Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
15.031 exploits
GitHub PoC
Bypassing connect()-based syscall rules using TCP Fast Open (CVE-2026-63828 PoC)
CVE-2026-63828HIGH02 set 2026
apparmor: mediate the implicit connect of TCP fast open sendmsg
41RISCO
abrir
GitHub PoC
EXEcution-py/CVE-2026-9055
CVE-2026-9055CRITICAL02 set 2026
Booking for Appointments and Events Calendar – Amelia (Premium) 8.0 - 9.6.2 - Unauthenticated Privilege Escalation to Administrator via 'externalId'
48RISCO
abrir
GitHub PoC
CVE-2026-0828
CVE-2026-0828HIGH02 set 2026
Kernel driver vulnerability in Safetica Endpoint Client
41RISCO
abrir
GitHub PoC
Saku0512/CVE-2026-84361-poc
CVE-2026-84361HIGH02 set 2026
Composer: Perforce source URL permits P4PORT `rsh:` command execution
41RISCO
abrir
GitHub PoC
CVE-2026-9586 - Draft or TODO
CVE-2026-9586CRITICALsob ataque02 set 2026
Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB
78RISCO
abrir
GitHub PoC
CVE-2026-9335: KerasFileEditor and load_weights follow h5py ExternalLinks, disclosing arbitrary local HDF5 file contents in keras ≤ 3.14.0. Advisory + verified PoCs.
CVE-2026-9335MEDIUM02 set 2026
Improper Handling of HDF5 ExternalLinks in keras-team/keras
33RISCO
abrir
GitHub PoC
tcollins-hashicorp/vault-cve-2026-5006-audit
CVE-2026-5006MEDIUM02 set 2026
Vault Vulnerable to Privilege Escalation via Slash Injection in Templated Policy Paths
33RISCO
abrir
GitHub PoC
SAP-system-update/CVE-2026-58231
CVE-2026-58231CRITICAL02 set 2026
Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
48RISCO
abrir
GitHub PoC
CVE-2026-73296
CVE-2026-73296CRITICAL02 set 2026
Microsoft UFO: Unauthenticated Mobile MCP access allows remote Android device control and screen disclosure
48RISCO
abrir
GitHub PoC
byt3l0rd/CVE-2026-73570
CVE-2026-73570HIGHsob ataque02 set 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
91RISCO
abrir
GitHub PoC1
CVE-2026-64788 PoC — IOGPUFamily Use-After-Free (iOS 26.6 / 23G71)
CVE-2026-64788MEDIUM02 set 2026
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe
33RISCO
abrir
GitHub PoC1
CVE-2026-65330 PoC — setxattr PAC bypass via fixed #0x307a diversifier (iOS 26.6 / 23G71)
CVE-2026-65330MEDIUM02 set 2026
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe
33RISCO
abrir
GitHub PoC
CVE-2026-38577
CVE-2026-38577CRITICAL02 set 2026
Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access.
48RISCO
abrir
GitHub PoC1
NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC
CVE-2026-19490CRITICAL02 set 2026
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
48RISCO
abrir
GitHub PoC1
CVE-2026-65349 PoC — getattrlist OOB write in vfs_attr_pack_internal (iOS 26.6 / 23G71)
CVE-2026-65349MEDIUM02 set 2026
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1,
33RISCO
abrir
GitHub PoC1
CVE-2026-82329 — JFrog Artifactory (self-hosted) Auth Bypass
CVE-2026-82329CRITICALsob ataque02 set 2026
Potential authentication bypass leading to administrative access in Artifactory
93RISCO
abrir
GitHub PoC
CVE-2026-82329 — JFrog Artifactory unauthenticated authentication bypass ("phantom join key" -> forged service admin token)
CVE-2026-82329CRITICALsob ataque02 set 2026
Potential authentication bypass leading to administrative access in Artifactory
93RISCO
abrir
GitHub PoC1
CVE-2026-65343 PoC — AppleKeyStore OOB read → KASLR defeat (iOS 26.6 / 23G71)
CVE-2026-65343HIGH02 set 2026
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.
41RISCO
abrir
GitHub PoC1
D-Link DIR-825M formDiskFormat stack overflow + command injection RCE PoC (CVE-2026-82592); for authorized security testing
CVE-2026-82592CRITICAL01 set 2026
D-Link DIR-825M Disk Formatting Handler Endpoint formDiskFormat sub_46725C stack-based overflow
48RISCO
abrir
GitHub PoC
CVE-2026-82329 - Draft or TODO
CVE-2026-82329CRITICALsob ataque01 set 2026
Potential authentication bypass leading to administrative access in Artifactory
93RISCO
abrir
GitHub PoC
PostgreSQL の全文検索(tsvector/tsquery)に見つかった範囲外書き込み脆弱性 CVE-2026-14662 を、修正前(18.4)と修正後(18.6)を Docker で並べて動かして検証した記録と発表資料
CVE-2026-14662HIGH01 set 2026
PostgreSQL tsvector and tsquery undersize allocations, via integer wraparound
41RISCO
abrir
GitHub PoC1
Poc of CVE-2026-13753
CVE-2026-13753HIGH01 set 2026
Certain HP DeskJet All in One – Potential Information Disclosure
41RISCO
abrir
GitHub PoC
PoC for Unauthenticated Reflected Cross-Site Scripting (XSS) in RegistrationMagic WordPress Plugin
CVE-2026-82221HIGH01 set 2026
WordPress RegistrationMagic plugin <= 6.0.9.8 - Cross Site Scripting (XSS) vulnerability
41RISCO
abrir
GitHub PoC
pervinzahidli/CVE-2026-75855
CVE-2026-75855HIGH01 set 2026
ArcadeDB before 26.8.1 Path Traversal via create/drop database
41RISCO
abrir
GitHub PoC2
Keycloak reset-credentials flow bypass
CVE-2026-18963CRITICAL01 set 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISCO
abrir
GitHub PoC7
CVE-2026-82329 JFrog Artifactory unauthenticated auth-bypass: reproducible Docker lab + URL-parameter validator PoC + patch-diff analysis
CVE-2026-82329CRITICALsob ataque01 set 2026
Potential authentication bypass leading to administrative access in Artifactory
93RISCO
abrir
GitHub PoC
GiveWP <= 4.16.7.1 Unauthenticated PHP Object Injection → RCE
CVE-2026-82222CRITICAL31 ago 2026
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RISCO
abrir
GitHub PoC
Reflected XSS via search GET Parameter in Phoca Download
CVE-2026-76569MEDIUM31 ago 2026
Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4
33RISCO
abrir
GitHub PoC1
Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp Vault (CVE-2026-5006), HashiCorp Nomad (CVE-2026-7474).
CVE-2026-18963CRITICAL31 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISCO
abrir
GitHub PoC
Weak-RNG stream-sweep research (CVE-2026-71851 class): PRNG schemes x seeds -> BIP39 -> victim set membership
CVE-2026-71851CRITICAL31 ago 2026
crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
48RISCO
abrir
página 1 / 502próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.