Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
79.305 exploits
GitHub PoC
0xROI/CVE-2026-77113
CVE-2026-77113MEDIUM18 ago 2026
Path Traversal Vulnerability in apport-unpack
33RISCO
abrir
GitHub PoC
codeb0ssx/CVE-2026-64849-PoC
CVE-2026-64849CRITICALsob ataque18 ago 2026
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
98RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-62593CRITICALsob ataque18 ago 2026
Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack
83RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-19478CRITICAL18 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir
GitHub PoC
Technical analysis and clean Java Thread Echo PoC for Oracle WebLogic Server vulnerability chain.
CVE-2020-14882CRITICALsob ataque18 ago 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-19598CRITICAL18 ago 2026
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALsob ataque18 ago 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC10
Reproducible A/B lab + safe PoC for GitLab CVE-2026-19478 / CVE-2026-19650 (GraphQL @gl_introduced)
CVE-2026-19478CRITICAL18 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir
GitHub PoC1
CVE-2026-62737 ExecutionContext.sys arbitrary kernel-call PoC
CVE-2026-62737HIGH17 ago 2026
Windows Kernel Elevation of Privilege Vulnerability
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-72898CRITICALsob ataque17 ago 2026
Metabase SQL injection via password reset endpoint
100RISCO
abrir
GitHub PoC
CVE-2026-59310 PoC
CVE-2026-59310CRITICALsob ataque17 ago 2026
vCenter directory-traversal vulnerability
90RISCO
abrir
GitHub PoC
CVE-2026-15826, CVE-2026-15748
CVE-2026-15826CRITICAL17 ago 2026
User Profile Builder <= 3.16.4 - Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter
63RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2017-7494CRITICALsob ataqueransomware17 ago 2026
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISCO
abrir
GitHub PoC
Isolated Docker lab, static detection scanner, and PoC validation for React2Shell (CVE-2025-55182).
CVE-2025-55182CRITICALsob ataqueransomware17 ago 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
Exploit-DB
D-Link DNS_340L - OS Command Injection
CVE-2024-10914CRITICALremotehardware17 ago 2026
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir
VulnCheck XDB
local
CVE-2018-8611HIGHsob ataque17 ago 2026
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "
71RISCO
abrir
GitHub PoC
CVE-2026-74943, Use after free in Firefox RasterImage (sec-high)
CVE-2026-74943CRITICAL17 ago 2026
Use-after-free in the Graphics: ImageLib component
48RISCO
abrir
GitHub PoC
CVE-2026-19650, CVE-2026-19478 - Draft or TODO
CVE-2026-19650HIGH17 ago 2026
Cross-Site Request Forgery (CSRF) in GitLab
41RISCO
abrir
VulnCheck XDB
local
CVE-2025-21479HIGHsob ataque17 ago 2026
Incorrect Authorization in Graphics
71RISCO
abrir
GitHub PoC9
Kernel root exploit (CVE-2026-43499) for some 5.X devices (mostly Amazon)
CVE-2026-43499HIGH17 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
golang.org/x/text v0.33.0 backport of CVE-2026-56852 (GO-2026-5970) for Go 1.24
CVE-2026-56852HIGH17 ago 2026
Infinite loop on invalid input in golang.org/x/text
41RISCO
abrir
GitHub PoC
CVE-2026-33017, vuln in langflow.
CVE-2026-33017CRITICALsob ataque17 ago 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALsob ataque17 ago 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir
GitHub PoC
CVE-2026-59310
CVE-2026-59310CRITICALsob ataque17 ago 2026
vCenter directory-traversal vulnerability
90RISCO
abrir
GitHub PoC
CVE-2026-68138 Linux Local Privilege Escalation Exploit
CVE-2026-68138HIGH17 ago 2026
net/sched: serialize qdisc_rtab_list against concurrent get/put
41RISCO
abrir
GitHub PoC1
ZendTo unauthenticated ClamAV CVE-2026-20217 RCE and default-profile root escalation reproduction
CVE-2026-20217HIGH17 ago 2026
ClamAV PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerability
41RISCO
abrir
GitHub PoC1
CVE-2026-71518 — Typemill <2.26.0 unauthenticated authorization bypass in media file download (path-equivalent URL variants). Advisory + PoC.
CVE-2026-71518HIGH17 ago 2026
Typemill < 2.26.0 Authorization Bypass via Media File Download Route
41RISCO
abrir
GitHub PoC6
A poc and write-up for CVE-2026-40345
CVE-2026-40345HIGH17 ago 2026
deepmerge-ts: Stack exhaustion when merging recursive object graphs
41RISCO
abrir
Exploit-DB
phpSysInfo 3.4.5 - IP Allowlist Bypass
CVE-2026-55584HIGHremotelinux17 ago 2026
phpSysInfo: IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP headers
41RISCO
abrir
Exploit-DB
Nmap 7.99 - Extension Header Integer Underflow
CVE-2026-58058MEDIUMdosmultiple17 ago 2026
Nmap - Integer Underflow in IPv6 Extension Header Parsing
33RISCO
abrir
anteriorpágina 15 / 2.644próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.