Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.697exploits catalogados
36.715CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.264GitHub PoC 15.172VulnCheck XDB 8.920Nuclei 4.373Metasploit 3.493✓ só verificadosrecentespopularesrisco
79.697 exploits
VulnCheck XDB
initial-access
An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration a
56RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
100RISCO
abrir ↗GitHub PoC
Conceptual C++ patch and structural analysis for CVE-2026-85046, a critical type confusion zero-day vulnerability in Google Chrome's V8 engine
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside
71RISCO
abrir ↗VulnCheck XDB
initial-access
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
100RISCO
abrir ↗GitHub PoC
Recovery notes for proxmox advisory ID: PSA-2026-00043-1 (CVE-2023-54391)
Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter
63RISCO
abrir ↗Exploit-DB
FreePBX 17.0.2 - Remote Code Execution (RCE)
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir ↗GitHub PoC
CVE-2026-64788 PoC — IOGPUFamily Use-After-Free (iOS 26.6 / 23G71)
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe
33RISCO
abrir ↗VulnCheck XDB
initial-access
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir ↗GitHub PoC
CVE-2026-19949 - Draft or TODO
All-in-One WP Migration and Backup <= 7.109 - Unauthenticated Second-Order SQL Injection via Archive Restore to Remote Code Execution
41RISCO
abrir ↗GitHub PoC
Research lab and exploit chain for CVE-2026-75604: path traversal in the Next.js incremental cache, to RCE on Windows.
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
48RISCO
abrir ↗GitHub PoC★ 2
🧰 CVE-2026-65643 – cPanel Domain Parking RCE Toolkit (CVSS 8.7) | Red/Blue Team suite for unpatched cPanel & WHM 11.x (110,134,136,138). 2 tools: Full Exploit (reverse shell, webshell, persistence, root passwd, file R/W, mass scan, Tor), Blue Team PoC (detection, reporting, audit). w/Python. 🦾 Only Use Ethically, Stay Legal <3
Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
41RISCO
abrir ↗GitHub PoC
CVE-2026-65343 PoC — AppleKeyStore OOB read → KASLR defeat (iOS 26.6 / 23G71)
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.
41RISCO
abrir ↗GitHub PoC
AJCloud AJY IPC Firmware Path Traversal via jdbhttpd
AJCloud AJY IPC Firmware Path Traversal via jdbhttpd
41RISCO
abrir ↗GitHub PoC
CVE‑2026‑82329 is a critical authentication bypass in JFrog Artifactory (CVSS 9.8) allowing unauthenticated attackers to obtain full administrative privileges. Actively exploited in the wild. Affects self‑hosted versions before patches. PoC for authorized testing only.
Potential authentication bypass leading to administrative access in Artifactory
93RISCO
abrir ↗GitHub PoC
Vulnerability Analysis of CVE-2026-83548 affecting SonicWall SMA1000 security systems.
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended altern
78RISCO
abrir ↗GitHub PoC
CVE-2026-59822 - Draft or TODO
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
71RISCO
abrir ↗GitHub PoC★ 3
Windows HTTP.sys integer overflow -> nonpaged pool overflow LPE PoC (CVE-2026-62735): crash + full SYSTEM exploit; for authorized testing
Windows HTTP.sys Elevation of Privilege Vulnerability
41RISCO
abrir ↗GitHub PoC
CVE-2026-52810 - Draft or TODO
Gogs: Write to readonly repositories using receive-pack + service=git-upload-pack confusion
41RISCO
abrir ↗Exploit-DB
Metabase 0.61.0 - Authenticated Remote Code Execution
Metabase: Unsafe Deserialization of H2 Query Results
48RISCO
abrir ↗GitHub PoC
SQL Injection via ORDER BY Shortcode in plg_content_dpcalendar — DPCalendar Free ≤ 10.11.2
Joomla Extension - digital-peak.com - Authenticated, privileged blind SQL injection in DP Calendar 5.5.0 - 10.11.2
33RISCO
abrir ↗GitHub PoC★ 1
CVE-2026-20212 - Draft or TODO
Cisco Nexus 3000 and 9000 Series Switches Silicon One Hardware Abstraction Layer Remote Code Execution Vulnerability
48RISCO
abrir ↗GitHub PoC
Stored XSS via Location Title in DPCalendar Free
Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0 - 10.11.2
41RISCO
abrir ↗GitHub PoC★ 1
Struts2 S2-045/S2-046 CVE-2017-5638 detection & exploitation tool
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir ↗GitHub PoC
ChrisBarack/cve-2025-55182
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗GitHub PoC
CVE-2026-9586 - Draft or TODO
Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB
98RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.