Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
79.305 exploits
Exploit-DB
Microsoft Edge 150.0.4078.48 - RCE
CVE-2026-58289CRITICALlocalmultiple10 ago 2026
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
48RISCO
abrir
Exploit-DB
OrkesConductor 3.30.2 - Unauthenticated Remote Code Execution
CVE-2026-58138CRITICALwebappsmultiple10 ago 2026
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
63RISCO
abrir
GitHub PoC1
Saku0512/CVE-2026-9086-poc
CVE-2026-9086HIGH10 ago 2026
Keycloak: keycloak: cross-site scripting (xss) via case-insensitive uri validation bypass
41RISCO
abrir
GitHub PoC1
IamDremig/CVE-2026-65591
CVE-2026-65591HIGH10 ago 2026
n8n before 1.123.64 Sanitizer Bypass Remote Code Execution
41RISCO
abrir
GitHub PoC1
IamDremig/CVE-2026-14802
CVE-2026-14802MEDIUM10 ago 2026
react create-react-app react-dev-utils openBrowser.js startBrowserProcess os command injection
33RISCO
abrir
VulnCheck XDB
local
CVE-2025-7771HIGH10 ago 2026
Code Execution / Escalation of Privileges in ThrottleStop
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL10 ago 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
GitHub PoC1
POC 4 CVE-2026-15038
CVE-2026-15038CRITICAL09 ago 2026
InfiniteWP Client < 1.13.6 - Unauthenticated Administrator Account Takeover on Multisite
48RISCO
abrir
GitHub PoC3
eh-amish/CVE-2026-64638-XSS-to-Shell-PoC
CVE-2026-64638HIGH09 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RISCO
abrir
GitHub PoC3
🔥 XSS2Shell — CVE-2026-64638 Scanner & PoC Toolkit
CVE-2026-64638HIGH09 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RISCO
abrir
GitHub PoC6
CVE-2026-34910/34909 — UniFi OS unauth RCE + file read via ..%2f auth bypass (CVSS 10.0, KEV, Mirai ITW)
CVE-2026-34910CRITICALsob ataque09 ago 2026
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALsob ataque09 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC1
CVE-2026-64638 — WordPress Pre-Auth Reflected XSS → RCE via DOM Clobbering + Application Password Theft + REST API Plugin Activation. Dual-mode PoC (XSS chain & direct).
CVE-2026-64638HIGH09 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RISCO
abrir
GitHub PoC
XSS2Shell ULTIMATE v3.0 is a powerful exploitation tool that chains Cross-Site Scripting (XSS) vulnerabilities in WordPress to achieve Remote Code Execution (RCE). This tool exploits CVE-2026-64638 to gain full control over vulnerable WordPress installations.
CVE-2026-64638HIGH09 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RISCO
abrir
GitHub PoC1
A Proof-Of-Concept for the CVE-2021-44228 vulnerability.
CVE-2021-44228CRITICALsob ataqueransomware09 ago 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
Windwos Zero Day Local PrivESc Exploit (CVE-2026-41091)
CVE-2026-41091HIGHsob ataque09 ago 2026
Microsoft Defender Elevation of Privilege Vulnerability
71RISCO
abrir
GitHub PoC
Exploiting the .lnk vulnerability and operating system handling mechanisms regarding explorer.exe and USB drives.
CVE-2017-8464HIGHsob ataque09 ago 2026
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RISCO
abrir
GitHub PoC
Technical vulnerability analysis and CVE briefing for CVE-2026-9645 affecting ScadaBR.
CVE-2026-9645CRITICAL09 ago 2026
ScadaBR Authenticated Remote Code Execution
48RISCO
abrir
VulnCheck XDB
client-side
CVE-2017-8464HIGHsob ataque09 ago 2026
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHsob ataqueransomware09 ago 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499
CVE-2026-43499HIGH09 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499 (Note: Fork)
CVE-2026-43499HIGH09 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
PoC for CVE-2025-59528 used to achieve remote code execution on the Silentium machine at HTB
CVE-2025-59528CRITICAL09 ago 2026
Flowise has Remote Code Execution vulnerability
85RISCO
abrir
GitHub PoC
WP2Shell is a powerful and modular exploit framework that combines two critical WordPress vulnerabilities (CVE-2026-63030 and CVE-2026-60137) to achieve complete compromise of a target site without any credentials.
CVE-2026-63030CRITICALsob ataque09 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC1
PoC for CVE-2025-3248: unauthenticated RCE in Langflow < 1.3.0 via /api/v1/validate/code.
CVE-2025-3248CRITICALsob ataqueransomware09 ago 2026
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
GitHub PoC1
CVE-2026-69084/69085 — SiYuan arbitrary SQL execution via searchEmbedBlock + searchDocs SQLi (CVSS 9.9). Verified on v3.7.2, rejected on v3.7.3.
CVE-2026-69084CRITICAL09 ago 2026
SiYuan before v3.7.3 SQL Injection via searchEmbedBlock
63RISCO
abrir
GitHub PoC
Emaar1x/CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware09 ago 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC8
CVE-2026-64638: WordPress Pre-auth XSS → RCE (XSS2Shell) PoC
CVE-2026-64638HIGH08 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RISCO
abrir
GitHub PoC
teamcity teamcity-CVE-2026-63077 exploitation pcap
CVE-2026-63077CRITICALsob ataque08 ago 2026
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
100RISCO
abrir
GitHub PoC2
CVE-2026-60004 — Gitea Pre-Auth RCE via diffpatch hook injection
CVE-2026-60004CRITICAL08 ago 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISCO
abrir
anteriorpágina 23 / 2.644próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.