Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
79.305 exploits
GitHub PoC
siboy17/CVE-2022-21907-http.sys
CVE-2022-21907CRITICAL03 ago 2026
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC2
CVE-2026-16232 (Check Point SmartConsole authentication bypass) PoC - unauth to admin; for authorized security testing
CVE-2026-16232CRITICALsob ataque03 ago 2026
Authentication Bypass in the SmartConsole Login Process Using an Application Token
100RISCO
abrir
GitHub PoC
SQL injection in PyAthena via DefaultParameterFormatter (CVE-2026-65321)
CVE-2026-65321CRITICAL03 ago 2026
PyAthena SQL Injection via DefaultParameterFormatter DELETE/CTAS
48RISCO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-6666-XPC-Service-NSKeyedUnarchiver-Deserialization-Attack-macOS-iOS-simulation-
CVE-2026-6666MEDIUM03 ago 2026
PgBouncer crash in kill_pool_logins_server_error
33RISCO
abrir
GitHub PoC
Path traversal (Tar Slip) in Cornac via _extract_archive (CVE-2026-43637)
CVE-2026-43637HIGH03 ago 2026
Cornac < 2.6.0 Path Traversal via _extract_archive() in download.py
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-39987CRITICALsob ataque03 ago 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISCO
abrir
VulnCheck XDB
info-leak
CVE-2026-60137MEDIUMsob ataque03 ago 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2022-21907CRITICAL03 ago 2026
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-68613CRITICALsob ataque03 ago 2026
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-57819CRITICALsob ataque03 ago 2026
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALsob ataque03 ago 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL03 ago 2026
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
OXDEV-77637 repro fixture: uv workspace whose transitive CVE (starlette 0.25.0 / CVE-2026-48710) is dropped when the lean clone omits workspace-member pyproject.toml. Tag: repro-OXDEV-77637
CVE-2026-48710MEDIUMsob ataque03 ago 2026
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
83RISCO
abrir
VulnCheck XDB
local
CVE-2022-22706HIGHsob ataque03 ago 2026
Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects
71RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-1263503 ago 2026
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RISCO
abrir
VulnCheck XDB
local
CVE-2023-21768HIGH03 ago 2026
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RISCO
abrir
VulnCheck XDB
info-leak
CVE-2018-999503 ago 2026
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir
VulnCheck XDB
info-leak
CVE-2017-7921CRITICALsob ataque03 ago 2026
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISCO
abrir
GitHub PoC3
Proof-of-Concept exploit for CVE-2026-15409 (SonicWall SMA 1000 RCE) via Erlang distribution over WebSocket. Achieves unauthenticated remote code execution as couchdb user.
CVE-2026-15409CRITICALsob ataqueransomware03 ago 2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RISCO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-9998-Insecure-Deserialization-in-Blockchain-Oracle
CVE-2026-9998HIGH03 ago 2026
Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the rend
41RISCO
abrir
GitHub PoC56
villager1314/CVE-2026-64560-Analysis
CVE-2026-64560HIGH03 ago 2026
posix-cpu-timers: Prevent UAF caused by non-leader exec() race
41RISCO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-9999-Serverless-Event-Injection-to-Code-Overwrite
CVE-2026-9999HIGH03 ago 2026
Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execu
41RISCO
abrir
GitHub PoC9
CVE-2026-64531 (OVSwrap) PoC - Linux kernel Open vSwitch LPE; for patch validation and security research
CVE-2026-64531HIGH03 ago 2026
net: openvswitch: reject oversized nested action attrs
41RISCO
abrir
GitHub PoC2
PoC for CVE-2026-3891 – Unauthenticated File Upload RCE in Pix for WooCommerce ≤ 1.5.0. Automated nonce retrieval, PHP upload, and command execution.
CVE-2026-3891CRITICAL03 ago 2026
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RISCO
abrir
GitHub PoC2
CVE-2026-16232 (Check Point SmartConsole authentication bypass) PoC - unauth to admin; for authorized security testing
CVE-2026-16232CRITICALsob ataque03 ago 2026
Authentication Bypass in the SmartConsole Login Process Using an Application Token
100RISCO
abrir
GitHub PoC
CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1
CVE-2026-60004CRITICAL03 ago 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALsob ataque03 ago 2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-66066CRITICAL03 ago 2026
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RISCO
abrir
GitHub PoC
This tool exploits two critical vulnerabilities in Apache CouchDB: | CVE | Description | Severity | |-----|-------------|----------| | **CVE-2017-12635** | Privilege Escalation via JSON Parsing Bypass | 🔴 Critical | | **CVE-2017-12636** | Remote Code Execution via Query Server | 🔴 Critical |
CVE-2017-1263503 ago 2026
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RISCO
abrir
GitHub PoC
0xdak/CVE-2026-69083_exploit
CVE-2026-69083CRITICAL03 ago 2026
SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContent
48RISCO
abrir
anteriorpágina 30 / 2.644próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.