Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8.829Nuclei 4.350Metasploit 3.489✓ só verificadosrecentespopularesrisco
14.497 exploits
GitHub PoC
CVE-2026-17532 Docker Lab.
Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting
48RISCO
abrir ↗GitHub PoC
TP-Link Archer BE800 V1 — VPN Key Injection RCE
Command Injection Vulnerability in VPN connection of Archer BE800
41RISCO
abrir ↗GitHub PoC
CVE-2026-68820 — Mass Exploit Framework Edition.
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
71RISCO
abrir ↗GitHub PoC
Patch: SSRF leading to RCE (Microsoft Exchange Server)
AojiaoZero Antaris PayPal IPN Payment ipn.php _rewardPurchase sql injection
33RISCO
abrir ↗GitHub PoC
CVE-2025-48595 Android Framework Integer Overflow PoC - 优化版
In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to
71RISCO
abrir ↗GitHub PoC
Reproducer for CVE-2026-71300 (Apache Camel camel-atmosphere-websocket dispatch header injection) — Camel Spring Boot
Apache Camel: Camel-Atmosphere-Websocket: WebSocket dispatch header injection
48RISCO
abrir ↗GitHub PoC
imbas007/RCE-CVE-2026-10520-CVE-2026-10523
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RISCO
abrir ↗GitHub PoC
Reproducer for CVE-2026-60093 (Apache Camel camel-azure-storage-datalake downloadToFile path traversal) — Camel Spring Boot + Camel Quarkus
Apache Camel: Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir
33RISCO
abrir ↗GitHub PoC
Patch: Command injection in GlobalProtect (Palo Alto PAN-OS)
Embed Google Photos Album Easily <= 2.2.1 - Contributor+ Stored XSS via link Shortcode Attribute
33RISCO
abrir ↗GitHub PoC
Reproducer for CVE-2026-59230 (Apache Camel camel-mail MimeMultipart headersInline header injection) — Camel Spring Boot + Camel Quarkus
Apache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled
33RISCO
abrir ↗GitHub PoC
Reproducer for CVE-2026-63039 (Apache InLong AuditAlertRule MyBatis ORDER BY SQL injection via orderField/orderType)
Apache InLong: SQL Injection via Unvalidated MyBatis Dollar-Sign Interpolation in AuditAlertRuleService
48RISCO
abrir ↗GitHub PoC
xAL6/cve-2026-64638-banner-poc
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISCO
abrir ↗GitHub PoC
Reproducer for CVE-2026-66907 (Apache Camel camel-google-storage downloadFileName path traversal) — Camel Spring Boot + Camel Quarkus
Apache Camel: Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result
41RISCO
abrir ↗GitHub PoC
Reproducer for CVE-2026-66908 (Apache Camel camel-platform-http-main JWT iss/aud not validated) — standalone camel-main
Apache Camel: Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted
41RISCO
abrir ↗GitHub PoC
Reproducer for CVE-2026-78329 (Apache Camel camel-undertow header filter strategy not applied, websocket.* injection) — Camel Spring Boot
Apache Camel: Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes
48RISCO
abrir ↗GitHub PoC
Reproducer for CVE-2026-63621 (Apache Camel camel-knative structured CloudEvent header injection) — Camel Spring Boot + Camel Quarkus
Apache Camel: Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy
33RISCO
abrir ↗GitHub PoC★ 1
Firefox content-to-parent IPDL privilege escalation (N-day, bug 2054416): forged PDocumentChannel with RemoteTypeOverride -> privilegedabout process placement, via mojo-port send-path injection from a compromised content process
Privilege escalation in the DOM: Navigation component
41RISCO
abrir ↗GitHub PoC★ 2
T0w0T/POC-CVE-2026-18963
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISCO
abrir ↗GitHub PoC
minh3102011/CVE-2026-18963_analyst
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISCO
abrir ↗GitHub PoC★ 2
CVE-2026-77806漏洞检测代码
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August
63RISCO
abrir ↗GitHub PoC
Reproducer for CVE-2026-66906 (Apache Camel camel-azure-storage-blob downloadBlobToFile path traversal) — Camel Spring Boot + Camel Quarkus
Apache Camel: Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir
48RISCO
abrir ↗GitHub PoC
Patch: Authentication bypass (VMware vCenter)
Tenda HG7HG9/HG10 formPPPEdit stack-based overflow
41RISCO
abrir ↗GitHub PoC
Patch: OGNL injection (Apache Struts)
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RISCO
abrir ↗GitHub PoC
CVE-2026-73570 PoC
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
91RISCO
abrir ↗GitHub PoC
Demostracion educativa de mitigacion de CVE-2026-68820: Use-After-Free en afd.sys de Windows.
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
71RISCO
abrir ↗GitHub PoC
Patch: Heap overflow in SSL-VPN (Fortinet FortiOS)
Socket versions before 2.041 for Perl have an out-of-bounds heap read
48RISCO
abrir ↗GitHub PoC★ 19
CVE-2026-18963
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISCO
abrir ↗GitHub PoC
Reproducer for CVE-2026-28672 (Apache Ranger UnixUserGroupBuilder OS command injection via username in the unixusersync module)
Apache Ranger: OS Command Injection via Username in UnixUserGroupBuilder
48RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.