Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.858exploits catalogados
36.825CVEs com exploração pública
24.695testados em laboratório
79.858 exploits
GitHub PoC1
4gaBoards < 3.3.9 - User Information Disclosure
CVE-2026-53959MEDIUM19 ago 2026
4gaBoards: Mass Information Disclosure (Internal PII Leakage) on /api/users to any authenticated user
33RISCO
abrir
GitHub PoC
Oracle OID LDAP Server Privileges Management Exploit
CVE-2026-61241CRITICAL19 ago 2026
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Suppor
28RISCO
abrir
GitHub PoC
MattiaCervelli/CVE-2025-24893_Analysis
CVE-2025-24893CRITICALsob ataque19 ago 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC
Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration
CVE-2026-15748CRITICAL19 ago 2026
Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration
48RISCO
abrir
VulnCheck XDB
local
CVE-2019-2215HIGHsob ataque19 ago 2026
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALsob ataqueransomware19 ago 2026
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-34486HIGHsob ataque19 ago 2026
Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALsob ataqueransomware19 ago 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC1
halo cms plugin 1-request rce from a url, PoC + exploit chain
CVE-2026-67919CRITICAL19 ago 2026
An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri m
48RISCO
abrir
GitHub PoC
Proof of Concept for CVE-2026-19598 affecting Pods <= 3.3.9.
CVE-2026-19598CRITICAL19 ago 2026
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
63RISCO
abrir
GitHub PoC
JetBrains TeamCity On-Premises CVE-2026-63077 Emergency Hardening & Patch Runbook Package
CVE-2026-63077CRITICALsob ataque19 ago 2026
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
100RISCO
abrir
GitHub PoC
CVE-2026-64849 PoC
CVE-2026-64849CRITICALsob ataque19 ago 2026
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
98RISCO
abrir
GitHub PoC1
0xdeadroot/SCTPhantom-CVE-2026-64564
CVE-2026-64564CRITICAL19 ago 2026
sctp: don't free the ASCONF's own transport in DEL-IP processing
48RISCO
abrir
GitHub PoC
TP-Link Archer BE800 V1 — Parental Control LAN RCE
CVE-2026-9254HIGH18 ago 2026
Command Injection Vulnerability in Parent Control of Multiple TP-Link Archer Devices
41RISCO
abrir
GitHub PoC1
PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.
CVE-2026-44848CRITICAL18 ago 2026
Portainer: Missing authorization on Docker plugin endpoints allows host RCE
48RISCO
abrir
GitHub PoC
kaleth4/CVE-2026-64638
CVE-2026-64638HIGH18 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RISCO
abrir
GitHub PoC3
CVE-2026-65400
CVE-2026-65400CRITICALsob ataque18 ago 2026
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS
78RISCO
abrir
GitHub PoC10
Reproducible A/B lab + safe PoC for GitLab CVE-2026-19478 / CVE-2026-19650 (GraphQL @gl_introduced)
CVE-2026-19478CRITICAL18 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir
GitHub PoC
codeb0ssx/CVE-2026-64849-PoC
CVE-2026-64849CRITICALsob ataque18 ago 2026
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
98RISCO
abrir
GitHub PoC
0xROI/CVE-2026-77113
CVE-2026-77113MEDIUM18 ago 2026
Path Traversal Vulnerability in apport-unpack
33RISCO
abrir
GitHub PoC1
Windows Defender 0day vulnerability CVE-2026-69414 ShieldBreak
CVE-2026-69414HIGH18 ago 2026
Microsoft Defender Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC
Technical analysis and clean Java Thread Echo PoC for Oracle WebLogic Server vulnerability chain.
CVE-2020-14882CRITICALsob ataque18 ago 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC3
CVE-2026-14669 - PostgreSQL to_char() timezone abbreviation heap buffer overflow PoC; for authorized security testing
CVE-2026-14669HIGH18 ago 2026
PostgreSQL to_char heap buffer overflow executes arbitrary code
41RISCO
abrir
VulnCheck XDB
info-leak
CVE-2014-0160HIGHsob ataque18 ago 2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-19478CRITICAL18 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir
GitHub PoC11
CVE-2026-19478 PoC . Unauthenticated remote code-injection in GitLab's GraphQL layer
CVE-2026-19478CRITICAL18 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-19478CRITICAL18 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir
GitHub PoC
CVE-2026-43499 (GhostLock) — Linux kernel futex PI rt_mutex UAF ARM32 privilege escalation research targeting Huawei Watch 4 Pro (kernel 5.4.210)
CVE-2026-43499HIGH18 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
CVE-2026-19501 poc
CVE-2026-19501HIGH18 ago 2026
CVE-2026-19501
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-62593CRITICALsob ataque18 ago 2026
Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack
83RISCO
abrir
anteriorpágina 20 / 2.662próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.