Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.360GitHub PoC 15.228VulnCheck XDB 8.946Nuclei 4.390Metasploit 3.501✓ só verificadosrecentespopularesrisco
79.900 exploits
GitHub PoC★ 325
Android complete exploit chain that enables privilege escalation from a local untrusted app to root/kernel, combination of CVE-2026-49881 and CVE-2026-43284
In serviceClassExists of InCallController.java, there is a possible arbitrary code execution due to a logic error in the
41RISCO
abrir ↗GitHub PoC
CVE Reproduction: cve-2025-5777-citrixbleed2_reproduction
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir ↗GitHub PoC
CVE-2026-41940 & CVE-2026-41948 — cPanel & WHM Auth Bypass
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir ↗GitHub PoC★ 5
soralis0912/CVE-2026-43499-aristotle-apk
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir ↗GitHub PoC★ 1
0xdak/CVE-2026-56121_exploit
Feast < 0.63.0 Unauthenticated RCE via ApplyFeatureView gRPC Deserialization
48RISCO
abrir ↗GitHub PoC
GitHub Actions workflow sandbox (CVE-2026-48546 reproduction)
KanaDojo < 0.1.18 Sandbox Escape RCE via messages.cjs
21RISCO
abrir ↗GitHub PoC
GitHub Actions workflow sandbox for CVE-2026-45132 reproduction
CloudPirates Open Source Helm Charts: GitHub Actions workflow leaks PAT and SSH signing key via unsafe credential handling
48RISCO
abrir ↗GitHub PoC★ 28
YellowKey free tool for the CVE-2026-45585 BitLocker bypass vulnerability on Windows 10/11. Covered on Tom's Hardware: extract recovery keys, apply remediation, test bypass mitigation and manage BitLocker encryption state. Download YellowKey
Windows BitLocker Security Feature Bypass Vulnerability
33RISCO
abrir ↗VulnCheck XDB
local
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISCO
abrir ↗VulnCheck XDB
initial-access
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir ↗GitHub PoC
Initialized & connected PostgreSQL to Metasploit. Reconnoitered 10.1.16.0/24 with Nmap and imported results. Enumerated hosts/services using SYN, SMB & LDAP scanners. Exploited DC10 via ZeroLogon (CVE-2020-1472), dumped AD NTLM hashes with Impacket, performed Pass-the-Hash, then gained a Meterpreter reverse shell.
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir ↗GitHub PoC★ 12
DavidCarliez/CVE-2026-66804-CrossDevice-LPE
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
41RISCO
abrir ↗GitHub PoC★ 1
CVE-2021-41773 Apache
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗GitHub PoC
0xdak/CVE-2026-63766_exploit
GPT-SoVITS 20250606v2pro OS Command Injection via webui.py
48RISCO
abrir ↗GitHub PoC★ 1
Metabase CVE-2026-59827 Vulnerability Scanner
Metabase: Unsafe Deserialization of H2 Query Results
48RISCO
abrir ↗VulnCheck XDB
initial-access
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISCO
abrir ↗GitHub PoC
finding by nvth
Immutable.js: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
21RISCO
abrir ↗VulnCheck XDB
info-leak
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir ↗VulnCheck XDB
initial-access
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗VulnCheck XDB
initial-access
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir ↗GitHub PoC★ 4
soralis0912/CVE-2026-43499-aristotle
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir ↗GitHub PoC
Scan WordPress installations for wp2shell vulnerabilities (CVE-2026-63030 + CVE-2026-60137). Identifies full RCE and SQL injection risks across multiple sites with severity classification and CSV reporting.
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir ↗GitHub PoC★ 1
CVE-2026-16540 — Simply Schedule Appointments < 1.6.12.6 Unauthenticated Appointment Data Disclosure and Mass Deletion
Simply Schedule Appointments < 1.6.12.6 - Unauthenticated Appointment Data Disclosure and Mass Deletion via purge Endpoint
41RISCO
abrir ↗GitHub PoC
Full ML-KEM-1024 key recovery from a partial Fujisaki-Okamoto comparison in wolfSSL (CVE-2026-6330 NEON, CVE-2026-10097 AVX2)
ML-KEM ARM64 NEON ciphertext comparison only compares half of the input
33RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.