Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.526exploits catalogados
36.593CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.152GitHub PoC 15.158VulnCheck XDB 8.883Nuclei 4.365Metasploit 3.493✓ só verificadosrecentespopularesrisco
14.991 exploits
GitHub PoC★ 58
CVE-2026-63030, CVE-2026-60137, wp2shell scanner
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir ↗GitHub PoC
Reproducer for CVE-2026-47323: Apache Camel CXF/Knative HeaderFilterStrategy missing inbound filtering, enabling Camel control-header injection (RCE via camel-exec) through CXF-RS/CXF-SOAP/Knative endpoints (fixed in 4.14.6/4.18.2/4.19.0)
Apache Camel: Camel-CXF Message Header Injection via Missing Inbound Filtering
48RISCO
abrir ↗GitHub PoC★ 865
KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir ↗GitHub PoC★ 1
bekwiner/cve-2026-47777
Mastodon has a consent-check bypass in its remote Collections
41RISCO
abrir ↗GitHub PoC
hg0434hongzh0/CVE-2026-14266
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability
41RISCO
abrir ↗GitHub PoC
Python port of the CVE-2023-23752 exploit — Joomla! < 4.2.8 unauthenticated information disclosure (user list + DB credentials leak)
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗GitHub PoC★ 4
HIKRAVEN - Advanced Hikvision Security Assessment Platform for professional penetration testing. Detects 12+ CVEs including CVE-2021-36260 (CRITICAL), tests default credentials, performs network discovery, and generates professional security reports. For authorized security testing only! 🛡️🔒
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISCO
abrir ↗GitHub PoC
CVE-2026-38526 Exploit | by infrar3d
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RISCO
abrir ↗GitHub PoC
Pentest completo sobre Metasploitable: recon con nmap, explotación con Metasploit (CVE-2007-2447), extracción y cracking de credenciales, persistencia SSH
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir ↗GitHub PoC★ 2
2932796375github/CVE-2026-43499_OPPO-MT6835
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir ↗GitHub PoC
tungduongNT/CVE-2014-0160.
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir ↗GitHub PoC
CVE-2026-43499 exploit with OnePlus Ace3 support
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir ↗GitHub PoC★ 1
CVE-2026-33017 Exploit | by infrar3d
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir ↗GitHub PoC
sadb98523-eng/CVE-2026-13001
Podlove Podcast Publisher <= 4.5.1 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter
63RISCO
abrir ↗GitHub PoC★ 2
syxlox/CVE-2026-50369
Windows Remote Desktop Services Elevation of Privilege Vulnerability
41RISCO
abrir ↗GitHub PoC★ 5
Next.js RSC RCE Exploit Tool (CVE-2025-55182)
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗GitHub PoC★ 1
Super Forms Unauthenticated File Upload RCE | CVSS 9.8
Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)
63RISCO
abrir ↗GitHub PoC
Reproducer for CVE-2026-46726: Apache Camel camel-vertx-websocket unfiltered inbound header injection enabling SSRF and secret disclosure via property-placeholder resolution (fixed in 4.14.8/4.18.3/4.21.0)
Apache Camel Vertx Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers
41RISCO
abrir ↗GitHub PoC
Reproducer for CVE-2026-46592: Apache Camel camel-cxf operationName header injection redirecting the invoked SOAP operation (confused deputy) from a read to a destructive one (fixed in 4.14.8/4.18.3/4.21.0)
Apache Camel: Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed names (operationName, operationNamespace) that bypass the HTTP header filter, allowing an HTTP client to redirect the invoked SOAP operation
41RISCO
abrir ↗GitHub PoC★ 2
PoC tools for CVE-2026-58457: Unauthenticated OS Command Injection leading to remote root on Shenzhen Aitemi M300 Wi-Fi Repeater (MT02). Includes exploit, validator, payload generator, and Metasploit module. For educational and authorized pentesting only.
Shenzhen Aitemi M300 MT02 Unauthenticated OS Command Injection via protocol.csp
48RISCO
abrir ↗GitHub PoC★ 1
CVE-2024-25600 - Unauthenticated RCE exploit for WordPress Bricks Builder Theme. Advanced exploitation framework with interactive shell, reverse shells, file upload/download, async scanning, stealth mode, proxy support, and multi-threaded vulnerability scanning. For authorized security testing only.
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir ↗GitHub PoC★ 6
Proof of concept for CVE-2026-54992, an MSMQ remote-read integer overflow
Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability
41RISCO
abrir ↗GitHub PoC
uname1able/CVE-2025-21333
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RISCO
abrir ↗GitHub PoC
bibotai/secveri-cve-2026-50011-positive
Netty has unbounded pre-allocation in RedisArrayAggregator from RESP array length
41RISCO
abrir ↗GitHub PoC
bibotai/secveri-cve-2026-50011-negative
Netty has unbounded pre-allocation in RedisArrayAggregator from RESP array length
41RISCO
abrir ↗GitHub PoC
Unofficial Bash IoC checker for SonicWall SMA1000 appliances affected by actively exploited CVE-2026-15409 and CVE-2026-15410.
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RISCO
abrir ↗GitHub PoC★ 6
CVE-2026-43499 GhostLock exploit for Redmi K70 Ultra (rothko) - data-only physmap overwrite
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir ↗GitHub PoC
Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗GitHub PoC★ 40
Standalone CVE-2026-43499 PoC for Galaxy S25 Ultra SM-S938N S938NKSUACZF1
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir ↗GitHub PoC
CVE-2026-43499 exploit reproduction on jinghu (Xiaomi Pad 7 Ultra)
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.