Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
15.228 exploits
GitHub PoC
notthemystery/CVE-2026-20700-POC-that-ll-never-work
CVE-2026-20700HIGHsob ataque25 mai 2026
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3,
71RISCO
abrir
GitHub PoC5
CVE-2026-42945 NGINX 堆溢出漏洞扫描与验证工具
CVE-2026-42945CRITICAL25 mai 2026
NGINX ngx_http_rewrite_module vulnerability
60RISCO
abrir
GitHub PoC
CVE-2026-33712 - Typebot <= 3.15.2 Unauthenticated SSRF via isolated-vm sandbox fetch
CVE-2026-33712CRITICAL25 mai 2026
TypeBot: Unauthenticated SSRF via isolated-vm fetch in preview chat endpoint bypasses SSRF controls
48RISCO
abrir
GitHub PoC
The code for personally reproducing the corresponding vulnerability
CVE-2026-47101HIGH25 mai 2026
LiteLLM < 1.83.14 Privilege Escalation via API Key Generation
41RISCO
abrir
GitHub PoC
translating original python exploit to C
CVE-2026-0073HIGH25 mai 2026
In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic err
41RISCO
abrir
GitHub PoC
Complete CosmicSting (CVE-2024-34102) exploit suite for Magento/Adobe Commerce XXE vulnerability
CVE-2024-34102CRITICALsob ataque25 mai 2026
XXE can expose crypt key and other secrets granting full admin access
100RISCO
abrir
GitHub PoC
Tomcat AJP文件读取/包含漏洞
CVE-2020-1938CRITICALsob ataque25 mai 2026
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISCO
abrir
GitHub PoC45
PoC for CVE-2026-28990, an ImageIO bug patched in iOS/macOS 26.5
CVE-2026-28990HIGH25 mai 2026
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 a
41RISCO
abrir
GitHub PoC
Educational laboratory for studying CVE-2014-0160 (Heartbleed) and framing inconsistencies in TLS heartbeat handling.
CVE-2014-0160HIGHsob ataque25 mai 2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC
Proof-of-concept for CVE-2026-43494 (PinTheft): Linux LPE via RDS zerocopy refcount bug + io_uring fixed buffers → SUID page-cache overwrite. Authorized research only.
CVE-2026-43494HIGH25 mai 2026
net/rds: reset op_nents when zerocopy page pin fails
41RISCO
abrir
GitHub PoC2
CVE-2026-36239 | Authenticated RCE in PbootCMS ≤3.2.12
CVE-2026-36239MEDIUM25 mai 2026
PbootCMS v.3.2.11 contains a code injection vulnerability in its site configuration functionality
33RISCO
abrir
GitHub PoC
Multi-language PoC (Python · Go · JS · C) and technical documentation for CVE-2025-63353, a critical predictable-default-PSK vulnerability in FiberHome HG6145F1 GPON ONT devices.
CVE-2025-63353CRITICAL25 mai 2026
A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-s
48RISCO
abrir
GitHub PoC
The code for personally reproducing the corresponding vulnerability
CVE-2026-47102HIGH25 mai 2026
LiteLLM < 1.83.10 Privilege Escalation via User Update
41RISCO
abrir
GitHub PoC
This is POC repo for CVE-2026-48188
CVE-2026-48188CRITICAL25 mai 2026
SQL Injection via MySQL Quote Method
48RISCO
abrir
GitHub PoC33
CVE-2026-0091, play with an issue in android window management to perform arbitrary code execution in Launcher process from adb
CVE-2026-0091HIGH25 mai 2026
In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell u
41RISCO
abrir
GitHub PoC
renewablehacking/CVE-2026-45321-Tanstack
CVE-2026-45321CRITICALsob ataqueransomware25 mai 2026
Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
78RISCO
abrir
GitHub PoC
Critical vulnerability in Siemens RuggedCom ROS devices allowing attackers to derive a hidden factory account password from the device MAC address and gain unauthorized administrative access via TELNET, rsh, or serial interfaces. Affects ROS 3.10.x and earlier.
CVE-2012-180325 mai 2026
RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC Ad
50RISCO
abrir
GitHub PoC
This is POC repo for CVE-2026-48208
CVE-2026-48208MEDIUM25 mai 2026
Denial-of-Service via SVG Rendering in Ticket
33RISCO
abrir
GitHub PoC
Tracking the nginx CVE-2026-9256 rewrite-module heap overflow
CVE-2026-9256CRITICAL24 mai 2026
NGINX ngx_http_rewrite_module vulnerability
53RISCO
abrir
GitHub PoC7
Drupal CVE-2026-9082 Blind SQL Injection Checker
CVE-2026-9082CRITICALsob ataque24 mai 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISCO
abrir
GitHub PoC
CMS Made Simple CVE-2019-9053 Exploit (Python 3)
CVE-2019-905324 mai 2026
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
GitHub PoC
Leemyunglyul/cve-2021-4034-mock
CVE-2021-4034HIGHsob ataqueransomware24 mai 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC4
CVE-2026-39987 Exploitation Tool - Marimo < 0.23.0 Pre-Auth RCE (WebSocket)
CVE-2026-39987CRITICALsob ataque24 mai 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISCO
abrir
GitHub PoC
CVE-2026-20182
CVE-2026-20182CRITICALsob ataque24 mai 2026
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
100RISCO
abrir
GitHub PoC
w3nch/CVE-2025-55182-in-go
CVE-2025-55182CRITICALsob ataqueransomware24 mai 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
CVE-2025-47812 Poc for wingdata HTB
CVE-2025-47812CRITICALsob ataque24 mai 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISCO
abrir
GitHub PoC
Ambiente Docker para demonstração prática da CVE-2025-54236 (SessionReaper): PHP Object Deserialization levando a RCE em Magento Open Source 2.4.7
CVE-2025-54236CRITICALsob ataque24 mai 2026
Adobe Commerce | Improper Input Validation (CWE-20)
100RISCO
abrir
GitHub PoC4
BitLocker TPM+PIN Hardening Against CVE-2026-45585 (YellowKey)
CVE-2026-45585MEDIUM24 mai 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RISCO
abrir
GitHub PoC3
CVE-2026-41096: Heap Overflow in the Windows DNS Client
CVE-2026-41096CRITICAL24 mai 2026
Windows DNS Client Remote Code Execution Vulnerability
48RISCO
abrir
GitHub PoC
mein-0/cve-2026-29923
CVE-2026-29923HIGH24 mai 2026
The pstrip64.sys driver in EnTech Taiwan PowerStrip <=3.90.736 allows local users to escalate privileges to SYSTEM via a
41RISCO
abrir
anteriorpágina 83 / 508próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.