Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
79.305 exploits
GitHub PoC
Python implementation/PoC for CVE-2024-40422. Exploits a critical directory traversal vulnerability in Devika v1's /api/get-browser-snapshot endpoint to read arbitrary system files.
CVE-2024-40422CRITICAL02 ago 2026
The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path tr
68RISCO
abrir
GitHub PoC
CVE-2026-14483 POC EXPLOIT BY MADEXPLOITS
CVE-2026-14483CRITICAL01 ago 2026
Realtyna Organic IDX plugin + WPL Real Estate <= 5.2.0 - Unauthenticated Arbitrary File Upload via 'files[file]' Parameter via Public I/O 'set_property' Command
63RISCO
abrir
GitHub PoC
Kestra Unauthenticated RCE Exploit (CVE-2026-53576)
CVE-2026-53576CRITICAL01 ago 2026
Kestra: Unauthenticated RCE via /configs path-suffix auth-filter bypass
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALsob ataqueransomware01 ago 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
Read-only-by-default WordPress incident-response scanner for the “wp2shell” attack chain (CVE-2026-60137 / CVE-2026-63030): detects shadow-admin, database and filesystem IOCs, verifies core integrity, and exports evidence. Optional controlled account cleanup; does not remove malware.
CVE-2026-60137MEDIUMsob ataque01 ago 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISCO
abrir
GitHub PoC
My write-ups from CyberDefenders' Blue Team labs, solved using Wireshark. Covers TeamCity RCE (CVE-2024-27198), XSS session hijacking, and LLMNR/NBT-NS credential poisoning — each with step-by-step packet analysis, screenshots, and a full Wireshark filter/command reference. Personal SOC Analyst Tier 1 learning log.
CVE-2024-27198CRITICALsob ataqueransomware01 ago 2026
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2023-44487HIGHsob ataque01 ago 2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISCO
abrir
GitHub PoC
MinhHK68/CVE-2026-13157
CVE-2026-13157HIGH01 ago 2026
Theme Demo Import <= 1.1.3 - Admin+ Arbitrary File Upload
41RISCO
abrir
GitHub PoC1
Wolf CMS <= 0.8.3.1 - RCE via Arbitrary File Write
CVE-2026-67206HIGH01 ago 2026
Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Upload
41RISCO
abrir
GitHub PoC
RichardKabuto/CVE-2026-52370
CVE-2026-52370MEDIUM01 ago 2026
A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execu
13RISCO
abrir
GitHub PoC1
Consul Template validated where a symlink pointed during template evaluation, but its later dependency fetch read the original path. Retargeting the link between those operations turned an in-sandbox file reference into an out-of-sandbox file disclosure.
CVE-2026-5061MEDIUM01 ago 2026
Consul-template vulnerable to sandbox path bypass in file helper via a symlink attack
33RISCO
abrir
GitHub PoC
YellowKey BitLocker CVE-2026-45585 - free open-source utility to extract, backup and view BitLocker recovery keys on Windows 10/11. BitLocker bypass vulnerability tool, remediation and mitigation. Tom's Hardware coverage. Check TPM status, protector types, encryption state. Download YellowKey free, portable, no install needed.
CVE-2026-45585MEDIUM01 ago 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RISCO
abrir
GitHub PoC1
CVE-2026-13152: Custom Fields Account Registration For WooCommerce Unauthenticated Privilege Escalation PoC & Advisory by Huynh Kien Minh (MinhHK).
CVE-2026-13152HIGH01 ago 2026
Custom Fields Account Registration For WooCommerce < 1.4 - Unauthenticated Privilege Escalation
41RISCO
abrir
GitHub PoC
aj2108/CVE-2026-9833
CVE-2026-9833HIGH01 ago 2026
Tag Groups < 2.2.0 - Reflected XSS via 'tag_groups_task' Parameter
41RISCO
abrir
GitHub PoC2
CVE-2026-64531
CVE-2026-64531HIGH01 ago 2026
net: openvswitch: reject oversized nested action attrs
41RISCO
abrir
GitHub PoC1
MinhHK68/CVE-2026-13158
CVE-2026-13158HIGH01 ago 2026
Everest Toolkit <= 1.2.3 - Admin+ Arbitrary File Upload
41RISCO
abrir
GitHub PoC
Full-lifecycle vulnerability management on a live Log4Shell (CVE-2021-44228) target — scan, manual exploitation, network detection, and remediation verification. Nessus, Suricata, Wireshark, Docker.
CVE-2021-44228CRITICALsob ataqueransomware01 ago 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
System Vulnerability Checklist & Network Security Hardening project featuring reconnaissance, vsFTPd backdoor analysis (CVE-2011-2523), and active transport-layer mitigation using IPTables.
CVE-2011-252301 ago 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
GitHub PoC1
Advanced CVE-2023-44487 HTTP/2 Rapid Reset vulnerability exploitation framework. Features multi-connection concurrent attacks, adaptive rate control, stealth mode with randomized headers, real-time metrics, and risk assessment reporting. For authorized penetration testing only. By Sudeepa Wanigarathna
CVE-2023-44487HIGHsob ataque01 ago 2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISCO
abrir
GitHub PoC1
PoC & checker for CVE-2026-15964 - unauthenticated password change in the WordPress plugin Single Sign On For TNG <= 2.0.0 (CVSS 9.8)
CVE-2026-15964CRITICAL01 ago 2026
Single Sign On For TNG <= 2.0.0 - Unauthenticated Privilege Escalation via Unverified Password Change
48RISCO
abrir
GitHub PoC1
Standalone CVE-2026-43499 port for Galaxy A36 5G SM-A366W A366WVLS3AYG1 with KernelSU late-load
CVE-2026-43499HIGH01 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC168
YellowKey BitLocker CVE-2026-45585 free open-source utility to extract, backup and view BitLocker recovery keys on Windows 10/11. BitLocker bypass vulnerability tool, remediation and mitigation. Tom's Hardware coverage. Check TPM status, protector types, encryption state. Download YellowKey free, portable, no install needed.
CVE-2026-45585MEDIUM01 ago 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RISCO
abrir
GitHub PoC
raihants/cve-2026-10702
CVE-2026-10702MEDIUM01 ago 2026
JIT miscompilation in the JavaScript Engine: JIT component
33RISCO
abrir
GitHub PoC
CVE-2026-8239 is an Insecure Direct Object Reference (IDOR) vulnerability affecting Concrete CMS 9.5.0 and earlier.
CVE-2026-8239MEDIUM01 ago 2026
Concrete CMS 9.5.0 and below is vulnerable to IDOR in '/ccm/frontend/conversations/get_rating'
33RISCO
abrir
GitHub PoC1
This project demonstrates the publicly disclosed CVE-2018-9995 vulnerability found in multiple embedded DVR devices.
CVE-2018-999501 ago 2026
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir
GitHub PoC7
Root prototype for Galaxy S26 (SM-S942U) that is very much indev
CVE-2026-43499HIGH01 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
CVE-2026-67595 — Embedded malicious JavaScript (spyware) in VaahCMS 2.0.0–2.3.4 official releases. CVSS 8.1. Advisory + detection.
CVE-2026-67595CRITICAL01 ago 2026
VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php
48RISCO
abrir
GitHub PoC
Vulnerability research write-ups — CVE-2026-12478 (libsoup), Apple WebKit, Google VRP
CVE-2026-12478MEDIUM01 ago 2026
Libsoup: incomplete fix for cve-2026-0716: out-of-bounds read in libsoup websocket frame processing (unmasked path)
33RISCO
abrir
GitHub PoC
CVE-2026-8237 is an Insecure Direct Object Reference (IDOR) vulnerability caused by missing authorization checks in Concrete CMS 9.5.0 and earlier.
CVE-2026-8237MEDIUM01 ago 2026
Concrete CMS 9.5.0 and below is vulnerable to IDOR in the`/ccm/frontend/conversations/message_detail` endpoint
48RISCO
abrir
GitHub PoC
PD2229B的43499(ghostlock)可行性研究
CVE-2026-43499HIGH01 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
anteriorpágina 33 / 2.644próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.