Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.360GitHub PoC 15.228VulnCheck XDB 8.946Nuclei 4.390Metasploit 3.501✓ só verificadosrecentespopularesrisco
79.894 exploits
VulnCheck XDB
initial-access
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RISCO
abrir ↗VulnCheck XDB
initial-access
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir ↗GitHub PoC
0xdak/CVE-2026-44024_exploit
Fluentd: Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
48RISCO
abrir ↗GitHub PoC
minwunn/wp2shell-CVE-2026-63030
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir ↗GitHub PoC★ 916
CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir ↗VulnCheck XDB
client-side
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISCO
abrir ↗GitHub PoC
Offline scanner telling you which of the 2026 Bouncy Castle CVEs actually apply to you - across BC, BC-LTS and BC-FJA (FIPS), which do not share a version scheme. CVE-2026-58062 / CVE-2026-8763 / CVE-2026-59650 / CVE-2026-59638
Stapled OCSP response accepted without binding to the checked certificate
48RISCO
abrir ↗GitHub PoC
Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything cross tenant.
In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication)
48RISCO
abrir ↗VulnCheck XDB
initial-access
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
100RISCO
abrir ↗GitHub PoC
Detection rules and analysis for Dirty Frag (CVE-2026-43284/CVE-2026-43500) Linux kernel LPE vulnerability. Based on community research and health probe configurations.
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISCO
abrir ↗GitHub PoC
qflksheep/CVE-2026-67689-FineAdmin.Mvc-vulnerability
SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `or
48RISCO
abrir ↗GitHub PoC★ 1
CVE-2026-42533: pre-auth nginx heap overflow and info leak from PCRE capture clobbering in the map/script engine, chained to RCE.
NGINX Map directive and Regex matching vulnerability
48RISCO
abrir ↗VulnCheck XDB
initial-access
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir ↗GitHub PoC★ 1
rmhowe425/PoC-CVE-2026-9198
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISCO
abrir ↗VulnCheck XDB
info-leak
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISCO
abrir ↗GitHub PoC★ 13
PoCs for Wellbia XIGNCODE3 anti-cheat xhunter driver family - xhunter1.sys v2023.12.7.78 and xhunter2.sys v2026.6.1.192 (CVE-2026-15430, CVE-2026-3609).
CVE-2026-15430
33RISCO
abrir ↗GitHub PoC
ICS-Park Smart Park Management System v2.0
Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/rol
41RISCO
abrir ↗GitHub PoC
x-znn/CVE-2026-63030
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir ↗GitHub PoC★ 2
CVE-2026-63223 — CI4RCE: CodeIgniter 4 is_image/mime_in File Upload RCE. Magic bytes bypass (getExtension vs getClientExtension). CVSS 9.8 | CWE-434 | CI4 < 4.7.4
CodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules
48RISCO
abrir ↗GitHub PoC
0xdak/CVE-2026-52680_exploit
Apache Kyuubi: REST batch multipart upload path traversal allows controlled file write
48RISCO
abrir ↗GitHub PoC
Shams-Ul-Mehmood/CVE-2021-41773-Exploit
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗GitHub PoC
0xdak/CVE-2026-59243_exploit
Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)
48RISCO
abrir ↗GitHub PoC
Foxer131/CVE-2026-70481
Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages
33RISCO
abrir ↗GitHub PoC★ 1
JVBotelho/cve-2026-69243-poc-aiohttp-smuggling
AIOHTTP: HTTP request smuggling via WebSocket upgrade
33RISCO
abrir ↗GitHub PoC★ 1
pgAdmin 4 Import/Export RCE (CVE-2026-17566) PoC - TO PROGRAM injection via backslash-escape mismatch
pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)
48RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.