Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.703exploits catalogados
36.717CVEs com exploração pública
24.695testados em laboratório
79.703 exploits
GitHub PoC
PoC for Unauthenticated Reflected Cross-Site Scripting (XSS) in RegistrationMagic WordPress Plugin
CVE-2026-82221HIGH01 set 2026
WordPress RegistrationMagic plugin <= 6.0.9.8 - Cross Site Scripting (XSS) vulnerability
41RISCO
abrir
GitHub PoC
pervinzahidli/CVE-2026-75855
CVE-2026-75855HIGH01 set 2026
ArcadeDB before 26.8.1 Path Traversal via create/drop database
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALsob ataque01 set 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALsob ataqueransomware01 set 2026
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISCO
abrir
GitHub PoC2
Keycloak reset-credentials flow bypass
CVE-2026-18963CRITICAL01 set 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISCO
abrir
GitHub PoC11
CVE-2026-82329 JFrog Artifactory unauthenticated auth-bypass: reproducible Docker lab + URL-parameter validator PoC + patch-diff analysis
CVE-2026-82329CRITICALsob ataque01 set 2026
Potential authentication bypass leading to administrative access in Artifactory
93RISCO
abrir
GitHub PoC
GiveWP <= 4.16.7.1 Unauthenticated PHP Object Injection → RCE
CVE-2026-82222CRITICAL31 ago 2026
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RISCO
abrir
Exploit-DB
Linksys E1200_2.0.04 - Unauthenticated OS Command Injection
CVE-2025-60689MEDIUMwebappshardware31 ago 2026
An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200
38RISCO
abrir
Exploit-DB
Langflow 1.8.4 - Path Traversal to Remote Code Execution
CVE-2026-5027HIGHwebappsmultiple31 ago 2026
Langflow - Path Traversal Arbitrary File Write via upload_user_file
68RISCO
abrir
GitHub PoC
Weak-RNG stream-sweep research (CVE-2026-71851 class): PRNG schemes x seeds -> BIP39 -> victim set membership
CVE-2026-71851CRITICAL31 ago 2026
crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
48RISCO
abrir
GitHub PoC1
Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp Vault (CVE-2026-5006), HashiCorp Nomad (CVE-2026-7474).
CVE-2026-18963CRITICAL31 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-60004CRITICALsob ataque31 ago 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-9198CRITICALsob ataque31 ago 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-18963CRITICAL31 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISCO
abrir
GitHub PoC
Reflected XSS via search GET Parameter in Phoca Download
CVE-2026-76569MEDIUM31 ago 2026
Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4
33RISCO
abrir
GitHub PoC1
FastGPT Community Edition NoSQL Injection PoC (CVE-2026-79483)
CVE-2026-79483MEDIUM30 ago 2026
FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistor
33RISCO
abrir
GitHub PoC16
Authorized Docker lab and clean PoC for validating CVE-2026-82222 RCE in GiveWP 4.16.5.1 and the 4.16.7.2 fix.
CVE-2026-82222CRITICAL30 ago 2026
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-6440CRITICAL30 ago 2026
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-48611CRITICAL30 ago 2026
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-82222CRITICAL30 ago 2026
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RISCO
abrir
GitHub PoC
Log4Shell CVE-2021-44228 vulnerable lab
CVE-2021-44228CRITICALsob ataqueransomware30 ago 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-60004CRITICALsob ataque30 ago 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
100RISCO
abrir
GitHub PoC
🫖 Contract-correlated discovery and authorized validation tool for Gitea CVE-2026-60004
CVE-2026-60004CRITICALsob ataque30 ago 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
100RISCO
abrir
GitHub PoC
Automated PoC for CVE-2026-48611 — phpBB OAuth login_link authentication bypass
CVE-2026-48611CRITICAL30 ago 2026
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-82222CRITICAL30 ago 2026
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RISCO
abrir
GitHub PoC
CVE-2026-12513 Vulnerability Advisory & PoC — Discovered by Huynh Kien Minh (MinhHK).
CVE-2026-12513MEDIUM30 ago 2026
Shared Files < 1.7.68 - Unauthenticated Arbitrary File Deletion via Path Traversal
33RISCO
abrir
GitHub PoC
CVE-2026-45833 ChromaDB
CVE-2026-45833CRITICAL30 ago 2026
A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacke
48RISCO
abrir
GitHub PoC
Safe passive detector for identifying WPMU DEV Dashboard versions affected by CVE-2026-76581.
CVE-2026-76581CRITICAL30 ago 2026
WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion
48RISCO
abrir
GitHub PoC
CVE-2026-76581
CVE-2026-76581CRITICAL30 ago 2026
WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion
48RISCO
abrir
GitHub PoC
CitrixBleed Exploit Tool - CVE-2025-5777 & CVE-2026-8452. Unauthenticated remote memory read from Citrix NetScaler ADC & Gateway. Steal admin session tokens, extract nsroot hashes, dump secrets, and bypass MFA. Python 3 exploit with full memory parsing.
CVE-2026-8452HIGHsob ataque30 ago 2026
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
71RISCO
abrir
anteriorpágina 7 / 2.657próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.