Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8.883Nuclei 4.361Metasploit 3.493✓ só verificadosrecentespopularesrisco
79.305 exploits
GitHub PoC
George0Papasotiriou/CVE-2026-21015-PHP-Filter-Chain-Arbitrary-File-Read
Incorrect default permissions in FactoryCamera prior to SMR May-2026 Release 1 allows local attacker to access unique id
33RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11120-Command-Injection-via-Git-URL-in-CI-CD-Pipeline
Insufficient validation of untrusted input in Enterprise Reporting in Google Chrome prior to 149.0.7827.53 allowed a rem
48RISCO
abrir ↗GitHub PoC★ 3
GhostLock (CVE-2026-43499) kernel exploit for samsung devices with locked bootloader
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir ↗GitHub PoC★ 1
CVE-2026-66066 — KindaRails2Shell: Rails Active Storage/libvips Arbitrary File Read → RCE. MATLAB/HDF5 dual-identity file → SECRET_KEY_BASE theft → forged variation. CVSS 9.5 | Rails < 8.1.3.1
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RISCO
abrir ↗GitHub PoC
webshellseo8/CVE-2026-12720-Proof-of-Concept
Kirki < 6.0.13 - Unauthenticated PHP Object Injection
41RISCO
abrir ↗GitHub PoC★ 5
WordPress All-in-One Exploit Framework — detector, scanner, enumerator, exploit, escalation. 10 CVEs from the 2026-08 wave incl. CVE-2026-63030 (wp2shell).
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir ↗GitHub PoC
CVE-2026-18577 - Draft
Incomplete patch leads to administrative account takeover
98RISCO
abrir ↗GitHub PoC★ 2
Security research project
Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
48RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11112-XXE-via-SVG-Image-Upload
Insufficient validation of untrusted input in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remo
48RISCO
abrir ↗GitHub PoC
CVE-2026-13934
Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.47 allowed a remote a
48RISCO
abrir ↗GitHub PoC
Foxer131/CVE-2026-70481
Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages
33RISCO
abrir ↗GitHub PoC
CVE-2026-60004 — Gitea <= 1.27.0 Pre-Auth RCE
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISCO
abrir ↗VulnCheck XDB
initial-access
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11115-Database-Connection-String-Injection-via-Env-Variable
Use after free in Updater in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform OS-leve
41RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-21017-LDAP-Anonymous-Bind-Privilege-Escalation
Improper handling of insufficient privileges in SecTelephonyProvider prior to SMR Jun-2026 Release 1 allows local attack
33RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11111-TOCTOU-in-File-Permission-Check-Before-Open
Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bound
41RISCO
abrir ↗VulnCheck XDB
initial-access
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir ↗VulnCheck XDB
initial-access
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir ↗VulnCheck XDB
local
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISCO
abrir ↗GitHub PoC
0xdak/CVE-2026-59243_exploit
Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)
48RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISCO
abrir ↗GitHub PoC★ 1
pgAdmin 4 Import/Export RCE (CVE-2026-17566) PoC - TO PROGRAM injection via backslash-escape mismatch
pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)
48RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11113-SMTP-Header-Injection-in-Contact-Form
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker wh
48RISCO
abrir ↗GitHub PoC
CVE-2026-13934
Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.47 allowed a remote a
48RISCO
abrir ↗GitHub PoC
0xdak/CVE-2026-67340_exploit
ArcadeDB before 26.7.2 Remote Code Execution via Trigger Scripts
41RISCO
abrir ↗GitHub PoC
0xdak/CVE-2026-14483_exploit
Realtyna Organic IDX plugin + WPL Real Estate <= 5.2.0 - Unauthenticated Arbitrary File Upload via 'files[file]' Parameter via Public I/O 'set_property' Command
63RISCO
abrir ↗GitHub PoC★ 17
CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISCO
abrir ↗GitHub PoC
CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISCO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-6666-XPC-Service-NSKeyedUnarchiver-Deserialization-Attack-macOS-iOS-simulation-
PgBouncer crash in kill_pool_logins_server_error
33RISCO
abrir ↗VulnCheck XDB
initial-access
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.