Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8.883Nuclei 4.361Metasploit 3.493✓ só verificadosrecentespopularesrisco
14.946 exploits
GitHub PoC
PoC: Shiori JWT CheckToken never re-validates account state (CVE-2026-71206, High 8.2)
shiori - JWT CheckToken Never Re-Validates Account State, Allowing Stale-Privilege Access After Deletion or Demotion
41RISCO
abrir ↗GitHub PoC
PoC: changedetection.io unlimited login brute-force, no rate limiting (CVE-2026-71205, Medium 6.5)
changedetection.io - No Rate Limiting on /login Enables Unlimited Password Brute-Force
33RISCO
abrir ↗GitHub PoC
Public writeup, PoC, and emulation materials for CVE-2026-8508 affecting Zyxel captive-portal social login.
An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions throug
33RISCO
abrir ↗GitHub PoC
PoC: Grafana Editor role deletes protected contact points (CVE-2026-72585, Medium 6.5)
23RISCO
abrir ↗GitHub PoC
PoC: changedetection.io settings blind-merge mass assignment (CVE-2026-71204, Medium 6.3)
changedetection.io - Omitted Checkbox in /settings Save Silently Disables API Key Enforcement
33RISCO
abrir ↗GitHub PoC★ 3
Public writeup, PoC, and emulation materials for CVE-2026-6837 affecting Zyxel export-cgi PKCS#12 export handling.
A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions
41RISCO
abrir ↗GitHub PoC
PoC for CVE-2026-73847 - emlog AI Assistant CSRF to SQL execution to admin takeover (CVSS 6.8)
Emlog: Missing CSRF protection in AI Assistant execute_tool leads to full database compromise and admin account takeover
33RISCO
abrir ↗GitHub PoC★ 1
CVE-2026-73678 — MindsDB Minds Platform unauthenticated RCE via scratchpad exec (CVSS 10.0). Verified end-to-end with real LLM
MindsDB Minds Platform v26.1.0 Unauthenticated RCE via scratchpad exec()
48RISCO
abrir ↗GitHub PoC
CVE-2026-73633(S2-072)概念验证代码
Apache Struts: Unbounded read of a JSON request body
41RISCO
abrir ↗GitHub PoC★ 1
Non-destructive detector for CVE-2026-64638 (XSS2Shell) — WordPress pre-auth XSS reflection primitive
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISCO
abrir ↗GitHub PoC
POC of CVE-2026-51031 for arbitrary local file read
FlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. T
41RISCO
abrir ↗GitHub PoC
a-mansilla/CVE-2020-6418
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RISCO
abrir ↗GitHub PoC
DuyDuongDuyDuong/CVE-2024-4577-Exploitation-AsyncRAT-Deployment-DFIR-Investigation
Argument Injection in PHP-CGI
100RISCO
abrir ↗GitHub PoC
mencari sebuah kerentanan, wodpres dan mengungah shell di kerentanan wodpres tersebut
GoodMeet <= 1.1.8 - Cross-Site Request Forgery to Google Meet Credential Reset via 'goodmeet_reset_google_meet_credential'
33RISCO
abrir ↗GitHub PoC
CVE-2026-58231 Detection & Confirmation Script
Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
48RISCO
abrir ↗GitHub PoC
Python StateMachine 3.0.0 < 3.2.0 RCE via unsafe SCXML <data expr> evaluation and Python eval() injection.
Python StateMachine 3.0.0 < 3.2.0 RCE via SCXML eval() Injection
48RISCO
abrir ↗GitHub PoC
Alixploit22/CVE-2026-53587
libgit2 - Unauthenticated network-reachable heap out-of-bounds read in transports/smart_pkt.c:set_data
41RISCO
abrir ↗GitHub PoC
ghostpels/CVE-2026-13610
KiviCare < 4.5.2 - Unauthenticated Privilege Escalation via Registration
41RISCO
abrir ↗GitHub PoC★ 1
This repository contains a conceptual patch demonstrating the mitigation for CVE-2026-68820, a critical Use-After-Free (UAF) vulnerability in the Windows Ancillary Function Driver for WinSock (`afd.sys`).
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
71RISCO
abrir ↗GitHub PoC
CVE-2026-17544: PHP bcmath OOB write → universal memory-only RCE & disable_functions/open_basedir bypass. Offset-free runtime resolver. Verified on PHP 8.4.x / 8.5.x.
Out-of-bounds write in bccomp() via crafted operand and scale
41RISCO
abrir ↗GitHub PoC
This is my simple implementation of an exploit for the PwnKit vulnerability.
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir ↗GitHub PoC
uproot <= 5.7.4 code injection via unsafe Python source generation from ROOT TStreamerInfo metadata.
uproot 5.7.4 and prior Code Injection via TStreamerInfo Metadata
41RISCO
abrir ↗GitHub PoC
PoC for CVE-2026-9090 — Casdoor SAML signature bypass (CWE-347). Reproduction-only; coordinated via CERT/CC VU#780781.
CVE-2026-9090
48RISCO
abrir ↗GitHub PoC★ 382
CVE-2026-9830 Proof of Concept
BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback Bug
41RISCO
abrir ↗GitHub PoC
CVE-2026-43499 research port for Galaxy Z Fold4 SM-F936W F936WVLU1AVGA (in progress)
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir ↗GitHub PoC★ 2
SambaCry Explanation and Exploitation Demo with POC
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISCO
abrir ↗GitHub PoC
Full root in kernel domain with selinux permissive **MOVED TO THIS REPO https://github.com/CamsShaft/IonStack-S22 WILL DELETE THIS ONE SOON**
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir ↗GitHub PoC★ 2
CVE-2026-43499 (GhostLock) rt_mutex stack-UAF privilege escalation research on Honor BVL-AN16 (Magic6 Pro, SM8650, kernel 6.1.128). Includes analysis docs, reverse-engineering scripts, disassembly artifacts, and exploit source with honor-BVL-AN16 target adaptation.
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir ↗GitHub PoC
Responsible disclosure write-ups for CVE-2026-8793 - PaperCut NG 25.0.11
PaperCut NG/MF: Insufficient brute-force protection
33RISCO
abrir ↗GitHub PoC★ 2
PoC for CVE-2026-72898
Metabase SQL injection via password reset endpoint
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.