Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.858exploits catalogados
36.825CVEs com exploração pública
24.695testados em laboratório
79.858 exploits
GitHub PoC
Full root in kernel domain with selinux permissive **MOVED TO THIS REPO https://github.com/CamsShaft/IonStack-S22 WILL DELETE THIS ONE SOON**
CVE-2026-43499HIGH15 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
CVE-2026-43499 research port for Galaxy Z Fold4 SM-F936W F936WVLU1AVGA (in progress)
CVE-2026-43499HIGH15 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC4
CVE-2026-72898 PoC : Metabase Unauthenticated SQL Injection
CVE-2026-72898CRITICALsob ataque15 ago 2026
Metabase SQL injection via password reset endpoint
100RISCO
abrir
GitHub PoC
OpenMed < 1.5.2 unauthenticated RCE via PII privacy-filter model loading and trust_remote_code=True
CVE-2026-47117CRITICAL15 ago 2026
OpenMed < 1.5.2 Remote Code Execution via PII Model Loading
48RISCO
abrir
GitHub PoC2
PoC for CVE-2026-72898
CVE-2026-72898CRITICALsob ataque15 ago 2026
Metabase SQL injection via password reset endpoint
100RISCO
abrir
GitHub PoC
Username Enumeration via Authentication Timing Side-Channel in PaperCut NG
CVE-2026-8794MEDIUM15 ago 2026
PaperCut NG/MF: User enumeration via timing attack
33RISCO
abrir
GitHub PoC
uproot <= 5.7.4 code injection via unsafe Python source generation from ROOT TStreamerInfo metadata.
CVE-2026-9147HIGH15 ago 2026
uproot 5.7.4 and prior Code Injection via TStreamerInfo Metadata
41RISCO
abrir
GitHub PoC
ghostpels/CVE-2026-13610
CVE-2026-13610HIGH15 ago 2026
KiviCare < 4.5.2 - Unauthenticated Privilege Escalation via Registration
41RISCO
abrir
GitHub PoC470
CVE-2026-9830 Proof of Concept
CVE-2026-9830HIGH15 ago 2026
BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback Bug
41RISCO
abrir
GitHub PoC
CVE-2026-17544: PHP bcmath OOB write → universal memory-only RCE & disable_functions/open_basedir bypass. Offset-free runtime resolver. Verified on PHP 8.4.x / 8.5.x.
CVE-2026-17544HIGH15 ago 2026
Out-of-bounds write in bccomp() via crafted operand and scale
41RISCO
abrir
GitHub PoC
jeffmarlonmandela/CVE-2021-4034-PwnKit
CVE-2021-4034HIGHsob ataqueransomware14 ago 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
Kentox493/CVE-2026-46300_Fragnesia
CVE-2026-46300HIGH14 ago 2026
net: skbuff: preserve shared-frag marker during coalescing
56RISCO
abrir
GitHub PoC5
KSuRoot 2.2.0 — One-click KernelSU rooting based on CVE-2026-43499. Synced from Root-My-Galaxy v0.2.6 with custom payload (.so) import. Mod by hmascs
CVE-2026-43499HIGH14 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC62
CVE-2026-8452 PreAuth RCE
CVE-2026-8452HIGHsob ataque14 ago 2026
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
71RISCO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataqueransomware14 ago 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALsob ataque14 ago 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALsob ataque14 ago 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir
GitHub PoC
PoC for RefluXFS
CVE-2026-64600HIGH14 ago 2026
xfs: resample the data fork mapping after cycling ILOCK
41RISCO
abrir
GitHub PoC
KovachVL/CVE-2026-54356
CVE-2026-54356HIGH14 ago 2026
Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`
41RISCO
abrir
GitHub PoC
CVE-2026-54433 Roundcube plain-text email stored XSS PoC
CVE-2026-54433HIGH14 ago 2026
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plai
41RISCO
abrir
VulnCheck XDB
info-leak
CVE-2021-41773HIGHsob ataqueransomware14 ago 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
VulnCheck XDB
info-leak
CVE-2021-41773HIGHsob ataqueransomware14 ago 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
CVE-2026-53365
CVE-2026-53365HIGH14 ago 2026
vsock/virtio: fix zerocopy completion for multi-skb sends
41RISCO
abrir
GitHub PoC
PoC funcional de CVE-2026-52715 (GeoLeak): SQLi no autenticada en GEO my WordPress <= 4.5.5 via swlatlng/nelatlng. Laboratorio Docker + exploit time-based/boolean-based + exfiltracion sin comas en payload.
CVE-2026-52715CRITICAL14 ago 2026
WordPress GEO my WordPress plugin <= 4.5.5 - SQL Injection vulnerability
48RISCO
abrir
GitHub PoC
CVE-2026-72550 — Friendica Unauthenticated Stacked-Query SQL Injection PoC (CVSS 9.8 Critical)
CVE-2026-72550CRITICAL14 ago 2026
Friendica Friendica - SQL Injection
48RISCO
abrir
GitHub PoC1
This package is not a complete root. It flips SELinux to Permissive and holds reclaim long enough for follow-on work. Host `uid=0` is not achieved here.
CVE-2026-43499HIGH14 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-31816CRITICAL14 ago 2026
Budibase Universal Auth Bypass via Webhook Query Param Injection
68RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALsob ataque14 ago 2026
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
GitHub PoC
CS50's Introduction to Cybersecurity final project on React2Shell (CVE-2025-55182)
CVE-2025-55182CRITICALsob ataqueransomware14 ago 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Mohaimenul370/Perform-an-RDP-exploitation-using-the-BlueKeep-vulnerability-CVE-2019-0708-on-Windows
CVE-2019-0708CRITICALsob ataqueransomware14 ago 2026
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
anteriorpágina 24 / 2.662próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.