Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.858exploits catalogados
36.825CVEs com exploração pública
24.695testados em laboratório
79.858 exploits
GitHub PoC1
Windows Defender 0day vulnerability CVE-2026-69414 ShieldBreak
CVE-2026-69414HIGH18 ago 2026
Microsoft Defender Elevation of Privilege Vulnerability
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-19478CRITICAL18 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir
GitHub PoC
IhsSpotlight/HeartBleed-CVE-2014-0160--SCRIPTS-python3
CVE-2014-0160HIGHsob ataque18 ago 2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC
0xROI/CVE-2026-77113
CVE-2026-77113MEDIUM18 ago 2026
Path Traversal Vulnerability in apport-unpack
33RISCO
abrir
GitHub PoC3
CVE-2026-15748 - Unauthenticated RCE exploit for WordPress Forminator plugin (≤1.56.1). Automated detection, deep crawl, nonce extraction, and safe upload test. For authorized testing only.
CVE-2026-15748CRITICAL18 ago 2026
Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration
48RISCO
abrir
GitHub PoC11
CVE-2026-19478 PoC . Unauthenticated remote code-injection in GitLab's GraphQL layer
CVE-2026-19478CRITICAL18 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir
GitHub PoC3
CVE-2026-14669 - PostgreSQL to_char() timezone abbreviation heap buffer overflow PoC; for authorized security testing
CVE-2026-14669HIGH18 ago 2026
PostgreSQL to_char heap buffer overflow executes arbitrary code
41RISCO
abrir
VulnCheck XDB
info-leak
CVE-2014-0160HIGHsob ataque18 ago 2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC3
CVE-2026-65400
CVE-2026-65400CRITICALsob ataque18 ago 2026
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS
78RISCO
abrir
GitHub PoC
katranSefa/CVE-2026-13714
CVE-2026-13714CRITICAL17 ago 2026
Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
48RISCO
abrir
GitHub PoC
CVE-2026-19650, CVE-2026-19478 - Draft or TODO
CVE-2026-19650HIGH17 ago 2026
Cross-Site Request Forgery (CSRF) in GitLab
41RISCO
abrir
GitHub PoC
CVE-2026-33017, vuln in langflow.
CVE-2026-33017CRITICALsob ataque17 ago 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-20896CRITICAL17 ago 2026
Gitea Docker image trusts spoofable reverse-proxy headers by default
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALsob ataqueransomware17 ago 2026
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
CVE-2026-59310 PoC
CVE-2026-59310CRITICALsob ataque17 ago 2026
vCenter directory-traversal vulnerability
90RISCO
abrir
Exploit-DB
NanaZip 6.5 - DoS
CVE-2026-55780LOWdoswindows17 ago 2026
NanaZip: Uncaught exception / unbounded allocation in NanaZip .NET single-file Extract() via unvalidated entry Size
28RISCO
abrir
GitHub PoC
iPad 8 iPadOS 26.3 AVE toolchain research (CVE-2026-64747 class)
CVE-2026-64747HIGH17 ago 2026
A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iO
41RISCO
abrir
GitHub PoC
Tracking CVE-2026-68138, the Linux kernel net/sched qdisc rate-table use-after-free
CVE-2026-68138HIGH17 ago 2026
net/sched: serialize qdisc_rtab_list against concurrent get/put
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-59310CRITICALsob ataque17 ago 2026
vCenter directory-traversal vulnerability
90RISCO
abrir
GitHub PoC
POC for CVE-2026-41042
CVE-2026-41042CRITICAL17 ago 2026
Apache Gravitino: Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter
63RISCO
abrir
GitHub PoC
CVE-2026-59310
CVE-2026-59310CRITICALsob ataque17 ago 2026
vCenter directory-traversal vulnerability
90RISCO
abrir
GitHub PoC1
CVE-2026-71518 — Typemill <2.26.0 unauthenticated authorization bypass in media file download (path-equivalent URL variants). Advisory + PoC.
CVE-2026-71518HIGH17 ago 2026
Typemill < 2.26.0 Authorization Bypass via Media File Download Route
41RISCO
abrir
Exploit-DB
webpack_devserver 5.2.5 - CSRF
CVE-2026-14620MEDIUMwebappsmultiple17 ago 2026
webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints
33RISCO
abrir
GitHub PoC1
ZendTo unauthenticated ClamAV CVE-2026-20217 RCE and default-profile root escalation reproduction
CVE-2026-20217HIGH17 ago 2026
ClamAV PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerability
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware17 ago 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
CVE-2026-74945, Uninitialized heap disclosure via a crafted web font (sec-high)
CVE-2026-74945MEDIUM17 ago 2026
Information disclosure in the Graphics: Text component
33RISCO
abrir
Exploit-DB
Joomla JCE_2.9.15 - Remote Code Execution
CVE-2026-48907CRITICALsob ataquewebappsmultiple17 ago 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISCO
abrir
GitHub PoC
CVE-2026-74970, Fission site isolation bypass in Firefox WebRender
CVE-2026-74970MEDIUM17 ago 2026
Site isolation issue in the Graphics component
33RISCO
abrir
GitHub PoC19
Linux Binder binder_free_transaction() process-lifetime use-after-free (CVE-2026-64468): unprivileged PoC + x86_64 LPE. Authorised security research.
CVE-2026-64468HIGH17 ago 2026
binder: fix UAF in binder_free_transaction()
41RISCO
abrir
Exploit-DB
Nmap 7.99 - Extension Header Integer Underflow
CVE-2026-58058MEDIUMdosmultiple17 ago 2026
Nmap - Integer Underflow in IPv6 Extension Header Parsing
33RISCO
abrir
anteriorpágina 21 / 2.662próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.