Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8.883Nuclei 4.361Metasploit 3.493✓ só verificadosrecentespopularesrisco
79.305 exploits
GitHub PoC★ 6
Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known CVE. Agentic loop-hunt: 25 generators, 22 judges, 9 live validators on Docker. Evidence trail + one-go checker included.
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISCO
abrir ↗GitHub PoC★ 1
IBM Langflow OSS 1.0.0 through 1.10.0 contains a remote code execution [RCE]
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISCO
abrir ↗VulnCheck XDB
initial-access
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RISCO
abrir ↗GitHub PoC
CyberVinner/CP-PLUS-EZ-P21-CVE-2026-65893-65894
Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera
41RISCO
abrir ↗VulnCheck XDB
initial-access
Authentication Bypass in the SmartConsole Login Process Using an Application Token
100RISCO
abrir ↗GitHub PoC★ 11
A proof-of-concept script to exploit CVE-2026-16232, an authentication bypass via the SmartConsole login process using an application token.
Authentication Bypass in the SmartConsole Login Process Using an Application Token
100RISCO
abrir ↗VulnCheck XDB
initial-access
Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'
48RISCO
abrir ↗GitHub PoC★ 4
Fastjson 1.2.83 RCE 靶场环境 (CVE-2026-16723)
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISCO
abrir ↗GitHub PoC
Microsoft SharePoint CVE-2026-50522
Microsoft SharePoint Remote Code Execution Vulnerability
100RISCO
abrir ↗GitHub PoC
Perl Image::WebP library. Unofficial. CVE-2026-58586
Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp
28RISCO
abrir ↗VulnCheck XDB
initial-access
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISCO
abrir ↗GitHub PoC★ 1
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISCO
abrir ↗GitHub PoC★ 4
KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir ↗GitHub PoC
Isolated regression and security-control lab for CVE-2026-59891 in @sigstore/oci
Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry
48RISCO
abrir ↗GitHub PoC★ 1
CVE-2026-8206: Kirki Customizer Framework - Unauthenticated Account Takeover (CVSS 9.8)
Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'
48RISCO
abrir ↗GitHub PoC★ 3
CVE-2026-53264 - Draft or Todo
net/sched: act_api: use RCU with deferred freeing for action lifecycle
41RISCO
abrir ↗GitHub PoC
IoT Security research conducted during my internship at IIIT Allahabad, leading to CVE-2026-65893, CVE-2026-65894, and the CERT-In Vulnerability Note CIVN-2026-0380.
Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera
41RISCO
abrir ↗VulnCheck XDB
initial-access
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISCO
abrir ↗GitHub PoC
CVE-2026-14856 TastyIgniter v4.3.0
Stored Cross-Site Scripting (XSS) in TastyIgniter Media Manager
33RISCO
abrir ↗GitHub PoC★ 3
Exploit code for CVE-2026-55040, it can create auth header for any validate account.
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISCO
abrir ↗GitHub PoC
0xdak/CVE-2025-71389_exploit
Cal.com before 5.9.9 Remote Code Execution via RSC
48RISCO
abrir ↗GitHub PoC
Proof of Concept for CVE-2026-65761 - EasyStore Pro Unauthenticated SQL Injection via `filter_sortby`
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1
63RISCO
abrir ↗GitHub PoC★ 10
KSU installer for supported firmware with CVE-2026-43499
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir ↗GitHub PoC
Simulated a real-world attack (CVE-2011-2523) against a vulnerable host, then cross-checked detection coverage against an existing Wazuh/Suricata/Zeek SOC — uncovering and fixing 5 real monitoring pipeline bugs along the way.
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir ↗GitHub PoC
bha-vin/CVE-2026-64600-Exploit
xfs: resample the data fork mapping after cycling ILOCK
41RISCO
abrir ↗GitHub PoC★ 1
A PoC for CVE-2026-64725
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS
41RISCO
abrir ↗GitHub PoC
letsr00t/RefluxFS_CVE-2026-64600
xfs: resample the data fork mapping after cycling ILOCK
41RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.