Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.697exploits catalogados
36.715CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.264GitHub PoC 15.172VulnCheck XDB 8.920Nuclei 4.373Metasploit 3.493✓ só verificadosrecentespopularesrisco
14.991 exploits
GitHub PoC
Exploit for MCPJam Inspector - Remote Code Execution (CVE-2026-23744)
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir ↗GitHub PoC
Script de python para Webmin 1.996
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
60RISCO
abrir ↗GitHub PoC
Walkthrough and PoC of File path traversal vulnerability(CVE-2026-36851) for UnPoller 2.33.0
Path traversal vulnerability in UnPoller 2.33.0 password field allows arbitrary file read and network exfiltration.
41RISCO
abrir ↗GitHub PoC★ 1
CVE-2026-49468 — LiteLLM (<1.84.0) unauthenticated auth bypass via Host-header route confusion. PoC + docker lab.
LiteLLM: Authentication Bypass via Host Header Injection
48RISCO
abrir ↗GitHub PoC
kn9annihilator/CVE-2011-2523-vsFTPd-2.3.4-Writeup
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir ↗GitHub PoC
Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in the computed fields feature uses an AST validator that only blocks attributes starting with underscore.
Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API
63RISCO
abrir ↗GitHub PoC★ 5
☄️ Mass reconnaissance & exploitation framework for Apache Solr CVE-2026-44825 — Velocity template injection to RCE
Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users
56RISCO
abrir ↗GitHub PoC
Tracking IPV6_FRAG_ESCAPE (CVE-2026-53362, CVE-2026-53366), the IPv6 fragmentation container escape
ipv6: account for fraggap on the paged allocation path
71RISCO
abrir ↗GitHub PoC
CVE-2017-12615 - Apache Tomcat Remote Code Execution (RCE)
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISCO
abrir ↗GitHub PoC★ 2
Page Builder CK for Joomla - Unauthenticated SSRF / Remote File Write leading to PHP execution Exploiter
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
75RISCO
abrir ↗GitHub PoC
Pardus Software Local Privilege Escalation PoC - affected from <= 1.0.4
Argument Injection in TUBITAK BILGEM's pardus-software
41RISCO
abrir ↗GitHub PoC★ 1
1beelze/CVE-2026-11387
SMS Alert <= 3.9.5 - Unauthenticated Privilege Escalation via Arbitrary Password Reset
63RISCO
abrir ↗GitHub PoC★ 4
# CVE-2026-28995 Proof of Concept for CVE-2026-28995 — Path Traversal vulnerability in App Intents on iOS 26.4.2 and below.
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 an
41RISCO
abrir ↗GitHub PoC★ 1
Proof of concept for CVE-2026-36027 and CVE-2026-36028
An issue in Code27 Companion Hub SQ3A.220705.003.A1 allows a physically proximate attacker to execute arbitrary code via
33RISCO
abrir ↗GitHub PoC
attarwahyup/Netscaler-CVE-2026-8451
Insufficient input validation leading to memory overread
46RISCO
abrir ↗GitHub PoC
CVE-2026-55726: Publicly Listable Azure Blob Storage Container (device logs) - Gardyn (ICSA-26-183-03)
Gardyn IoT Hub Exposure of Sensitive System Information to an Unauthorized Control Sphere
33RISCO
abrir ↗GitHub PoC
CVE-2026-54477: Admin Panel Missing Security Headers (clickjacking/XSS) - Gardyn (ICSA-26-183-03)
Gardyn IoT Hub Improper Neutralization of HTTP Headers for Scripting Syntax
33RISCO
abrir ↗GitHub PoC★ 1
kaleth4/CVE-2026-20896
Gitea Docker image trusts spoofable reverse-proxy headers by default
63RISCO
abrir ↗GitHub PoC
Gogs has Path Traversal in organization name that results in RCE through Git hooks
Gogs: Path Traversal in organization name results in RCE through Git hooks
48RISCO
abrir ↗GitHub PoC
Gorse < 0.5.10 contains an authentication bypass caused by empty admin_api_key in /api/dump and /api/restore endpoints, letting unauthenticated remote attackers access and modify protected data, exploit requires default empty admin_api_key configuration.
Gorse - Unauthenticated Database Dump and Restore via /api/dump and /api/restore Endpoints
63RISCO
abrir ↗GitHub PoC
Hunt-Benito/llama-factory-webui-rce-cve-2026-58116-trust-remote-code-model-path-injection
LLaMA-Factory 0.9.5 Remote Code Execution via WebUI Model Path
48RISCO
abrir ↗GitHub PoC★ 7
SimpleHelp OIDC Authentication Bypass PoC
SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification
53RISCO
abrir ↗GitHub PoC
kaleth4/CVE-2026-55200
libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
48RISCO
abrir ↗GitHub PoC
Crawl4AI <= 0.8.6 pre-auth RCE via AST sandbox escape (gi_frame.f_back.f_builtins chain) — CVSS 10.0
Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API
63RISCO
abrir ↗GitHub PoC
BastianXploited/CVE-2026-0740-mass
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RISCO
abrir ↗GitHub PoC
CVE-2025-5777 Research writeup
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir ↗GitHub PoC
This repository contains a proof-of-concept (PoC) exploit for CVE-2026-38751, affecting OpenSTAManager ≤ 2.10. The vulnerability allows an authenticated attacker to upload a malicious module via the module update functionality, leading to arbitrary file upload and remote code execution (RCE).
OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionali
41RISCO
abrir ↗GitHub PoC
CVE-2026-13768: Privileged iothubowner IoT Hub credential — fleet enumeration, device RCE, home-network pivot — Gardyn (ICSA-26-183-03)
Gardyn IoT Hub Use of Hard-coded Credentials
48RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.