Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
14.946 exploits
GitHub PoC
IhsSpotlight/HeartBleed-CVE-2014-0160--SCRIPTS-python3
CVE-2014-0160HIGHsob ataque18 ago 2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC
CVE-2026-59310
CVE-2026-59310CRITICALsob ataque17 ago 2026
vCenter directory-traversal vulnerability
90RISCO
abrir
GitHub PoC
CVE-2026-59310 PoC
CVE-2026-59310CRITICALsob ataque17 ago 2026
vCenter directory-traversal vulnerability
90RISCO
abrir
GitHub PoC
golang.org/x/text v0.33.0 backport of CVE-2026-56852 (GO-2026-5970) for Go 1.24
CVE-2026-56852HIGH17 ago 2026
Infinite loop on invalid input in golang.org/x/text
41RISCO
abrir
GitHub PoC
CVE-2026-74943, Use after free in Firefox RasterImage (sec-high)
CVE-2026-74943CRITICAL17 ago 2026
Use-after-free in the Graphics: ImageLib component
48RISCO
abrir
GitHub PoC
CVE-2026-74970, Fission site isolation bypass in Firefox WebRender
CVE-2026-74970MEDIUM17 ago 2026
Site isolation issue in the Graphics component
33RISCO
abrir
GitHub PoC9
Kernel root exploit (CVE-2026-43499) for some 5.X devices (mostly Amazon)
CVE-2026-43499HIGH17 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
Unauthenticated SQL Injection via Attribute Filter in Phoca Cart - CVSS 9.3
CVE-2026-74251CRITICAL17 ago 2026
Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6
48RISCO
abrir
GitHub PoC1
ZendTo unauthenticated ClamAV CVE-2026-20217 RCE and default-profile root escalation reproduction
CVE-2026-20217HIGH17 ago 2026
ClamAV PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerability
41RISCO
abrir
GitHub PoC1
CVE-2026-71518 — Typemill <2.26.0 unauthenticated authorization bypass in media file download (path-equivalent URL variants). Advisory + PoC.
CVE-2026-71518HIGH17 ago 2026
Typemill < 2.26.0 Authorization Bypass via Media File Download Route
41RISCO
abrir
GitHub PoC
iPad 8 iPadOS 26.3 AVE toolchain research (CVE-2026-64747 class)
CVE-2026-64747HIGH17 ago 2026
A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iO
41RISCO
abrir
GitHub PoC
CVE-2026-74945, Uninitialized heap disclosure via a crafted web font (sec-high)
CVE-2026-74945MEDIUM17 ago 2026
Information disclosure in the Graphics: Text component
33RISCO
abrir
GitHub PoC
Tracking CVE-2026-68138, the Linux kernel net/sched qdisc rate-table use-after-free
CVE-2026-68138HIGH17 ago 2026
net/sched: serialize qdisc_rtab_list against concurrent get/put
41RISCO
abrir
GitHub PoC
CVE-2026-15826, CVE-2026-15748
CVE-2026-15826CRITICAL17 ago 2026
User Profile Builder <= 3.16.4 - Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter
63RISCO
abrir
GitHub PoC
POC for CVE-2026-41042
CVE-2026-41042CRITICAL17 ago 2026
Apache Gravitino: Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter
63RISCO
abrir
GitHub PoC
katranSefa/CVE-2026-13714
CVE-2026-13714CRITICAL17 ago 2026
Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
48RISCO
abrir
GitHub PoC
CVE-2026-19650, CVE-2026-19478 - Draft or TODO
CVE-2026-19650HIGH17 ago 2026
Cross-Site Request Forgery (CSRF) in GitLab
41RISCO
abrir
GitHub PoC1
CVE-2026-62737 ExecutionContext.sys arbitrary kernel-call PoC
CVE-2026-62737HIGH17 ago 2026
Windows Kernel Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC
CVE-2026-33017, vuln in langflow.
CVE-2026-33017CRITICALsob ataque17 ago 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir
GitHub PoC
Isolated Docker lab, static detection scanner, and PoC validation for React2Shell (CVE-2025-55182).
CVE-2025-55182CRITICALsob ataqueransomware17 ago 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
CVE-2026-68138 Linux Local Privilege Escalation Exploit
CVE-2026-68138HIGH17 ago 2026
net/sched: serialize qdisc_rtab_list against concurrent get/put
41RISCO
abrir
GitHub PoC6
A poc and write-up for CVE-2026-40345
CVE-2026-40345HIGH17 ago 2026
deepmerge-ts: Stack exhaustion when merging recursive object graphs
41RISCO
abrir
GitHub PoC
a-mansilla/CVE-2020-6418
CVE-2020-6418HIGHsob ataque16 ago 2026
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RISCO
abrir
GitHub PoC1
CVE-2026-73678 — MindsDB Minds Platform unauthenticated RCE via scratchpad exec (CVSS 10.0). Verified end-to-end with real LLM
CVE-2026-73678CRITICAL16 ago 2026
MindsDB Minds Platform v26.1.0 Unauthenticated RCE via scratchpad exec()
48RISCO
abrir
GitHub PoC
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
CVE-2026-18366CRITICAL16 ago 2026
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
48RISCO
abrir
GitHub PoC
PoC: changedetection.io settings blind-merge mass assignment (CVE-2026-71204, Medium 6.3)
CVE-2026-71204MEDIUM16 ago 2026
changedetection.io - Omitted Checkbox in /settings Save Silently Disables API Key Enforcement
33RISCO
abrir
GitHub PoC
POC of CVE-2026-51031 for arbitrary local file read
CVE-2026-51031HIGH16 ago 2026
FlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. T
41RISCO
abrir
GitHub PoC
PoC: Grafana Editor role deletes protected contact points (CVE-2026-72585, Medium 6.5)
CVE-2026-7258516 ago 2026
23RISCO
abrir
GitHub PoC
React2Shell(CVE-2025-55182) 취약점 기반 침해 시나리오를 재현하고, Wazuh/Sysmon/Coraza WAF 로그로 침해사고를 분석·대응한 DFIR 프로젝트
CVE-2025-55182CRITICALsob ataqueransomware16 ago 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
eh-amish/Windows-Defender-Security-Auditor-CVE-2026-50656-
CVE-2026-50656HIGH16 ago 2026
Microsoft Defender Elevation of Privilege Vulnerability
46RISCO
abrir

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.