Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8.883Nuclei 4.361Metasploit 3.493✓ só verificadosrecentespopularesrisco
79.305 exploits
GitHub PoC
CVE-2026-63077 — Unauthenticated Remote Code Execution in JetBrains TeamCity via agent polling protocol deserialization. CVSS 9.8 CRITICAL. Mass exploitation tool with interactive shell, multi-threading, and real-time result logging.
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
100RISCO
abrir ↗GitHub PoC
Write-up do Sudo Agent CTF (TryHackMe), com enumeração, exploração web, esteganografia, SSH e privilege escalation via CVE-2019-14287.
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISCO
abrir ↗GitHub PoC★ 8
CVE-2026-64638: WordPress Pre-auth XSS → RCE (XSS2Shell) PoC
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISCO
abrir ↗GitHub PoC★ 1
🛡️ CVE-2026-64638 - WordPress Security Assessment Suite (CVSS 8.9) | WordPress 4.7.0-7.0.2 pentest toolkit. Includes vulnerability assessment & advanced analysis modules. 🐍 Safe Check & Exploit, 2 mode. Advanced Blue&Red Team Best 2026-64638 Toolkit, Authorized use only. Stay Legal <3zd
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISCO
abrir ↗GitHub PoC★ 18
Root your Galaxy using CVE-2026-43499
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir ↗GitHub PoC★ 1
XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE PoC mirror — WordSec, MIT; for authorized security testing
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISCO
abrir ↗GitHub PoC★ 1
yogaGymn/XSS2Shell-CVE-2026-64638
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISCO
abrir ↗GitHub PoC
Linux 内核升级指南 - 修复 CVE-2026-64561
KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
41RISCO
abrir ↗VulnCheck XDB
initial-access
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISCO
abrir ↗GitHub PoC★ 1
CVE-2026-64638 (XSS2shell) POC.
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISCO
abrir ↗GitHub PoC★ 2
CVE-2026-60004 — Gitea Pre-Auth RCE via diffpatch hook injection
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISCO
abrir ↗GitHub PoC
PoC for CVE-2026-18953 — arbitrary file write (CWE-22) in awslabs.aws-transform-mcp-server's get_resource tool via the savePath parameter
Improper limitation of a pathname to a restricted directory in aws-transform-mcp-server
33RISCO
abrir ↗GitHub PoC★ 1
MR-LeonardoGomes/XSS2Shell-CVE-2026-64638
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISCO
abrir ↗GitHub PoC
Dungsocool/CVE-2026-64638
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISCO
abrir ↗GitHub PoC
mohwahyudi/poc-CVE-2026-64638-
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISCO
abrir ↗GitHub PoC
Saku0512/CVE-2026-71557-poc
go-git: Malicious reference names may modify files outside the reference storage
33RISCO
abrir ↗GitHub PoC
teamcity teamcity-CVE-2026-63077 exploitation pcap
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
100RISCO
abrir ↗GitHub PoC
Wormable exploit for CVE-2026-57858
Cal.com Cal.diy 6.2.0 Stored XSS via BookingPageTagManager Analytics Tracking ID
48RISCO
abrir ↗GitHub PoC
Giangdurian/CVE-2021-3129
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir ↗GitHub PoC★ 1
CVE-2026-44613
Apache Zeppelin: Cross-site request forgery in REST and WebSocket request handling
33RISCO
abrir ↗GitHub PoC
Shams-Ul-Mehmood/CVE-2021-3156-Project
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISCO
abrir ↗GitHub PoC★ 1
PoC for CVE-2026-71554 - h2 duplicate Host header request smuggling primitive (fixed in 4.4.1)
h2: Duplicate Host header could facilitate request smuggling
33RISCO
abrir ↗GitHub PoC
CVE-2026-64638
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISCO
abrir ↗GitHub PoC
PoC funcional de CVE-2026-64638 (XSS2Shell): cadena pre-auth XSS a RCE en WordPress Core. Laboratorio Docker + servidor atacante Python + análisis técnico y mitigación.
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISCO
abrir ↗GitHub PoC★ 53
XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE chain — PoC exploit + defensive audit tool + nuclei template
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISCO
abrir ↗GitHub PoC
Hunt-Benito/one-multiply-too-many-cve-2026-70638-llama-cpp-android-jni-integer-overflow
llama.cpp b1886–b7445 Integer Overflow via new_1batch() in llama-android.cpp
41RISCO
abrir ↗GitHub PoC★ 1
CVE-2026-70559
Dinky Unauthenticated System Configuration and Credential Disclosure via GET /api/sysConfig/getAll
41RISCO
abrir ↗VulnCheck XDB
initial-access
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.