Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.858exploits catalogados
36.825CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.346GitHub PoC 15.209VulnCheck XDB 8.944Nuclei 4.383Metasploit 3.501✓ só verificadosrecentespopularesrisco
79.858 exploits
Exploit-DB
webpack_devserver 5.2.5 - CSRF
webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints
33RISCO
abrir ↗GitHub PoC
CVE-2026-74943, Use after free in Firefox RasterImage (sec-high)
Use-after-free in the Graphics: ImageLib component
48RISCO
abrir ↗GitHub PoC
golang.org/x/text v0.33.0 backport of CVE-2026-56852 (GO-2026-5970) for Go 1.24
Infinite loop on invalid input in golang.org/x/text
41RISCO
abrir ↗GitHub PoC
Tracking CVE-2026-68138, the Linux kernel net/sched qdisc rate-table use-after-free
net/sched: serialize qdisc_rtab_list against concurrent get/put
41RISCO
abrir ↗GitHub PoC
CVE-2026-68138 Linux Local Privilege Escalation Exploit
net/sched: serialize qdisc_rtab_list against concurrent get/put
41RISCO
abrir ↗VulnCheck XDB
local
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "
71RISCO
abrir ↗GitHub PoC
iPad 8 iPadOS 26.3 AVE toolchain research (CVE-2026-64747 class)
A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iO
41RISCO
abrir ↗GitHub PoC
CVE-2026-15826, CVE-2026-15748
User Profile Builder <= 3.16.4 - Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter
63RISCO
abrir ↗GitHub PoC★ 6
A poc and write-up for CVE-2026-40345
deepmerge-ts: Stack exhaustion when merging recursive object graphs
41RISCO
abrir ↗GitHub PoC★ 1
ZendTo unauthenticated ClamAV CVE-2026-20217 RCE and default-profile root escalation reproduction
ClamAV PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerability
41RISCO
abrir ↗GitHub PoC★ 9
Kernel root exploit (CVE-2026-43499) for some 5.X devices (mostly Amazon)
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir ↗GitHub PoC
CVE-2026-74945, Uninitialized heap disclosure via a crafted web font (sec-high)
Information disclosure in the Graphics: Text component
33RISCO
abrir ↗VulnCheck XDB
initial-access
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir ↗GitHub PoC★ 1
CVE-2026-71518 — Typemill <2.26.0 unauthenticated authorization bypass in media file download (path-equivalent URL variants). Advisory + PoC.
Typemill < 2.26.0 Authorization Bypass via Media File Download Route
41RISCO
abrir ↗GitHub PoC
CVE-2026-74970, Fission site isolation bypass in Firefox WebRender
Site isolation issue in the Graphics component
33RISCO
abrir ↗GitHub PoC
PoC: changedetection.io unauthenticated OpenAPI schema disclosure (CVE-2026-71203, Medium 5.3)
changedetection.io - Missing Authentication on /api/v1/full-spec Discloses Full OpenAPI Schema
33RISCO
abrir ↗VulnCheck XDB
initial-access
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
48RISCO
abrir ↗GitHub PoC★ 1
CVE-2026-73678 — MindsDB Minds Platform unauthenticated RCE via scratchpad exec (CVSS 10.0). Verified end-to-end with real LLM
MindsDB Minds Platform v26.1.0 Unauthenticated RCE via scratchpad exec()
48RISCO
abrir ↗GitHub PoC
Public writeup, PoC, and emulation materials for CVE-2026-8508 affecting Zyxel captive-portal social login.
An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions throug
33RISCO
abrir ↗GitHub PoC★ 3
Using CVE-2026-43499 to root your Galaxy S24 Ultra(SM-S9280 ,(China / Hong Kong SAR / Taiwan))
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir ↗GitHub PoC★ 1
Non-destructive detector for CVE-2026-64638 (XSS2Shell) — WordPress pre-auth XSS reflection primitive
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISCO
abrir ↗GitHub PoC
PoC for CVE-2026-73847 - emlog AI Assistant CSRF to SQL execution to admin takeover (CVSS 6.8)
Emlog: Missing CSRF protection in AI Assistant execute_tool leads to full database compromise and admin account takeover
33RISCO
abrir ↗GitHub PoC
PoC: changedetection.io settings blind-merge mass assignment (CVE-2026-71204, Medium 6.3)
changedetection.io - Omitted Checkbox in /settings Save Silently Disables API Key Enforcement
33RISCO
abrir ↗GitHub PoC
CVE-2026-73633(S2-072)概念验证代码
Apache Struts: Unbounded read of a JSON request body
41RISCO
abrir ↗GitHub PoC★ 3
Public writeup, PoC, and emulation materials for CVE-2026-6837 affecting Zyxel export-cgi PKCS#12 export handling.
A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions
41RISCO
abrir ↗GitHub PoC
PoC: changedetection.io unlimited login brute-force, no rate limiting (CVE-2026-71205, Medium 6.5)
changedetection.io - No Rate Limiting on /login Enables Unlimited Password Brute-Force
33RISCO
abrir ↗GitHub PoC
PoC: Shiori JWT CheckToken never re-validates account state (CVE-2026-71206, High 8.2)
shiori - JWT CheckToken Never Re-Validates Account State, Allowing Stale-Privilege Access After Deletion or Demotion
41RISCO
abrir ↗GitHub PoC
a-mansilla/CVE-2020-6418
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.