Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.858exploits catalogados
36.825CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.346GitHub PoC 15.209VulnCheck XDB 8.944Nuclei 4.383Metasploit 3.501✓ só verificadosrecentespopularesrisco
15.209 exploits
GitHub PoC
Goal is to triage well known attack and learn how security teams quickly respond.
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗GitHub PoC
Goal is to triage well known attack and learn how security teams quickly respond.
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir ↗GitHub PoC★ 3
DirtyClone - local privilege escalation (LPE) proof-of-concept targeting a kernel/XFRM-related vulnerability described in the source as CVE-2026-43503
net: skbuff: propagate shared-frag marker through frag-transfer helpers
41RISCO
abrir ↗GitHub PoC★ 192
CVE-2026-41940 authentication bypass vulnerability proof-of-concept
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir ↗GitHub PoC
kyukazamiqq/CVE-2026-24061
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir ↗GitHub PoC★ 2
Educational, defensive kit for two Linux page-cache-corruption LPEs (DirtyClone CVE-2026-43503, pedit COW CVE-2026-46331): hardening, detection, verification, seccomp + validation harness. Detection and prevention only — no exploit code. TLP:CLEAR.
net: skbuff: propagate shared-frag marker through frag-transfer helpers
41RISCO
abrir ↗GitHub PoC
patched ffmpeg-tools for jellyfin to patch CVE-2026-8461 aka PixelSmash
Heap out-of-bounds write via odd slice_height in FFmpeg MagicYUV decoder
41RISCO
abrir ↗GitHub PoC
Hack The Box - Orion (Easy) | CVE-2025-32432 & CVE-2026-24061
Craft CMS Allows Remote Code Execution
100RISCO
abrir ↗GitHub PoC
CVE-2026-46331 - Draft
net/sched: fix pedit partial COW leading to page cache corruption
41RISCO
abrir ↗GitHub PoC★ 3
CVE-2026-0073-Android-ADBD-bypass-POC汉化版
In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic err
41RISCO
abrir ↗GitHub PoC★ 3
CVE-2026-0073-Android-ADBD-bypass-POC汉化版
In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic err
41RISCO
abrir ↗GitHub PoC
CVE-2026-48907 is a CVSS 10.0 pre-auth RCE in Joomla Content Editor affecting all versions ≤ 2.9.99.4. The Grayxploit team breaks down the 3-weakness chain — missing auth, no extension validation, and an unsafe upload flag — that lets attackers pop a shell in 3 HTTP requests.
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISCO
abrir ↗GitHub PoC★ 8
OpenSTAManager-RCE-Exploit-CVE-2026-38751
OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionali
41RISCO
abrir ↗GitHub PoC
Hack The Box - Orion (Easy) | CVE-2025-32432 & CVE-2026-24061
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir ↗GitHub PoC★ 59
cve-2026-48907 scanner
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISCO
abrir ↗GitHub PoC
Hunt-Benito/traefik-stripprefix-auth-bypass-cve-2026-48020-path-normalization
Traefik StripPrefix Route-Level Auth Bypass via Path Normalization
41RISCO
abrir ↗GitHub PoC
PoC for CVE-2026-5366: git argument injection in Prefect's GitRepository leading to RCE on the worker.
Git Argument Injection in prefecthq/prefect
48RISCO
abrir ↗GitHub PoC★ 1
WP Full Stripe Free <= 8.4.3 - Missing Authorization
Stripe Payment Forms by WP Full Pay <= 8.4.3 - Missing Authorization to Unauthenticated Payment Record Manipulation via 'paymentIntentId' Parameter
33RISCO
abrir ↗GitHub PoC
Defensive analysis and non-weaponized validation of CVE-2016-5195 (Dirty COW), including root-cause research, patch analysis, and reproducible evidence.
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir ↗GitHub PoC
SugiB3o/CVE-2026-31431
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir ↗GitHub PoC★ 148
CVE-2026-43499 PoC
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir ↗GitHub PoC★ 3
CVE-2026-20251 — Splunk Secure Gateway jsonpickle deserialization RCE (CVSS 8.8) | ReactiveZero Security Research
Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway
53RISCO
abrir ↗GitHub PoC
12hrformat/CVE-2026-35273-POC
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Mana
100RISCO
abrir ↗GitHub PoC
The SSRF filter checked hostname text, but the actual destination was decided later by DNS. That gap let attacker-controlled Webhook URLs reach loopback, metadata, and private network targets.
TypeBot: SSRF Protection Bypass via DNS-Resolved Hostnames in Webhook / HTTP Request Validation
41RISCO
abrir ↗GitHub PoC★ 31
CVE-2026-46331
net/sched: fix pedit partial COW leading to page cache corruption
41RISCO
abrir ↗GitHub PoC★ 1
CVE-2026-24207 — NVIDIA Triton SageMaker auth bypass to unauth RCE. Detection script, bypass demo, RCE-chain PoC, and IDS rules.
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A succes
63RISCO
abrir ↗GitHub PoC★ 4
aexdyhaxor/CVE-2026-43503-DirtyClone
net: skbuff: propagate shared-frag marker through frag-transfer helpers
41RISCO
abrir ↗GitHub PoC
Flowiseai Flowise Auth Bypass Vulnerability Proof of Concept
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
75RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.