Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.360GitHub PoC 15.228VulnCheck XDB 8.946Nuclei 4.390Metasploit 3.501✓ só verificadosrecentespopularesrisco
79.900 exploits
GitHub PoC
CVE-2026-12940 — Langflow OSS <=1.10.1 unauthenticated RCE via MCP stdio environment-variable injection (SHELLOPTS/PS4). Author PoC + source analysis + lab.
Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoints
48RISCO
abrir ↗GitHub PoC
0xdak/CVE-2026-69083_exploit
SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContent
48RISCO
abrir ↗GitHub PoC★ 17
CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
100RISCO
abrir ↗GitHub PoC
Procjevt/CVE-2026-63030
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-9090-Modbus-TCP-Write-to-Read-Only-Coils-via-Function-Code-Spoofing
CVE-2026-9090
48RISCO
abrir ↗GitHub PoC
CVE-2026-9848 is an Unauthenticated SQL Injection (SQLi) vulnerability affecting the WP Ticket (Customer Support Ticket System & Helpdesk) plugin for WordPress up to and including version 6.0.4.
WP Ticket <= 6.0.4 - Unauthenticated SQL Injection via WordPress Search 's' Parameter
41RISCO
abrir ↗GitHub PoC
wpsqli full SQLi extractor + dumper for CVE-2026-60137
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISCO
abrir ↗GitHub PoC
CVE-2026-52887 — NocoBase SQL injection -> PostgreSQL-superuser RCE (myInAppChannels:list filter, CVSS 10.0). Author PoC + source analysis + docker lab.
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
48RISCO
abrir ↗GitHub PoC
CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
100RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-9998-Insecure-Deserialization-in-Blockchain-Oracle
Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the rend
41RISCO
abrir ↗GitHub PoC
Unauthenticated arbitrary file read in Flowise (< 2.2.4) via path traversal in getFileFromStorage (storageUtils.ts). Caused by un-sanitized file path combined with mass-assignment in PUT /api/v1/document-store/store/:id. Allows full compromise via /root/.flowise/encryption.key read. Distinct from CVE-2025-71338 (fixed in 2.2.4).
Flowise - Arbitrary File Write to Remote Code Execution via document-store API
48RISCO
abrir ↗VulnCheck XDB
initial-access
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RISCO
abrir ↗GitHub PoC★ 11
proof-of-concept scripts for 2 unauthenticated RCEs in Samba (CVE-2026-4408 & CVE-2026-4480) and local privilege escalation in TelnetD (CVE-2026-28372)
Samba: remote code execution in samr
48RISCO
abrir ↗GitHub PoC
CVE-2026-17583 - Draft
Thermo Fisher Applied Biosystems Genetic Analyzers Missing Support for Integrity Check
41RISCO
abrir ↗GitHub PoC★ 2
GhostLock (CVE-2026-43499) kernel exploit port for REDMI K90 Pro Max Taiwan firmware (myron, WPMTWXM) — offsets, build guide, prebuilt binary
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-9999-Serverless-Event-Injection-to-Code-Overwrite
Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execu
41RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11105-Stack-Buffer-Overflow-in-Custom-Base64-Decoder
Insufficient validation of untrusted input in WebUI in Google Chrome prior to 149.0.7827.53 allowed a remote attacker wh
33RISCO
abrir ↗GitHub PoC
DharmarajPS/pdfjs-cve-2024-4367-poc
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
100RISCO
abrir ↗VulnCheck XDB
initial-access
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
100RISCO
abrir ↗GitHub PoC
OXDEV-77637 repro fixture: uv workspace whose transitive CVE (starlette 0.25.0 / CVE-2026-48710) is dropped when the lean clone omits workspace-member pyproject.toml. Tag: repro-OXDEV-77637
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
90RISCO
abrir ↗GitHub PoC★ 101
Proof-of-concept exploit chain (CVE-2026-47301) for Microsoft Configuration Manager (SCCM), combining a broken access, CAB arbitrary-write path traversal, certificate verification bypass, and DLL hijacking to achieve SYSTEM-level code execution.
Configuration Manager Elevation of Privilege Vulnerability
41RISCO
abrir ↗GitHub PoC
Manage BitLocker recovery keys, unlock encrypted drives, and monitor encryption status with this lightweight Windows utility.
Windows BitLocker Security Feature Bypass Vulnerability
33RISCO
abrir ↗GitHub PoC
SQL injection in PyAthena via DefaultParameterFormatter (CVE-2026-65321)
PyAthena SQL Injection via DefaultParameterFormatter DELETE/CTAS
48RISCO
abrir ↗GitHub PoC
This tool exploits two critical vulnerabilities in Apache CouchDB: | CVE | Description | Severity | |-----|-------------|----------| | **CVE-2017-12635** | Privilege Escalation via JSON Parsing Bypass | 🔴 Critical | | **CVE-2017-12636** | Remote Code Execution via Query Server | 🔴 Critical |
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RISCO
abrir ↗GitHub PoC★ 1
Bu laboratuvar ortamını sıfırdan kendim oluşturdum. Next.js uygulaması içerisinde giriş, ana sayfa ve admin sayfalarını hazırladım. Middleware ile yetkilendirme mekanizmasını kurduktan sonra Burp Suite kullanarak CVE-2025-29927 zafiyetini kontrollü ortamda gösterdim.
Authorization Bypass in Next.js Middleware
85RISCO
abrir ↗VulnCheck XDB
initial-access
Kestra: Unauthenticated RCE via /configs path-suffix auth-filter bypass
63RISCO
abrir ↗GitHub PoC
fastjson vulnerability scanner - detect fastjson in JARs and Spring Boot fat-JARs, check exposure to CVE-2026-16723, and verify whether you already run the official patch 1.2.84. Zero-dependency offline CLI. fastjson 漏洞检测与排查工具:一条命令扫描依赖,支持 fat-JAR 与 shaded 依赖,并判定是否已升到官方补丁版本 1.2.84。
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISCO
abrir ↗GitHub PoC★ 2
CVE-2026-16232 (Check Point SmartConsole authentication bypass) PoC - unauth to admin; for authorized security testing
Authentication Bypass in the SmartConsole Login Process Using an Application Token
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.