Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8.829Nuclei 4.357Metasploit 3.489✓ só verificadosrecentespopularesrisco
14.991 exploits
GitHub PoC
Isolated regression and security-control lab for CVE-2026-59891 in @sigstore/oci
Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry
48RISCO
abrir ↗GitHub PoC★ 10
KSU installer for supported firmware with CVE-2026-43499
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir ↗GitHub PoC★ 1
A PoC for CVE-2026-64725
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS
41RISCO
abrir ↗GitHub PoC
Simulated a real-world attack (CVE-2011-2523) against a vulnerable host, then cross-checked detection coverage against an existing Wazuh/Suricata/Zeek SOC — uncovering and fixing 5 real monitoring pipeline bugs along the way.
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir ↗GitHub PoC
CVE-2026-61511 - Draft or Todo
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
85RISCO
abrir ↗GitHub PoC★ 3
cve-2026-61511
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
85RISCO
abrir ↗GitHub PoC★ 11
A proof-of-concept script to exploit CVE-2026-16232, an authentication bypass via the SmartConsole login process using an application token.
Authentication Bypass in the SmartConsole Login Process Using an Application Token
100RISCO
abrir ↗GitHub PoC
CyberVinner/CP-PLUS-EZ-P21-CVE-2026-65893-65894
Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera
41RISCO
abrir ↗GitHub PoC
0xdak/CVE-2025-71389_exploit
Cal.com before 5.9.9 Remote Code Execution via RSC
48RISCO
abrir ↗GitHub PoC
CVE-2026-14856 TastyIgniter v4.3.0
Stored Cross-Site Scripting (XSS) in TastyIgniter Media Manager
33RISCO
abrir ↗GitHub PoC★ 3
CVE-2026-53264 - Draft or Todo
net/sched: act_api: use RCU with deferred freeing for action lifecycle
41RISCO
abrir ↗GitHub PoC★ 4
Fastjson 1.2.83 RCE 靶场环境 (CVE-2026-16723)
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISCO
abrir ↗GitHub PoC
bha-vin/CVE-2026-64600-Exploit
xfs: resample the data fork mapping after cycling ILOCK
41RISCO
abrir ↗GitHub PoC
letsr00t/RefluxFS_CVE-2026-64600
xfs: resample the data fork mapping after cycling ILOCK
41RISCO
abrir ↗GitHub PoC
Proof of Concept for CVE-2026-65761 - EasyStore Pro Unauthenticated SQL Injection via `filter_sortby`
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1
63RISCO
abrir ↗GitHub PoC
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Microsoft SharePoint Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC★ 12
Unprivileged user to root on macOS Sonoma, Sequoia, and Tahoe. Patched in macOS 26.6 / 15.7.8 / 14.8.8.
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonom
41RISCO
abrir ↗GitHub PoC★ 1
A poc for a vulnerability in ZTE File Manager (zte.com.cn.filer) which allows to read arbitrary files from other apps as the privileges of this file manager
Path Traversal Vulnerability in ZTE Blade A75 5G
28RISCO
abrir ↗GitHub PoC
Phucc29/CVE-2025-55182
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗GitHub PoC
Procjevt/CVE-2026-58138
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
63RISCO
abrir ↗GitHub PoC★ 1
CVE-2026-65008
Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData
48RISCO
abrir ↗GitHub PoC
The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings.
BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback Bug
41RISCO
abrir ↗GitHub PoC
PoC and analysis of CVE-2021-41773
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗GitHub PoC★ 2
Read-only WordPress security scanner for HestiaCP servers. Detects wp2shell compromise indicators (CVE-2026-63030 / CVE-2026-60137) across all hosted sites — per-user email reports, core file diff against clean WordPress, PHP/JS/htaccess/image analysis, and optional AI evaluation via Claude API.
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir ↗GitHub PoC★ 3
A POC for the recently discovered Qualys bug on COW with XFS
xfs: resample the data fork mapping after cycling ILOCK
41RISCO
abrir ↗GitHub PoC★ 1
CVE-2026-43499: Linux kernel futex PI use-after-free research package
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir ↗GitHub PoC★ 1
CVE-2026-15013
SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm Confusion
48RISCO
abrir ↗GitHub PoC★ 1
soralis0912/CVE-2026-43499-pmg110-root
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.