Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.858exploits catalogados
36.825CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.346GitHub PoC 15.209VulnCheck XDB 8.944Nuclei 4.383Metasploit 3.501✓ só verificadosrecentespopularesrisco
79.858 exploits
GitHub PoC
Giangdurian/CVE-2021-3129
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir ↗GitHub PoC★ 19
Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
100RISCO
abrir ↗GitHub PoC★ 1
Guest-to-host KVM/x86 escape exploiting CVE-2026-64561, delivering a full PoC chain and analysis for security researchers.
KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
41RISCO
abrir ↗GitHub PoC★ 3
CVE-2026-64561
KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
41RISCO
abrir ↗GitHub PoC★ 6
SCTPhantom (CVE-2026-64564) SCTP ASCONF DEL-IP UAF LPE PoC (Debian 13 6.12.95) — community PoC mirror, MIT; for authorized security testing
sctp: don't free the ASCONF's own transport in DEL-IP processing
48RISCO
abrir ↗GitHub PoC★ 1
CVE-2026-64638
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISCO
abrir ↗GitHub PoC★ 5
CVE-2026-64638 — WordPress Pre-Auth Reflected XSS → RCE via DOM Clobbering + Application Password Theft + REST API Plugin Activation. Dual-mode PoC (XSS chain & direct).
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISCO
abrir ↗GitHub PoC★ 2
CVE-2026-64638
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISCO
abrir ↗GitHub PoC
Maintained Python 3 port of the original FUEL CMS CVE-2018-16763 proof-of-concept.
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir ↗GitHub PoC★ 1
ZSecur1ty/XSS2Shell-CVE-2026-64638
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISCO
abrir ↗GitHub PoC★ 6
Wordpress Pre-auth XSS to RCE exploit PoC (xss2shell & CVE-2026-64638)
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISCO
abrir ↗GitHub PoC★ 1
CVE-2026-11961 — UserRegistration: WordPress User Registration <= 5.2.2 Privilege Escalation. Misconfigured Membership Roles → Unauthenticated Admin Creation → Site Compromise. CVSS 8.1
User Registration & Membership < 5.2.3 - Unauthenticated Privilege Escalation via Unbound members_data Membership ID
41RISCO
abrir ↗GitHub PoC
Reproducible Docker lab for the Apache Tomcat JNDIRealm GSSAPI authentication bypass
Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind
41RISCO
abrir ↗GitHub PoC★ 3
Template Nuclei para detecção não-intrusiva do XSS2Shell, um parser differential pré-autenticado no WordPress Core que permite injeção de elementos DOM na página de login, servindo de base para uma cadeia de XSS → RCE.
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISCO
abrir ↗GitHub PoC
Hunt-Benito/go-without-bounds-cve-2026-67822-stack-overflow-in-tenda-w6-s-wifissidset
Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The fu
48RISCO
abrir ↗GitHub PoC★ 1
PoC for CVE-2026-71554 - h2 duplicate Host header request smuggling primitive (fixed in 4.4.1)
h2: Duplicate Host header could facilitate request smuggling
33RISCO
abrir ↗GitHub PoC★ 1
CVE-2026-44613
Apache Zeppelin: Cross-site request forgery in REST and WebSocket request handling
33RISCO
abrir ↗GitHub PoC
Hunt-Benito/one-multiply-too-many-cve-2026-70638-llama-cpp-android-jni-integer-overflow
llama.cpp b1886–b7445 Integer Overflow via new_1batch() in llama-android.cpp
41RISCO
abrir ↗GitHub PoC★ 53
XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE chain — PoC exploit + defensive audit tool + nuclei template
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISCO
abrir ↗GitHub PoC
PoC funcional de CVE-2026-64638 (XSS2Shell): cadena pre-auth XSS a RCE en WordPress Core. Laboratorio Docker + servidor atacante Python + análisis técnico y mitigación.
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISCO
abrir ↗GitHub PoC★ 7
LPE on Deb
sctp: don't free the ASCONF's own transport in DEL-IP processing
48RISCO
abrir ↗GitHub PoC★ 1
Advanced React Server Components RCE scanner for CVE-2025-55182. Features: multi-stage fingerprinting, vulnerability verification, DNS exfiltration, interactive shell, payload obfuscation, and professional reporting (JSON/HTML/PDF). Authorized testing only.
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗GitHub PoC
CVE-2026-39987 for marimo 0.20.4 PoC
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISCO
abrir ↗GitHub PoC
Wormable exploit for CVE-2026-57858
Cal.com Cal.diy 6.2.0 Stored XSS via BookingPageTagManager Analytics Tracking ID
48RISCO
abrir ↗GitHub PoC
jackson-databind 2026 年 11 条安全公告自查:扫源码注解降噪,告诉你真中几条;逐条求交集给出真正到位的版本(2.18.9/2.21.5/3.1.5,不是 advisory 上最常见的 2.21.4) CVE-2026-54515 / CVE-2026-54512
jackson-databind: Case-insensitive deserialization bypasses per-property @JsonIgnoreProperties
33RISCO
abrir ↗GitHub PoC
0init/CVE-2026-45185
Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing p
48RISCO
abrir ↗VulnCheck XDB
initial-access
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir ↗GitHub PoC
Exploit KVM/x86 guest-to-host escape CVE-2026-64561 with Zapscape, a proof-of-concept demonstrating hypervisor vulnerability.
KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
41RISCO
abrir ↗GitHub PoC
CVE-2026-64638
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.