Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
79.305 exploits
Metasploit600
SPIP X-Spip-Filtre Unauthenticated RCE
CVE-2026-77647CRITICAL20 ago 2026
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August
43RISCO
abrir
GitHub PoC38
Exploit for KeyCloak CVE-2026-18963
CVE-2026-18963CRITICAL20 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISCO
abrir
VulnCheck XDB
local
CVE-2022-38181HIGHsob ataque20 ago 2026
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishan
76RISCO
abrir
GitHub PoC1
Safely detect Citrix NetScaler CVE-2026-8452
CVE-2026-8452HIGHsob ataque20 ago 2026
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
71RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-19478CRITICAL20 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALsob ataqueransomware20 ago 2026
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
VulnCheck XDB
local
CVE-2025-21479HIGHsob ataque20 ago 2026
Incorrect Authorization in Graphics
71RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-39987CRITICALsob ataque20 ago 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISCO
abrir
GitHub PoC
Analyze and reproduce CVE-2025-55182.
CVE-2025-55182CRITICALsob ataqueransomware20 ago 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
MattiaCervelli/CVE-2025-24893_Analysis
CVE-2025-24893CRITICALsob ataque19 ago 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALsob ataque19 ago 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC
fork and edits from https://github.com/aniqfakhrul/CVE-2026-54121
CVE-2026-54121HIGH19 ago 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-16723CRITICAL19 ago 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISCO
abrir
VulnCheck XDB
local
CVE-2025-21479HIGHsob ataque19 ago 2026
Incorrect Authorization in Graphics
71RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALsob ataqueransomware19 ago 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-39987CRITICALsob ataque19 ago 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISCO
abrir
GitHub PoC
fastjson jsontype利用
CVE-2026-16723CRITICAL19 ago 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISCO
abrir
GitHub PoC
Oracle OID LDAP Server Privileges Management Exploit
CVE-2026-61241CRITICAL19 ago 2026
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Suppor
28RISCO
abrir
GitHub PoC
Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration
CVE-2026-15748CRITICAL19 ago 2026
Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-34486HIGHsob ataque19 ago 2026
Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
100RISCO
abrir
GitHub PoC
zavisco/CVE-2026-64849.yaml
CVE-2026-64849CRITICALsob ataque19 ago 2026
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
98RISCO
abrir
GitHub PoC1
renzi25031469/CVE-2026-19478
CVE-2026-19478CRITICAL19 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir
GitHub PoC
CVE-2026-64849 PoC
CVE-2026-64849CRITICALsob ataque19 ago 2026
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
98RISCO
abrir
VulnCheck XDB
local
CVE-2019-2215HIGHsob ataque19 ago 2026
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir
GitHub PoC
open-flaw/CVE-2026-56848
CVE-2026-56848HIGH19 ago 2026
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_m
41RISCO
abrir
GitHub PoC
JetBrains TeamCity On-Premises CVE-2026-63077 Emergency Hardening & Patch Runbook Package
CVE-2026-63077CRITICALsob ataque19 ago 2026
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-19598CRITICAL19 ago 2026
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-19478CRITICAL19 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir
GitHub PoC
CVE-2026-73072 - Draft or TODO
CVE-2026-73072HIGH19 ago 2026
Vim: Heap Buffer Overflow when Loading a Spell File
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALsob ataqueransomware19 ago 2026
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISCO
abrir
anteriorpágina 13 / 2.644próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.