Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
79.900 exploits
GitHub PoC
fastjson vulnerability scanner - detect fastjson in JARs and Spring Boot fat-JARs, check exposure to CVE-2026-16723, and verify whether you already run the official patch 1.2.84. Zero-dependency offline CLI. fastjson 漏洞检测与排查工具:一条命令扫描依赖,支持 fat-JAR 与 shaded 依赖,并判定是否已升到官方补丁版本 1.2.84。
CVE-2026-16723CRITICAL03 ago 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISCO
abrir
GitHub PoC
This tool exploits two critical vulnerabilities in Apache CouchDB: | CVE | Description | Severity | |-----|-------------|----------| | **CVE-2017-12635** | Privilege Escalation via JSON Parsing Bypass | 🔴 Critical | | **CVE-2017-12636** | Remote Code Execution via Query Server | 🔴 Critical |
CVE-2017-1263503 ago 2026
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RISCO
abrir
GitHub PoC
SQL injection in PyAthena via DefaultParameterFormatter (CVE-2026-65321)
CVE-2026-65321CRITICAL03 ago 2026
PyAthena SQL Injection via DefaultParameterFormatter DELETE/CTAS
48RISCO
abrir
VulnCheck XDB
local
CVE-2022-22706HIGHsob ataque03 ago 2026
Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects
71RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL03 ago 2026
Authorization Bypass in Next.js Middleware
85RISCO
abrir
VulnCheck XDB
local
CVE-2023-21768HIGH03 ago 2026
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RISCO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-9997-VPN-Split-Tunneling-Bypass-via-DHCP-Option-Injection
CVE-2026-9997HIGH03 ago 2026
Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the rende
41RISCO
abrir
VulnCheck XDB
info-leak
CVE-2018-999503 ago 2026
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir
VulnCheck XDB
info-leak
CVE-2017-7921CRITICALsob ataque03 ago 2026
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-39987CRITICALsob ataque03 ago 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISCO
abrir
GitHub PoC2
CVE-2026-66066 (KindaRails2Shell) PoC - Rails Active Storage/libvips arbitrary file read to RCE; for authorized security testing
CVE-2026-66066CRITICAL03 ago 2026
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RISCO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALsob ataque03 ago 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
VulnCheck XDB
info-leak
CVE-2026-60137MEDIUMsob ataque03 ago 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-57819CRITICALsob ataque03 ago 2026
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir
GitHub PoC1
Found a 0-Day in Ghidra: Shared Project File Became a Code Execution Vector
CVE-2026-18718HIGH03 ago 2026
Ghidra Swift Demangler Analyzer Arbitrary Code Execution via Project State
41RISCO
abrir
GitHub PoC3
CVE-2026-63223 PoC — CodeIgniter 4 is_image/mime_in File Upload RCE (CVSS 9.8). Unauthenticated remote code execution via unrestricted file upload bypass using image magic bytes. Fixed in v4.7.4.
CVE-2026-63223CRITICAL03 ago 2026
CodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules
48RISCO
abrir
GitHub PoC
CVE-2026-52887 — NocoBase SQL injection -> PostgreSQL-superuser RCE (myInAppChannels:list filter, CVSS 10.0). Author PoC + source analysis + docker lab.
CVE-2026-52887CRITICAL03 ago 2026
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
48RISCO
abrir
GitHub PoC
0xdak/CVE-2026-69083_exploit
CVE-2026-69083CRITICAL03 ago 2026
SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContent
48RISCO
abrir
GitHub PoC
DharmarajPS/pdfjs-cve-2024-4367-poc
CVE-2024-4367MEDIUM03 ago 2026
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir
GitHub PoC
Code injection (RCE) in datamodel-code-generator via unvalidated customBasePath (CVE-2026-63720)
CVE-2026-63720HIGH03 ago 2026
datamodel-code-generator Code Injection via Unvalidated customBasePath Schema Field
41RISCO
abrir
GitHub PoC
Procjevt/CVE-2026-63030
CVE-2026-63030CRITICALsob ataque03 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC
sam00/POC-CVE-2026-54121-Certighost
CVE-2026-54121HIGH03 ago 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-8888-Printer-Firmware-Unsigned-Update-via-HTTP
CVE-2026-8888HIGH03 ago 2026
CVE-2026-8888
41RISCO
abrir
GitHub PoC1
CY376 Blue Team project — pfSense DMZ, Suricata IDS/IPS, and automated host hardening against CVE-2014-6271
CVE-2014-6271CRITICALsob ataque03 ago 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-11103-GraphQL-Batching-Alias-Rate-Limit-Bypass
CVE-2026-11103HIGH03 ago 2026
Inappropriate implementation in Installer in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to
41RISCO
abrir
GitHub PoC
Unauthenticated arbitrary file read in Flowise (< 2.2.4) via path traversal in getFileFromStorage (storageUtils.ts). Caused by un-sanitized file path combined with mass-assignment in PUT /api/v1/document-store/store/:id. Allows full compromise via /root/.flowise/encryption.key read. Distinct from CVE-2025-71338 (fixed in 2.2.4).
CVE-2025-71338CRITICAL03 ago 2026
Flowise - Arbitrary File Write to Remote Code Execution via document-store API
48RISCO
abrir
GitHub PoC17
CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)
CVE-2026-60004CRITICALsob ataque03 ago 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
100RISCO
abrir
GitHub PoC
wpsqli full SQLi extractor + dumper for CVE-2026-60137
CVE-2026-60137MEDIUMsob ataque03 ago 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISCO
abrir
GitHub PoC
CVE-2026-46243
CVE-2026-46243HIGH03 ago 2026
smb: client: reject userspace cifs.spnego descriptions
41RISCO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-11105-Stack-Buffer-Overflow-in-Custom-Base64-Decoder
CVE-2026-11105MEDIUM03 ago 2026
Insufficient validation of untrusted input in WebUI in Google Chrome prior to 149.0.7827.53 allowed a remote attacker wh
33RISCO
abrir
anteriorpágina 37 / 2.664próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.