Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8.883Nuclei 4.361Metasploit 3.493✓ só verificadosrecentespopularesrisco
79.305 exploits
GitHub PoC
codeb0ssx/CVE-2026-64849-PoC
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
98RISCO
abrir ↗VulnCheck XDB
initial-access
Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack
83RISCO
abrir ↗VulnCheck XDB
initial-access
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir ↗GitHub PoC
Technical analysis and clean Java Thread Echo PoC for Oracle WebLogic Server vulnerability chain.
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir ↗VulnCheck XDB
initial-access
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
63RISCO
abrir ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir ↗GitHub PoC★ 10
Reproducible A/B lab + safe PoC for GitLab CVE-2026-19478 / CVE-2026-19650 (GraphQL @gl_introduced)
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir ↗GitHub PoC★ 1
CVE-2026-62737 ExecutionContext.sys arbitrary kernel-call PoC
Windows Kernel Elevation of Privilege Vulnerability
41RISCO
abrir ↗GitHub PoC
CVE-2026-15826, CVE-2026-15748
User Profile Builder <= 3.16.4 - Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter
63RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISCO
abrir ↗GitHub PoC
Isolated Docker lab, static detection scanner, and PoC validation for React2Shell (CVE-2025-55182).
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗Exploit-DB
D-Link DNS_340L - OS Command Injection
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir ↗VulnCheck XDB
local
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "
71RISCO
abrir ↗GitHub PoC
CVE-2026-74943, Use after free in Firefox RasterImage (sec-high)
Use-after-free in the Graphics: ImageLib component
48RISCO
abrir ↗GitHub PoC
CVE-2026-19650, CVE-2026-19478 - Draft or TODO
Cross-Site Request Forgery (CSRF) in GitLab
41RISCO
abrir ↗GitHub PoC★ 9
Kernel root exploit (CVE-2026-43499) for some 5.X devices (mostly Amazon)
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir ↗GitHub PoC
golang.org/x/text v0.33.0 backport of CVE-2026-56852 (GO-2026-5970) for Go 1.24
Infinite loop on invalid input in golang.org/x/text
41RISCO
abrir ↗GitHub PoC
CVE-2026-33017, vuln in langflow.
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir ↗VulnCheck XDB
initial-access
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir ↗GitHub PoC
CVE-2026-68138 Linux Local Privilege Escalation Exploit
net/sched: serialize qdisc_rtab_list against concurrent get/put
41RISCO
abrir ↗GitHub PoC★ 1
ZendTo unauthenticated ClamAV CVE-2026-20217 RCE and default-profile root escalation reproduction
ClamAV PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerability
41RISCO
abrir ↗GitHub PoC★ 1
CVE-2026-71518 — Typemill <2.26.0 unauthenticated authorization bypass in media file download (path-equivalent URL variants). Advisory + PoC.
Typemill < 2.26.0 Authorization Bypass via Media File Download Route
41RISCO
abrir ↗GitHub PoC★ 6
A poc and write-up for CVE-2026-40345
deepmerge-ts: Stack exhaustion when merging recursive object graphs
41RISCO
abrir ↗Exploit-DB
phpSysInfo 3.4.5 - IP Allowlist Bypass
phpSysInfo: IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP headers
41RISCO
abrir ↗Exploit-DB
Nmap 7.99 - Extension Header Integer Underflow
Nmap - Integer Underflow in IPv6 Extension Header Parsing
33RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.