-Authentication-Bypass-via-None-Security-Policy
Out-of-bounds write in SveService prior to SMR May-2026 Release 1 allows local privileged attackers to execute arbitrary
33RISCO
abrir ↗GitHub PoC
0xdak/CVE-2026-59243_exploit
Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)
48RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-21016-Malicious-PyPI-Package-Install-Hook-setup.py-Execution-
Incorrect privilege assignment in LocationManager prior to SMR May-2026 Release 1 allows local attackers to access sensi
33RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-21015-PHP-Filter-Chain-Arbitrary-File-Read
Incorrect default permissions in FactoryCamera prior to SMR May-2026 Release 1 allows local attacker to access unique id
33RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11111-TOCTOU-in-File-Permission-Check-Before-Open
Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bound
41RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11119-Padding-Oracle-Attack-on-CBC-Mode-Encryption
Inappropriate implementation in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had
48RISCO
abrir ↗GitHub PoC
webshellseo8/CVE-2026-12720-Proof-of-Concept
Kirki < 6.0.13 - Unauthenticated PHP Object Injection
41RISCO
abrir ↗GitHub PoC
0xdak/CVE-2026-67340_exploit
ArcadeDB before 26.7.2 Remote Code Execution via Trigger Scripts
41RISCO
abrir ↗GitHub PoC★ 3
GhostLock (CVE-2026-43499) kernel exploit for samsung devices with locked bootloader
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11108-Integer-Overflow-in-Memory-Allocator-kmalloc-Sim-
Inappropriate implementation in NFC in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perf
41RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11113-SMTP-Header-Injection-in-Contact-Form
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker wh
48RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11118-HTTP-2-Rapid-Reset-DDoS
Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code ins
41RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11109-Bluetooth-Classic-KNOB-Attack-Key-Negotiation-of-Bluetooth-
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data v
33RISCO
abrir ↗GitHub PoC
CVE-2026-60004 — Gitea <= 1.27.0 Pre-Auth RCE
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11110-AES-GCM-Nonce-Reuse-Leading-to-Key-Recovery
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data v
33RISCO
abrir ↗GitHub PoC
CVE-2026-13934
Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.47 allowed a remote a
48RISCO
abrir ↗GitHub PoC★ 1
pgAdmin 4 Import/Export RCE (CVE-2026-17566) PoC - TO PROGRAM injection via backslash-escape mismatch
pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)
48RISCO
abrir ↗GitHub PoC
x-znn/CVE-2026-63030
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.