Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.893exploits catalogados
36.846CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.360GitHub PoC 15.221VulnCheck XDB 8.946Nuclei 4.390Metasploit 3.501✓ só verificadosrecentespopularesrisco
79.886 exploits
GitHub PoC
Shams-Ul-Mehmood/CVE-2018-7600-Drupalgeddon2-RCE
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir ↗GitHub PoC★ 1
woshidashabi1126/CVE-2026-70553-PoC
MaxSite CMS Unauthenticated RCE via Install Endpoint
48RISCO
abrir ↗GitHub PoC★ 1
CVE-2026-0163 Exploit
In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to rem
48RISCO
abrir ↗GitHub PoC★ 1
Joomla RSFiles 未授权文件上传CVE-2026-57827检测&利用脚本
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12
63RISCO
abrir ↗GitHub PoC
The Joomla extension PhocaCommander is vulnerable to Path Traversal in delete, copy, move actions - CVSS 6.4
Joomla Extension - phoca.cz - Path traversal vulnerability in Phoca Commander 1.0.0-6.1.3
33RISCO
abrir ↗GitHub PoC
The Joomla extension PhocaCommander is vulnerable to Path Traversal in the getSource function - CVSS 8.2
Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3
41RISCO
abrir ↗GitHub PoC
0xdak/CVE-2026-69098_exploit
kotaemon 0.12.0 Unauthenticated Remote Code Execution via Insecure Deserialization
48RISCO
abrir ↗GitHub PoC★ 4
Proof of concept for CVE-2026-18649, a remote denial of service vulnerability in GStreamer's H.264 RTP depayloader (rtph264depay).
Gstreamer1-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay rtp depayloaders
41RISCO
abrir ↗GitHub PoC
The Joomla extension PhocaCommander is vulnerable to Path Traversal in the file upload action - CVSS 6.1
Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3
33RISCO
abrir ↗VulnCheck XDB
info-leak
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISCO
abrir ↗GitHub PoC★ 1
Craft CMS CVE-2025-32432 command runner adapted from Nicolas Bourras and Orange Cyberdefense research
Craft CMS Allows Remote Code Execution
100RISCO
abrir ↗VulnCheck XDB
initial-access
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir ↗VulnCheck XDB
initial-access
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RISCO
abrir ↗VulnCheck XDB
initial-access
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir ↗GitHub PoC★ 916
CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir ↗GitHub PoC
Offline scanner telling you which of the 2026 Bouncy Castle CVEs actually apply to you - across BC, BC-LTS and BC-FJA (FIPS), which do not share a version scheme. CVE-2026-58062 / CVE-2026-8763 / CVE-2026-59650 / CVE-2026-59638
Stapled OCSP response accepted without binding to the checked certificate
48RISCO
abrir ↗VulnCheck XDB
initial-access
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISCO
abrir ↗VulnCheck XDB
client-side
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir ↗GitHub PoC
Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything cross tenant.
In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication)
48RISCO
abrir ↗GitHub PoC
Detection rules and analysis for Dirty Frag (CVE-2026-43284/CVE-2026-43500) Linux kernel LPE vulnerability. Based on community research and health probe configurations.
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISCO
abrir ↗GitHub PoC
Non-destructive proof-of-concept and verification harness for CVE-2026-60137, a blind SQL injection in WordPress core (`WP_Query::author__not_in`), reachable via the REST API's `author_exclude` parameter.
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISCO
abrir ↗GitHub PoC
qflksheep/CVE-2026-67689-FineAdmin.Mvc-vulnerability
SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `or
48RISCO
abrir ↗GitHub PoC
PoC + analysis for CVE-2026-54917 — SeaweedFS S3 gateway cross-bucket path traversal (CVSS 10.0, <4.30). Read/write any bucket via .. in the object key.
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access
56RISCO
abrir ↗GitHub PoC★ 1
rmhowe425/PoC-CVE-2026-9198
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISCO
abrir ↗GitHub PoC
ICS-Park Smart Park Management System v2.0
Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/rol
41RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.