Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.697exploits catalogados
36.715CVEs com exploração pública
24.695testados em laboratório
79.697 exploits
GitHub PoC30
**CVE-2026-18963** — unauthenticated Keycloak account takeover via the reset-credentials flow.
CVE-2026-18963CRITICAL06 set 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-31324CRITICALsob ataqueransomware06 set 2026
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISCO
abrir
VulnCheck XDB
info-leak
CVE-2026-64849CRITICALsob ataque06 set 2026
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
98RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-67276CRITICAL06 set 2026
SSH user impersonation possible in Mikrotik RouterOS
48RISCO
abrir
GitHub PoC
katranSefa/CVE-2026-19949
CVE-2026-19949HIGH06 set 2026
All-in-One WP Migration and Backup <= 7.109 - Unauthenticated Second-Order SQL Injection via Archive Restore to Remote Code Execution
41RISCO
abrir
GitHub PoC59
CVE-2026-67276 RouterOS SSH public-key authentication bypass lab PoC
CVE-2026-67276CRITICAL06 set 2026
SSH user impersonation possible in Mikrotik RouterOS
48RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-68613CRITICALsob ataque05 set 2026
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISCO
abrir
GitHub PoC
katranSefa/CVE-2026-3891
CVE-2026-3891CRITICAL05 set 2026
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RISCO
abrir
GitHub PoC2
adriyansyah-mf/cve-2026-85046-poc
CVE-2026-85046HIGHsob ataque05 set 2026
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside
71RISCO
abrir
GitHub PoC
AppleAVE2 kernel driver wire-format research and macOS reachability PoC for CVE-2026-64747.
CVE-2026-64747HIGH05 set 2026
A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iO
41RISCO
abrir
GitHub PoC7
Device-bound CVE-2026-64560 adaptation for Xiaomi 15 dada OS4.0.0.8
CVE-2026-64560HIGH05 set 2026
posix-cpu-timers: Prevent UAF caused by non-leader exec() race
41RISCO
abrir
GitHub PoC
Keycloak Blind SSRF POC
CVE-2020-1077005 set 2026
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using
50RISCO
abrir
GitHub PoC
Unauthenticated arbitrary file upload -> RCE in WPLP Cookie Consent (gdpr-cookie-consent) <= 4.4.1 - technical write-up and PoC
CVE-2026-75865CRITICAL05 set 2026
WPLP Cookie Consent <= 4.4.1 - Unauthenticated Arbitrary File Upload via 'upload-logo' REST Endpoint
48RISCO
abrir
GitHub PoC
V8 TurboFan CheckMaps type-confusion research and compressed-heap R/W exploit notes for CVE-2026-78938.
CVE-2026-78938HIGH05 set 2026
Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside
41RISCO
abrir
GitHub PoC
Root-cause analysis and crash-tier PoC for CVE-2026-64705, an HFS xattr kernel heap overflow on macOS.
CVE-2026-64705MEDIUM05 set 2026
A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma
33RISCO
abrir
GitHub PoC6
A/B Docker lab + PoC for CVE-2026-32475 (Elementor Pro Forms unauthenticated arbitrary file upload -> RCE via validation/move loop desync)
CVE-2026-32475CRITICAL05 set 2026
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RISCO
abrir
GitHub PoC1
CVE-2026-32475 PoC : Elementor Pro Unauthenticated Arbitrary File Upload to RCE
CVE-2026-32475CRITICAL05 set 2026
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RISCO
abrir
GitHub PoC
CVE-2026-18963 — Keycloak reset-credentials bypass -> Account Takeover
CVE-2026-18963CRITICAL05 set 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISCO
abrir
GitHub PoC
0xCyp1337/CVE-2026-19598-
CVE-2026-19598CRITICAL05 set 2026
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
63RISCO
abrir
GitHub PoC
Zimbra Collaboration Suite RCE — SMTP log poisoning → swatchdog → OS Command Injection (CVSS 8.9, CISA KEV)
CVE-2026-73570HIGHsob ataque05 set 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RISCO
abrir
GitHub PoC
postgres CVE-2026-6471 Exploit
CVE-2026-6471HIGH05 set 2026
PostgreSQL logical decoding can dlopen arbitrary file
41RISCO
abrir
GitHub PoC1
CVE-2026-6471
CVE-2026-6471HIGH05 set 2026
PostgreSQL logical decoding can dlopen arbitrary file
41RISCO
abrir
GitHub PoC
CVE-2025-55163 / CVE-2026-56819: offline checker for the 7 netty-codec-http2 CVEs. Tells you which ones you are exposed to, and the one version that fixes all seven (4.1.136.Final / 4.2.16.Final) - written on none of the advisories. Does not scan pom.xml on purpose: WebFlux pulls it in transitively.
CVE-2026-56819HIGH05 set 2026
Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)
41RISCO
abrir
GitHub PoC
katranSefa/CVE-2026-18366
CVE-2026-18366CRITICAL05 set 2026
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
48RISCO
abrir
GitHub PoC
katranSefa/CVE-2026-15981
CVE-2026-15981CRITICAL05 set 2026
SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter
48RISCO
abrir
GitHub PoC
Ritinify/CVE-2025-29927-PoC
CVE-2025-29927CRITICAL05 set 2026
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
Exploit Framework for CVE-2025-4255
CVE-2025-4255MEDIUM05 set 2026
PCMan FTP Server RMD Command buffer overflow
33RISCO
abrir
GitHub PoC
gpgsm CVE-2026-57062 exploit POC
CVE-2026-57062LOW05 set 2026
CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM becaus
28RISCO
abrir
GitHub PoC
Jenkins PersistenceRoot Deserialization RCE (SECURITY-3972) — PoC & analysis. Requires Item/Configure; affects weekly <= 2.579 / LTS <= 2.568.2
CVE-2026-84645HIGH05 set 2026
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in indepen
41RISCO
abrir
GitHub PoC
katranSefa/CVE-2026-3326
CVE-2026-3326HIGH05 set 2026
XStore < 9.7.3 - Unauthenticated SQLi
56RISCO
abrir
anteriorpágina 2 / 2.657próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.