Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.260exploits catalogados
36.452CVEs com exploração pública
24.695testados em laboratório
79.232 exploits
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALsob ataqueransomware01 set 2026
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-21762CRITICALsob ataqueransomware01 set 2026
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISCO
abrir
GitHub PoC1
D-Link DIR-825M formDiskFormat stack overflow + command injection RCE PoC (CVE-2026-82592); for authorized security testing
CVE-2026-82592CRITICAL01 set 2026
D-Link DIR-825M Disk Formatting Handler Endpoint formDiskFormat sub_46725C stack-based overflow
48RISCO
abrir
Exploit-DB
Grav CMS 2.0.7 - RCE
CVE-2026-65008CRITICALwebappsmultiple01 set 2026
Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData
48RISCO
abrir
GitHub PoC
CVE-2026-82329 - Draft or TODO
CVE-2026-82329CRITICALsob ataque01 set 2026
Potential authentication bypass leading to administrative access in Artifactory
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-0768CRITICAL01 set 2026
Langflow code Code Injection Remote Code Execution Vulnerability
48RISCO
abrir
Exploit-DB
EasyAppointments 1.5.1 - Blind SQL Injection
CVE-2025-50455CRITICALwebappsmultiple01 set 2026
SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAp
48RISCO
abrir
GitHub PoC
PostgreSQL の全文検索(tsvector/tsquery)に見つかった範囲外書き込み脆弱性 CVE-2026-14662 を、修正前(18.4)と修正後(18.6)を Docker で並べて動かして検証した記録と発表資料
CVE-2026-14662HIGH01 set 2026
PostgreSQL tsvector and tsquery undersize allocations, via integer wraparound
41RISCO
abrir
GitHub PoC1
Poc of CVE-2026-13753
CVE-2026-13753HIGH01 set 2026
Certain HP DeskJet All in One – Potential Information Disclosure
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALsob ataqueransomware01 set 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
VulnCheck XDB
local
CVE-2021-3493HIGHsob ataque01 set 2026
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISCO
abrir
Exploit-DB
miniOrange 5.4.3 - Unauthenticated Auth Bypass
CVE-2026-15013CRITICALwebappsmultiple01 set 2026
SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm Confusion
48RISCO
abrir
Exploit-DB
Wolf CMS 0.8.3.1 - RCE v
CVE-2026-67206HIGHwebappsmultiple01 set 2026
Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Upload
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALsob ataque01 set 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC7
CVE-2026-82329 JFrog Artifactory unauthenticated auth-bypass: reproducible Docker lab + URL-parameter validator PoC + patch-diff analysis
CVE-2026-82329CRITICALsob ataque01 set 2026
Potential authentication bypass leading to administrative access in Artifactory
93RISCO
abrir
GitHub PoC
PoC for Unauthenticated Reflected Cross-Site Scripting (XSS) in RegistrationMagic WordPress Plugin
CVE-2026-82221HIGH01 set 2026
WordPress RegistrationMagic plugin <= 6.0.9.8 - Cross Site Scripting (XSS) vulnerability
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-18963CRITICAL31 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISCO
abrir
GitHub PoC
GiveWP <= 4.16.7.1 Unauthenticated PHP Object Injection → RCE
CVE-2026-82222CRITICAL31 ago 2026
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RISCO
abrir
GitHub PoC
Reflected XSS via search GET Parameter in Phoca Download
CVE-2026-76569MEDIUM31 ago 2026
Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4
33RISCO
abrir
GitHub PoC
Weak-RNG stream-sweep research (CVE-2026-71851 class): PRNG schemes x seeds -> BIP39 -> victim set membership
CVE-2026-71851CRITICAL31 ago 2026
crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
48RISCO
abrir
GitHub PoC1
Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp Vault (CVE-2026-5006), HashiCorp Nomad (CVE-2026-7474).
CVE-2026-18963CRITICAL31 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-9198CRITICALsob ataque31 ago 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-60004CRITICAL31 ago 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISCO
abrir
GitHub PoC1
Social Media Infrastructure Vulnerability Research. CVE-2026-78905: OAuth token reuse and session hijacking in Facebook's Graph API.
CVE-2026-78905HIGH30 ago 2026
Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitra
41RISCO
abrir
GitHub PoC2
CBDC Infrastructure Vulnerability Research. CVE-2026-78904: Infinite mint and redemption bypass in central bank digital currency APIs.
CVE-2026-78904CRITICAL30 ago 2026
Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitra
48RISCO
abrir
GitHub PoC1
Offensive Research & Exploit Development. Vulnerability research, PoC development, and offensive tooling for financial infrastructure.
CVE-2026-78903LOW30 ago 2026
Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromise
28RISCO
abrir
GitHub PoC
CVE-2026-45833 ChromaDB
CVE-2026-45833CRITICAL30 ago 2026
A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacke
48RISCO
abrir
GitHub PoC
CitrixBleed Exploit Tool - CVE-2025-5777 & CVE-2026-8452. Unauthenticated remote memory read from Citrix NetScaler ADC & Gateway. Steal admin session tokens, extract nsroot hashes, dump secrets, and bypass MFA. Python 3 exploit with full memory parsing.
CVE-2026-8452HIGHsob ataque30 ago 2026
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
71RISCO
abrir
GitHub PoC
Balboa form Command Injection POC
CVE-2026-67363HIGH30 ago 2026
Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2
41RISCO
abrir
GitHub PoC
🫖 Contract-correlated discovery and authorized validation tool for Gitea CVE-2026-60004
CVE-2026-60004CRITICAL30 ago 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISCO
abrir
anteriorpágina 2 / 2.642próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.