Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
14.946 exploits
GitHub PoC
PoC: Shiori JWT CheckToken never re-validates account state (CVE-2026-71206, High 8.2)
CVE-2026-71206HIGH16 ago 2026
shiori - JWT CheckToken Never Re-Validates Account State, Allowing Stale-Privilege Access After Deletion or Demotion
41RISCO
abrir
GitHub PoC
PoC: changedetection.io unlimited login brute-force, no rate limiting (CVE-2026-71205, Medium 6.5)
CVE-2026-71205MEDIUM16 ago 2026
changedetection.io - No Rate Limiting on /login Enables Unlimited Password Brute-Force
33RISCO
abrir
GitHub PoC
Public writeup, PoC, and emulation materials for CVE-2026-8508 affecting Zyxel captive-portal social login.
CVE-2026-8508MEDIUM16 ago 2026
An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions throug
33RISCO
abrir
GitHub PoC
PoC: Grafana Editor role deletes protected contact points (CVE-2026-72585, Medium 6.5)
CVE-2026-7258516 ago 2026
23RISCO
abrir
GitHub PoC
PoC: changedetection.io settings blind-merge mass assignment (CVE-2026-71204, Medium 6.3)
CVE-2026-71204MEDIUM16 ago 2026
changedetection.io - Omitted Checkbox in /settings Save Silently Disables API Key Enforcement
33RISCO
abrir
GitHub PoC3
Public writeup, PoC, and emulation materials for CVE-2026-6837 affecting Zyxel export-cgi PKCS#12 export handling.
CVE-2026-6837HIGH16 ago 2026
A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions
41RISCO
abrir
GitHub PoC
PoC for CVE-2026-73847 - emlog AI Assistant CSRF to SQL execution to admin takeover (CVSS 6.8)
CVE-2026-73847MEDIUM16 ago 2026
Emlog: Missing CSRF protection in AI Assistant execute_tool leads to full database compromise and admin account takeover
33RISCO
abrir
GitHub PoC1
CVE-2026-73678 — MindsDB Minds Platform unauthenticated RCE via scratchpad exec (CVSS 10.0). Verified end-to-end with real LLM
CVE-2026-73678CRITICAL16 ago 2026
MindsDB Minds Platform v26.1.0 Unauthenticated RCE via scratchpad exec()
48RISCO
abrir
GitHub PoC
CVE-2026-73633(S2-072)概念验证代码
CVE-2026-73633HIGH16 ago 2026
Apache Struts: Unbounded read of a JSON request body
41RISCO
abrir
GitHub PoC1
Non-destructive detector for CVE-2026-64638 (XSS2Shell) — WordPress pre-auth XSS reflection primitive
CVE-2026-64638HIGH16 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RISCO
abrir
GitHub PoC
POC of CVE-2026-51031 for arbitrary local file read
CVE-2026-51031HIGH16 ago 2026
FlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. T
41RISCO
abrir
GitHub PoC
a-mansilla/CVE-2020-6418
CVE-2020-6418HIGHsob ataque16 ago 2026
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RISCO
abrir
GitHub PoC
DuyDuongDuyDuong/CVE-2024-4577-Exploitation-AsyncRAT-Deployment-DFIR-Investigation
CVE-2024-4577CRITICALsob ataqueransomware15 ago 2026
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
mencari sebuah kerentanan, wodpres dan mengungah shell di kerentanan wodpres tersebut
CVE-2026-6440MEDIUM15 ago 2026
GoodMeet <= 1.1.8 - Cross-Site Request Forgery to Google Meet Credential Reset via 'goodmeet_reset_google_meet_credential'
33RISCO
abrir
GitHub PoC
CVE-2026-58231 Detection & Confirmation Script
CVE-2026-58231CRITICAL15 ago 2026
Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
48RISCO
abrir
GitHub PoC
Python StateMachine 3.0.0 < 3.2.0 RCE via unsafe SCXML <data expr> evaluation and Python eval() injection.
CVE-2026-47103CRITICAL15 ago 2026
Python StateMachine 3.0.0 < 3.2.0 RCE via SCXML eval() Injection
48RISCO
abrir
GitHub PoC
Alixploit22/CVE-2026-53587
CVE-2026-53587HIGH15 ago 2026
libgit2 - Unauthenticated network-reachable heap out-of-bounds read in transports/smart_pkt.c:set_data
41RISCO
abrir
GitHub PoC
ghostpels/CVE-2026-13610
CVE-2026-13610HIGH15 ago 2026
KiviCare < 4.5.2 - Unauthenticated Privilege Escalation via Registration
41RISCO
abrir
GitHub PoC1
This repository contains a conceptual patch demonstrating the mitigation for CVE-2026-68820, a critical Use-After-Free (UAF) vulnerability in the Windows Ancillary Function Driver for WinSock (`afd.sys`).
CVE-2026-68820HIGHsob ataque15 ago 2026
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
71RISCO
abrir
GitHub PoC
CVE-2026-17544: PHP bcmath OOB write → universal memory-only RCE & disable_functions/open_basedir bypass. Offset-free runtime resolver. Verified on PHP 8.4.x / 8.5.x.
CVE-2026-17544HIGH15 ago 2026
Out-of-bounds write in bccomp() via crafted operand and scale
41RISCO
abrir
GitHub PoC
This is my simple implementation of an exploit for the PwnKit vulnerability.
CVE-2021-4034HIGHsob ataqueransomware15 ago 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
uproot <= 5.7.4 code injection via unsafe Python source generation from ROOT TStreamerInfo metadata.
CVE-2026-9147HIGH15 ago 2026
uproot 5.7.4 and prior Code Injection via TStreamerInfo Metadata
41RISCO
abrir
GitHub PoC
PoC for CVE-2026-9090 — Casdoor SAML signature bypass (CWE-347). Reproduction-only; coordinated via CERT/CC VU#780781.
CVE-2026-9090CRITICAL15 ago 2026
CVE-2026-9090
48RISCO
abrir
GitHub PoC382
CVE-2026-9830 Proof of Concept
CVE-2026-9830HIGH15 ago 2026
BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback Bug
41RISCO
abrir
GitHub PoC
CVE-2026-43499 research port for Galaxy Z Fold4 SM-F936W F936WVLU1AVGA (in progress)
CVE-2026-43499HIGH15 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC2
SambaCry Explanation and Exploitation Demo with POC
CVE-2017-7494CRITICALsob ataqueransomware15 ago 2026
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISCO
abrir
GitHub PoC
Full root in kernel domain with selinux permissive **MOVED TO THIS REPO https://github.com/CamsShaft/IonStack-S22 WILL DELETE THIS ONE SOON**
CVE-2026-43499HIGH15 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC2
CVE-2026-43499 (GhostLock) rt_mutex stack-UAF privilege escalation research on Honor BVL-AN16 (Magic6 Pro, SM8650, kernel 6.1.128). Includes analysis docs, reverse-engineering scripts, disassembly artifacts, and exploit source with honor-BVL-AN16 target adaptation.
CVE-2026-43499HIGH15 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
Responsible disclosure write-ups for CVE-2026-8793 - PaperCut NG 25.0.11
CVE-2026-8793MEDIUM15 ago 2026
PaperCut NG/MF: Insufficient brute-force protection
33RISCO
abrir
GitHub PoC2
PoC for CVE-2026-72898
CVE-2026-72898CRITICALsob ataque15 ago 2026
Metabase SQL injection via password reset endpoint
100RISCO
abrir

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.