Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
79.305 exploits
GitHub PoC
golang.org/x/text v0.33.0 backport of CVE-2026-56852 (GO-2026-5970) for Go 1.24
CVE-2026-56852HIGH17 ago 2026
Infinite loop on invalid input in golang.org/x/text
41RISCO
abrir
GitHub PoC
CVE-2026-15826, CVE-2026-15748
CVE-2026-15826CRITICAL17 ago 2026
User Profile Builder <= 3.16.4 - Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter
63RISCO
abrir
GitHub PoC
CVE-2026-59310
CVE-2026-59310CRITICALsob ataque17 ago 2026
vCenter directory-traversal vulnerability
90RISCO
abrir
GitHub PoC
CVE-2026-59310 PoC
CVE-2026-59310CRITICALsob ataque17 ago 2026
vCenter directory-traversal vulnerability
90RISCO
abrir
GitHub PoC
katranSefa/CVE-2026-13714
CVE-2026-13714CRITICAL17 ago 2026
Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
48RISCO
abrir
GitHub PoC9
Kernel root exploit (CVE-2026-43499) for some 5.X devices (mostly Amazon)
CVE-2026-43499HIGH17 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
Exploit-DB
Joomla JCE_2.9.15 - Remote Code Execution
CVE-2026-48907CRITICALsob ataquewebappsmultiple17 ago 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISCO
abrir
GitHub PoC
CVE-2026-33017, vuln in langflow.
CVE-2026-33017CRITICALsob ataque17 ago 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir
GitHub PoC
CVE-2026-19650, CVE-2026-19478 - Draft or TODO
CVE-2026-19650HIGH17 ago 2026
Cross-Site Request Forgery (CSRF) in GitLab
41RISCO
abrir
GitHub PoC
iPad 8 iPadOS 26.3 AVE toolchain research (CVE-2026-64747 class)
CVE-2026-64747HIGH17 ago 2026
A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iO
41RISCO
abrir
GitHub PoC
CVE-2026-74945, Uninitialized heap disclosure via a crafted web font (sec-high)
CVE-2026-74945MEDIUM17 ago 2026
Information disclosure in the Graphics: Text component
33RISCO
abrir
GitHub PoC
Isolated Docker lab, static detection scanner, and PoC validation for React2Shell (CVE-2025-55182).
CVE-2025-55182CRITICALsob ataqueransomware17 ago 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
Exploit-DB
webpack_devserver 5.2.5 - CSRF
CVE-2026-14620MEDIUMwebappsmultiple17 ago 2026
webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints
33RISCO
abrir
VulnCheck XDB
local
CVE-2025-21479HIGHsob ataque17 ago 2026
Incorrect Authorization in Graphics
71RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALsob ataque17 ago 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir
GitHub PoC
eh-amish/Windows-Defender-Security-Auditor-CVE-2026-50656-
CVE-2026-50656HIGH16 ago 2026
Microsoft Defender Elevation of Privilege Vulnerability
46RISCO
abrir
GitHub PoC
PoC for CVE-2026-73519 - WolfStack hardcoded cluster secret leads to unauthenticated RCE (CVSS 9.8)
CVE-2026-73519CRITICAL16 ago 2026
WolfStack < 25.9.2 Hard-coded Secret Authentication Bypass via X-WolfStack-Secret
48RISCO
abrir
VulnCheck XDB
client-side
CVE-2020-6418HIGHsob ataque16 ago 2026
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RISCO
abrir
GitHub PoC
POC of CVE-2026-51031 for arbitrary local file read
CVE-2026-51031HIGH16 ago 2026
FlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. T
41RISCO
abrir
GitHub PoC
React2Shell(CVE-2025-55182) 취약점 기반 침해 시나리오를 재현하고, Wazuh/Sysmon/Coraza WAF 로그로 침해사고를 분석·대응한 DFIR 프로젝트
CVE-2025-55182CRITICALsob ataqueransomware16 ago 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
PoC: changedetection.io settings blind-merge mass assignment (CVE-2026-71204, Medium 6.3)
CVE-2026-71204MEDIUM16 ago 2026
changedetection.io - Omitted Checkbox in /settings Save Silently Disables API Key Enforcement
33RISCO
abrir
GitHub PoC1
CVE-2026-73678 — MindsDB Minds Platform unauthenticated RCE via scratchpad exec (CVSS 10.0). Verified end-to-end with real LLM
CVE-2026-73678CRITICAL16 ago 2026
MindsDB Minds Platform v26.1.0 Unauthenticated RCE via scratchpad exec()
48RISCO
abrir
GitHub PoC
CVE-2026-73633(S2-072)概念验证代码
CVE-2026-73633HIGH16 ago 2026
Apache Struts: Unbounded read of a JSON request body
41RISCO
abrir
GitHub PoC
PoC: Grafana Editor role deletes protected contact points (CVE-2026-72585, Medium 6.5)
CVE-2026-7258516 ago 2026
23RISCO
abrir
GitHub PoC
a-mansilla/CVE-2020-6418
CVE-2020-6418HIGHsob ataque16 ago 2026
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RISCO
abrir
GitHub PoC
Simple script to achieve safe and non-desruptive active detection of CVE-2026-72898 (SQLi in Metabase)
CVE-2026-72898CRITICALsob ataque16 ago 2026
Metabase SQL injection via password reset endpoint
100RISCO
abrir
GitHub PoC
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
CVE-2026-18366CRITICAL16 ago 2026
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
48RISCO
abrir
GitHub PoC3
Using CVE-2026-43499 to root your Galaxy S24 Ultra(SM-S9280 ,(China / Hong Kong SAR / Taiwan))
CVE-2026-43499HIGH16 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC3
One-Day POC | GeoServer Unauthenticated SQL injection to complete RCE
CVE-2026-76904CRITICAL16 ago 2026
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
63RISCO
abrir
GitHub PoC1
Non-destructive detector for CVE-2026-64638 (XSS2Shell) — WordPress pre-auth XSS reflection primitive
CVE-2026-64638HIGH16 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RISCO
abrir
anteriorpágina 16 / 2.644próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.