Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
14.946 exploits
GitHub PoC
0init/CVE-2026-45185
CVE-2026-45185CRITICAL07 ago 2026
Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing p
48RISCO
abrir
GitHub PoC3
CVE-2026-64561
CVE-2026-64561HIGH07 ago 2026
KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
41RISCO
abrir
GitHub PoC1
Guest-to-host KVM/x86 escape exploiting CVE-2026-64561, delivering a full PoC chain and analysis for security researchers.
CVE-2026-64561HIGH07 ago 2026
KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
41RISCO
abrir
GitHub PoC19
Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
CVE-2026-63077CRITICALsob ataque07 ago 2026
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
100RISCO
abrir
GitHub PoC
Hunt-Benito/go-without-bounds-cve-2026-67822-stack-overflow-in-tenda-w6-s-wifissidset
CVE-2026-67822CRITICAL07 ago 2026
Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The fu
48RISCO
abrir
GitHub PoC
CVE-2026-67598 — Emlog Pro: disabled TLS certificate validation in AI assistant (MITM → API-key theft). CWE-295, CVSS 9.1. Reported by @IlhomjonR.
CVE-2026-67598CRITICAL06 ago 2026
Emlog Pro 2.6.23 TLS Certificate Validation Disabled in ai.php
48RISCO
abrir
GitHub PoC
The Joomla extension PhocaCommander is vulnerable to Path Traversal in the getSource function - CVSS 8.2
CVE-2026-66491HIGH06 ago 2026
Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3
41RISCO
abrir
GitHub PoC
查出 Spring Boot 内嵌 Tomcat 的真实版本(pom 里没有),并对每条 2026 年 CVE 同时给出 ASF 官方评级与 GitHub 评级、触发条件、以及这条会不会进 Dependabot 告警 CVE-2026-41293
CVE-2026-41293CRITICAL06 ago 2026
Apache Tomcat: HTTP/2 request headers not validated
48RISCO
abrir
GitHub PoC58
Microsoft SharePoint JWT Authentication Bypass (CVE-2026-55040)
CVE-2026-55040CRITICALsob ataque06 ago 2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISCO
abrir
GitHub PoC
tfawnies/CVE-2026-64633
CVE-2026-64633CRITICAL06 ago 2026
A vulnerability allowing remote unauthenticated code execution on the agent host.
48RISCO
abrir
GitHub PoC
Shams-Ul-Mehmood/CVE-2018-7600-Drupalgeddon2-RCE
CVE-2018-7600CRITICALsob ataqueransomware06 ago 2026
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC
The Joomla extension PhocaCommander is vulnerable to Path Traversal in the file upload action - CVSS 6.1
CVE-2026-66492MEDIUM06 ago 2026
Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3
33RISCO
abrir
GitHub PoC1
Security research: Trezor Safe calldata confirmation-binding bypass vulnerability analysis. Educational proof-of-concept for hardware wallet transaction display verification.
CVE-2026-65058MEDIUM06 ago 2026
Trezor Safe improper security check in on-device display
13RISCO
abrir
GitHub PoC
扫出你实际装的 Apache Shiro 模块与版本,逐条判定官方 26 条 CVE 里哪些真的落在你身上。按「CVE × 模块」判定,零依赖单 jar。 CVE-2026-49268
CVE-2026-49268HIGH06 ago 2026
Apache Shiro: LDAP DN Injection in DefaultLdapRealm
41RISCO
abrir
GitHub PoC
hasan8babiker/CVE-2024-6387
CVE-2024-6387HIGH06 ago 2026
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir
GitHub PoC5
👾 CVE-2026-58048 – cPanel Root SQL Execution Toolkit (CVSS 9.4) | Full Red/Blue Team Toolkit suite for unpatched cPanel & WHM 11.x. 2 tools: Safe Checker (audit/reporting), Weaponized (reverse shell, persistence, UDF RCE, deployment, file read/write, database operations, mass scan). w/Python. 🦾 Use Ethically, Stay Legal <3
CVE-2026-58048CRITICAL06 ago 2026
Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
48RISCO
abrir
GitHub PoC
CVE-2022-31626, CVE-2024-2961, CVE-2019-6977, PHP security research
CVE-2019-697706 ago 2026
gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch funct
35RISCO
abrir
GitHub PoC
Notepad++ CVE-2026-52886 — session.xml backupFilePath starts_with() path traversal (GHSA-rqfm-pw34-r7j6)
CVE-2026-52886MEDIUM06 ago 2026
Notepad++: session.xml backupFilePath starts_with Bypass
33RISCO
abrir
GitHub PoC
0xdak/CVE-2026-69098_exploit
CVE-2026-69098CRITICAL06 ago 2026
kotaemon 0.12.0 Unauthenticated Remote Code Execution via Insecure Deserialization
48RISCO
abrir
GitHub PoC4
Proof of concept for CVE-2026-18649, a remote denial of service vulnerability in GStreamer's H.264 RTP depayloader (rtph264depay).
CVE-2026-18649HIGH06 ago 2026
Gst-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay rtp depayloaders
41RISCO
abrir
GitHub PoC2
CVE-2026-56164 is a critical missing-authentication vulnerability affecting on-premises Microsoft SharePoint Server. It allows unauthenticated, remote attackers to elevate privileges over a network.
CVE-2026-56164MEDIUMsob ataque06 ago 2026
Microsoft SharePoint Server Elevation of Privilege Vulnerability
68RISCO
abrir
GitHub PoC
Read-only N-able N-central CVE-2026-18556/CVE-2026-18577 post-exploitation IoC hunter for Windows endpoints
CVE-2026-18556HIGHsob ataque06 ago 2026
Unauthenticated administrative account takeover
83RISCO
abrir
GitHub PoC1
CVE-2026-0163 Exploit
CVE-2026-0163CRITICAL06 ago 2026
In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to rem
48RISCO
abrir
GitHub PoC1
woshidashabi1126/CVE-2026-70553-PoC
CVE-2026-70553CRITICAL06 ago 2026
MaxSite CMS Unauthenticated RCE via Install Endpoint
48RISCO
abrir
GitHub PoC1
Joomla RSFiles 未授权文件上传CVE-2026-57827检测&利用脚本
CVE-2026-57827CRITICAL06 ago 2026
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12
63RISCO
abrir
GitHub PoC1
Hunt-Benito/e-is-for-exploit-cve-2026-17543-php-pgsql-sql-injection-backslash-breakout
CVE-2026-17543HIGH06 ago 2026
SQL injection in ext-pgsql via E'...' backslash breakout
41RISCO
abrir
GitHub PoC
The Joomla extension PhocaCommander is vulnerable to Path Traversal in delete, copy, move actions - CVSS 6.4
CVE-2026-66493MEDIUM06 ago 2026
Joomla Extension - phoca.cz - Path traversal vulnerability in Phoca Commander 1.0.0-6.1.3
33RISCO
abrir
GitHub PoC
CVE-2026-71211 exploit
CVE-2026-71211HIGH05 ago 2026
mlflow - Unvalidated Gateway Secret api_base Enables SSRF via Gateway Proxy Endpoint
41RISCO
abrir
GitHub PoC
CVE-2026-33017 Langflow RCE PoC
CVE-2026-33017CRITICALsob ataque05 ago 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir
GitHub PoC
Non-destructive proof-of-concept and verification harness for CVE-2026-60137, a blind SQL injection in WordPress core (`WP_Query::author__not_in`), reachable via the REST API's `author_exclude` parameter.
CVE-2026-60137MEDIUMsob ataque05 ago 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISCO
abrir
anteriorpágina 16 / 499próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.