Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
79.305 exploits
GitHub PoC
PoC: changedetection.io unauthenticated OpenAPI schema disclosure (CVE-2026-71203, Medium 5.3)
CVE-2026-71203MEDIUM16 ago 2026
changedetection.io - Missing Authentication on /api/v1/full-spec Discloses Full OpenAPI Schema
33RISCO
abrir
GitHub PoC
a-mansilla/CVE-2020-6418
CVE-2020-6418HIGHsob ataque16 ago 2026
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RISCO
abrir
GitHub PoC
POC of CVE-2026-51031 for arbitrary local file read
CVE-2026-51031HIGH16 ago 2026
FlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. T
41RISCO
abrir
VulnCheck XDB
client-side
CVE-2020-6418HIGHsob ataque16 ago 2026
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RISCO
abrir
GitHub PoC
React2Shell(CVE-2025-55182) 취약점 기반 침해 시나리오를 재현하고, Wazuh/Sysmon/Coraza WAF 로그로 침해사고를 분석·대응한 DFIR 프로젝트
CVE-2025-55182CRITICALsob ataqueransomware16 ago 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
CVE-2026-18366CRITICAL16 ago 2026
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
48RISCO
abrir
GitHub PoC1
CVE-2026-73678 — MindsDB Minds Platform unauthenticated RCE via scratchpad exec (CVSS 10.0). Verified end-to-end with real LLM
CVE-2026-73678CRITICAL16 ago 2026
MindsDB Minds Platform v26.1.0 Unauthenticated RCE via scratchpad exec()
48RISCO
abrir
GitHub PoC2
PoC for CVE-2026-72898
CVE-2026-72898CRITICALsob ataque15 ago 2026
Metabase SQL injection via password reset endpoint
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-72898CRITICALsob ataque15 ago 2026
Metabase SQL injection via password reset endpoint
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataqueransomware15 ago 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC
An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in the Gitea instance.
CVE-2026-20896CRITICAL15 ago 2026
Gitea Docker image trusts spoofable reverse-proxy headers by default
63RISCO
abrir
GitHub PoC
mencari sebuah kerentanan, wodpres dan mengungah shell di kerentanan wodpres tersebut
CVE-2026-6440MEDIUM15 ago 2026
GoodMeet <= 1.1.8 - Cross-Site Request Forgery to Google Meet Credential Reset via 'goodmeet_reset_google_meet_credential'
33RISCO
abrir
GitHub PoC
Alixploit22/CVE-2026-53587
CVE-2026-53587HIGH15 ago 2026
libgit2 - Unauthenticated network-reachable heap out-of-bounds read in transports/smart_pkt.c:set_data
41RISCO
abrir
GitHub PoC1
This repository contains a conceptual patch demonstrating the mitigation for CVE-2026-68820, a critical Use-After-Free (UAF) vulnerability in the Windows Ancillary Function Driver for WinSock (`afd.sys`).
CVE-2026-68820HIGHsob ataque15 ago 2026
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
71RISCO
abrir
GitHub PoC
PoC for CVE-2026-9090 — Casdoor SAML signature bypass (CWE-347). Reproduction-only; coordinated via CERT/CC VU#780781.
CVE-2026-9090CRITICAL15 ago 2026
CVE-2026-9090
48RISCO
abrir
GitHub PoC
uproot <= 5.7.4 code injection via unsafe Python source generation from ROOT TStreamerInfo metadata.
CVE-2026-9147HIGH15 ago 2026
uproot 5.7.4 and prior Code Injection via TStreamerInfo Metadata
41RISCO
abrir
GitHub PoC
Python StateMachine 3.0.0 < 3.2.0 RCE via unsafe SCXML <data expr> evaluation and Python eval() injection.
CVE-2026-47103CRITICAL15 ago 2026
Python StateMachine 3.0.0 < 3.2.0 RCE via SCXML eval() Injection
48RISCO
abrir
GitHub PoC2
CVE-2026-43499 (GhostLock) rt_mutex stack-UAF privilege escalation research on Honor BVL-AN16 (Magic6 Pro, SM8650, kernel 6.1.128). Includes analysis docs, reverse-engineering scripts, disassembly artifacts, and exploit source with honor-BVL-AN16 target adaptation.
CVE-2026-43499HIGH15 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC4
One-command Docker lab reproducing CVE-2026-71362 (Adobe Commerce / Magento Open Source customer-session identity-switch account takeover, APSB26-92, CVSS 9.1) with a PoC and an A/B/A official-patch negative control. For authorized security research and education.
CVE-2026-71362CRITICAL15 ago 2026
Adobe Commerce | Incorrect Authorization (CWE-863)
68RISCO
abrir
GitHub PoC
CVE-2026-43499 research port for Galaxy Z Fold4 SM-F936W F936WVLU1AVGA (in progress)
CVE-2026-43499HIGH15 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
Responsible disclosure write-ups for CVE-2026-8793 - PaperCut NG 25.0.11
CVE-2026-8793MEDIUM15 ago 2026
PaperCut NG/MF: Insufficient brute-force protection
33RISCO
abrir
GitHub PoC4
CVE-2026-72898 PoC : Metabase Unauthenticated SQL Injection
CVE-2026-72898CRITICALsob ataque15 ago 2026
Metabase SQL injection via password reset endpoint
100RISCO
abrir
GitHub PoC
CVE-2026-58231 Detection & Confirmation Script
CVE-2026-58231CRITICAL15 ago 2026
Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
48RISCO
abrir
GitHub PoC
Username Enumeration via Authentication Timing Side-Channel in PaperCut NG
CVE-2026-8794MEDIUM15 ago 2026
PaperCut NG/MF: User enumeration via timing attack
33RISCO
abrir
GitHub PoC
CVE-2026-17544: PHP bcmath OOB write → universal memory-only RCE & disable_functions/open_basedir bypass. Offset-free runtime resolver. Verified on PHP 8.4.x / 8.5.x.
CVE-2026-17544HIGH15 ago 2026
Out-of-bounds write in bccomp() via crafted operand and scale
41RISCO
abrir
GitHub PoC
OpenMed < 1.5.2 unauthenticated RCE via PII privacy-filter model loading and trust_remote_code=True
CVE-2026-47117CRITICAL15 ago 2026
OpenMed < 1.5.2 Remote Code Execution via PII Model Loading
48RISCO
abrir
GitHub PoC
This is my simple implementation of an exploit for the PwnKit vulnerability.
CVE-2021-4034HIGHsob ataqueransomware15 ago 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC469
CVE-2026-9830 Proof of Concept
CVE-2026-9830HIGH15 ago 2026
BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback Bug
41RISCO
abrir
GitHub PoC
Hunt-Benito/bring-your-own-key-cve-2026-73678-unauthenticated-rce-in-mindsdb-cowork
CVE-2026-73678CRITICAL15 ago 2026
MindsDB Minds Platform v26.1.0 Unauthenticated RCE via scratchpad exec()
48RISCO
abrir
GitHub PoC
DuyDuongDuyDuong/CVE-2024-4577-Exploitation-AsyncRAT-Deployment-DFIR-Investigation
CVE-2024-4577CRITICALsob ataqueransomware15 ago 2026
Argument Injection in PHP-CGI
100RISCO
abrir
anteriorpágina 17 / 2.644próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.