Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8.883Nuclei 4.361Metasploit 3.493✓ só verificadosrecentespopularesrisco
79.305 exploits
GitHub PoC
CVE-2026-73570 PoC
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RISCO
abrir ↗VulnCheck XDB
initial-access
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗GitHub PoC
Demostracion educativa de mitigacion de CVE-2026-68820: Use-After-Free en afd.sys de Windows.
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
71RISCO
abrir ↗GitHub PoC
imbas007/RCE-CVE-2026-10520-CVE-2026-10523
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RISCO
abrir ↗GitHub PoC
Demostración práctica y bitácora técnica de explotación de BlueKeep (CVE-2019-0708) en RDP usando Nmap y Metasploit, documentando la resolución de errores en el entorno virtual.
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir ↗GitHub PoC
CVE-2025-48595 Android Framework Integer Overflow PoC - 优化版
In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to
71RISCO
abrir ↗VulnCheck XDB
denial-of-service
A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secu
100RISCO
abrir ↗GitHub PoC
Patch: Authentication bypass (VMware vCenter)
Tenda HG7HG9/HG10 formPPPEdit stack-based overflow
41RISCO
abrir ↗GitHub PoC
Patch: Heap overflow in SSL-VPN (Fortinet FortiOS)
Socket versions before 2.041 for Perl have an out-of-bounds heap read
48RISCO
abrir ↗GitHub PoC★ 1
PoC exploit chain for CVE-2026-15718: SpiderMonkey wasm baseline compiler array.fill missing-sync -> invalid pointer -> addrOf/fakeobj -> arbitrary R/W -> RCE
Invalid pointer in the JavaScript: WebAssembly component
33RISCO
abrir ↗GitHub PoC
From MCPJam Inspector RCE to root — CVE-2026-23744, JupyterLab token disclosure, kernel execution, and OPSMCP privilege escalation
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir ↗GitHub PoC
CVSS v3.1 assessment of CVE-2009-0658 (Adobe Acrobat Buffer Overflow), including Base, Temporal, and Environmental scoring and remediation recommendations.
Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitra
60RISCO
abrir ↗GitHub PoC
Professional PHPMyAdmin 5.0.0 SQL Injection (CVE-2020-5504) exploitation framework with automated database enumeration, table extraction, and data dumping capabilities. Features blind injection, proxy support, JSON output, and comprehensive error handling for authorized penetration testing and security research. Author: Sudeepa Wanigarathna
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could
35RISCO
abrir ↗GitHub PoC★ 4
Reproducible lab for CVE-2026-10053 (GitLab npm package-registry path traversal -> arbitrary file write as git). Vulnerable 19.2.1 vs patched 19.2.2, deterministic oracle.
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
41RISCO
abrir ↗GitHub PoC
chessalekin/cve-2026-9198_exploit
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISCO
abrir ↗GitHub PoC★ 1
Legendile7/CVE-2026-78122-POC
docker-socket-proxy through 0.5.0 Insufficient Access Control Granularity Exposes Container Filesystems
41RISCO
abrir ↗GitHub PoC
IDOR + Stored XSS via Broken Object-Level Authorization in JoomGallery
Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery < 4.4.0
41RISCO
abrir ↗GitHub PoC
Exploiting the vsftpd 2.3.4 backdoor (CVE-2011-2523) on Metasploitable2 — a hands-on pentesting lab writeup covering recon, exploitation, and remediation.
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir ↗GitHub PoC
Password-Protected Category Bypass via JSON Format in JoomGallery
Joomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON Format in JoomGallery < 4.4.0
33RISCO
abrir ↗VulnCheck XDB
info-leak
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to a
90RISCO
abrir ↗VulnCheck XDB
initial-access
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir ↗VulnCheck XDB
initial-access
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RISCO
abrir ↗GitHub PoC
CVE-2026-32475
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RISCO
abrir ↗GitHub PoC★ 1
PoC for CVE-2026-75616, an authenticated OS command injection in TP-Link Archer C20 v6 firmware
Command Injection in Router Web Management Interface
41RISCO
abrir ↗GitHub PoC★ 4
Apple MacOS Screen Sharing Arbitrary File read/write -> RCE
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS
78RISCO
abrir ↗GitHub PoC★ 3
내 공유기가 Zbtlink ENDLESSDOORS 백도어(CVE-2026-66747) 대상인지 클릭 한 번으로 검사하는 Windows 프로그램
ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant
48RISCO
abrir ↗VulnCheck XDB
initial-access
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS
100RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as
83RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as
83RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.