Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.275exploits catalogados
36.462CVEs com exploração pública
24.695testados em laboratório
79.274 exploits
VulnCheck XDB
initial-access
CVE-2026-60004CRITICAL31 ago 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISCO
abrir
GitHub PoC
Reflected XSS via search GET Parameter in Phoca Download
CVE-2026-76569MEDIUM31 ago 2026
Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4
33RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-18963CRITICAL31 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISCO
abrir
GitHub PoC
Weak-RNG stream-sweep research (CVE-2026-71851 class): PRNG schemes x seeds -> BIP39 -> victim set membership
CVE-2026-71851CRITICAL31 ago 2026
crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
48RISCO
abrir
GitHub PoC
GiveWP <= 4.16.7.1 Unauthenticated PHP Object Injection → RCE
CVE-2026-82222CRITICAL31 ago 2026
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-9198CRITICALsob ataque31 ago 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISCO
abrir
GitHub PoC
PoC CVE-2026-18741
CVE-2026-18741MEDIUM30 ago 2026
Worksuite SaaS version prior to 6.0.14 Stored XSS via Asset Management Location and Description Fields
33RISCO
abrir
GitHub PoC
🫖 Contract-correlated discovery and authorized validation tool for Gitea CVE-2026-60004
CVE-2026-60004CRITICAL30 ago 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-82222CRITICAL30 ago 2026
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RISCO
abrir
GitHub PoC
🫖 Direct single-target Gitea CVE-2026-60004 RCE validation PoC
CVE-2026-60004CRITICAL30 ago 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISCO
abrir
GitHub PoC
CVE-2026-76581
CVE-2026-76581CRITICAL30 ago 2026
WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion
48RISCO
abrir
GitHub PoC
Balboa form Command Injection POC
CVE-2026-67363HIGH30 ago 2026
Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2
41RISCO
abrir
GitHub PoC1
Automated PoC for CVE-2026-48611 — phpBB OAuth login_link authentication bypass
CVE-2026-48611CRITICAL30 ago 2026
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or
63RISCO
abrir
GitHub PoC15
Authorized Docker lab and clean PoC for validating CVE-2026-82222 RCE in GiveWP 4.16.5.1 and the 4.16.7.2 fix.
CVE-2026-82222CRITICAL30 ago 2026
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RISCO
abrir
GitHub PoC1
Offensive Research & Exploit Development. Vulnerability research, PoC development, and offensive tooling for financial infrastructure.
CVE-2026-78903LOW30 ago 2026
Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromise
28RISCO
abrir
GitHub PoC
Read-only CLI to check whether a WordPress site is exposed to WP2Shell (CVE-2026-63030 / CVE-2026-60137)
CVE-2026-63030CRITICALsob ataque30 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC1
Social Media Infrastructure Vulnerability Research. CVE-2026-78905: OAuth token reuse and session hijacking in Facebook's Graph API.
CVE-2026-78905HIGH30 ago 2026
Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitra
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-82222CRITICAL30 ago 2026
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RISCO
abrir
GitHub PoC2
CBDC Infrastructure Vulnerability Research. CVE-2026-78904: Infinite mint and redemption bypass in central bank digital currency APIs.
CVE-2026-78904CRITICAL30 ago 2026
Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitra
48RISCO
abrir
GitHub PoC1
FastGPT Community Edition NoSQL Injection PoC (CVE-2026-79483)
CVE-2026-79483MEDIUM30 ago 2026
FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistor
33RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-60004CRITICAL30 ago 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISCO
abrir
GitHub PoC1
CVE-2026-80724 PoC + full write-up — Linux kernel ptp/vmclock read-only mapping becomes writable (VM_MAYWRITE). Discovered, reported & fixed by Abdifatah Suruur (suruurism)
CVE-2026-80724HIGH30 ago 2026
ptp: vmclock: prevent read-only mappings from becoming writable
41RISCO
abrir
GitHub PoC
CVE-2026-45833 ChromaDB
CVE-2026-45833CRITICAL30 ago 2026
A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacke
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-6440CRITICAL30 ago 2026
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-48611CRITICAL30 ago 2026
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or
63RISCO
abrir
GitHub PoC1
Public PoC for CVE-2026-82222
CVE-2026-82222CRITICAL30 ago 2026
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-42945CRITICAL30 ago 2026
NGINX ngx_http_rewrite_module vulnerability
60RISCO
abrir
GitHub PoC
CitrixBleed Exploit Tool - CVE-2025-5777 & CVE-2026-8452. Unauthenticated remote memory read from Citrix NetScaler ADC & Gateway. Steal admin session tokens, extract nsroot hashes, dump secrets, and bypass MFA. Python 3 exploit with full memory parsing.
CVE-2026-8452HIGHsob ataque30 ago 2026
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
71RISCO
abrir
GitHub PoC
CVE-2026-12513 Vulnerability Advisory & PoC — Discovered by Huynh Kien Minh (MinhHK).
CVE-2026-12513MEDIUM30 ago 2026
Shared Files < 1.7.68 - Unauthenticated Arbitrary File Deletion via Path Traversal
33RISCO
abrir
GitHub PoC
Safe passive detector for identifying WPMU DEV Dashboard versions affected by CVE-2026-76581.
CVE-2026-76581CRITICAL30 ago 2026
WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion
48RISCO
abrir
anteriorpágina 3 / 2.643próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.