Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.278exploits catalogados
36.463CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.465Referência 23.051GitHub PoC 15.048VulnCheck XDB 8.860Nuclei 4.361Metasploit 3.493✓ só verificadosrecentespopularesrisco
79.279 exploits
GitHub PoC
Read-only CLI to check whether a WordPress site is exposed to WP2Shell (CVE-2026-63030 / CVE-2026-60137)
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir ↗VulnCheck XDB
initial-access
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISCO
abrir ↗GitHub PoC
CVE-2026-12513 Vulnerability Advisory & PoC — Discovered by Huynh Kien Minh (MinhHK).
Shared Files < 1.7.68 - Unauthenticated Arbitrary File Deletion via Path Traversal
33RISCO
abrir ↗GitHub PoC★ 1
Public PoC for CVE-2026-82222
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RISCO
abrir ↗GitHub PoC★ 1
Automated PoC for CVE-2026-48611 — phpBB OAuth login_link authentication bypass
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or
63RISCO
abrir ↗GitHub PoC★ 2
Offensive Research & Exploit Development. Vulnerability research, PoC development, and offensive tooling for financial infrastructure.
Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromise
28RISCO
abrir ↗GitHub PoC
rmhowe425/POC-CVE-2026-18729
Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement
41RISCO
abrir ↗GitHub PoC
CVE-2026-82286 — gpt-crawler <=1.5.1 unauthenticated arbitrary file write via outputFileName (POST /crawl). PoC + self-contained Docker lab. CVSS 8.6, CWE-22.
gpt-crawler Arbitrary File Write via outputFileName Parameter
41RISCO
abrir ↗GitHub PoC★ 2
Security research tool for PaperCut CVE-2026-81578 & CVE-2026-82078
PaperCut MF/NG: Authentication Bypass
86RISCO
abrir ↗GitHub PoC
rmhowe425/POC-CVE-2026-19286
Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement
48RISCO
abrir ↗VulnCheck XDB
initial-access
Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload
75RISCO
abrir ↗GitHub PoC★ 1
#PaperCut CVE-2026-81578 + CVE-2026-82078 Defense Toolkit 2 3 A **defensive** toolkit to check and understand exposure to the chained
PaperCut MF/NG: Authentication Bypass
86RISCO
abrir ↗GitHub PoC
Hunt-Benito/your-bot-my-inbox-cve-2026-68929-fastgpt-unauthenticated-wechat-channel-hijack
FastGPT: Unauthenticated WeChat channel hijack and denial of service via shareId-only authorization
48RISCO
abrir ↗GitHub PoC
FranklinF25/cve-2026-42533
NGINX Map directive and Regex matching vulnerability
48RISCO
abrir ↗GitHub PoC★ 2
Learn how I found my first two CVEs by pure accident.
Calix GigaSpire Web Management utilities_configurationsave.cgi denial of service
33RISCO
abrir ↗GitHub PoC
joaovicdev/EXPLOIT-CVE-2026-9198
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISCO
abrir ↗GitHub PoC
CVE-2026-47884:覆盖 15 条 Spring / Tomcat 官方安全公告,8 条被 NVD 报成 CRITICAL 9.x 而厂商官方评 LOW/MEDIUM,另 7 条两边一致 —— 差别只在厂商有没有自己提交 CVSS。工具告诉你中了哪几条、官方评多少分、是否真满足触发条件,以及官方叫你升的版本 Maven Central 上有没有。
Spring Framework Improper Path Limitation in XsltView
48RISCO
abrir ↗GitHub PoC
SOC investigation of a CVE-2024-49138 exploitation alert using log analysis, threat intelligence, and endpoint containment.
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir ↗GitHub PoC
Static XML fixtures for authorized bug bounty testing of XML parser behaviour (CVE-2026-45071).
Symfony: XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse = true
41RISCO
abrir ↗GitHub PoC
CVE-2023-27350, CVE-2023-27351 - PaperCut - Draft or TODO
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir ↗GitHub PoC
A specialized Python framework that executes unauthenticated remote code execution via the 9Router Model Context Protocol (MCP) bridge by deploying a 33-layer temporal phase cascade, Riemann-Hadamard dispersion, and an 11 ns wedge filter to bypass traditional proxy and process-monitoring defenses.
9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
63RISCO
abrir ↗GitHub PoC
CVE-2026-33017 - Langflow Unauthenticated RCE Exploit
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir ↗GitHub PoC
CVE-2026-33017 PoC Reverse Shell
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir ↗GitHub PoC
IKEv1 VPN scanners, attempts a Check Point authentication-bypass exploit, and includes internal network scanning and reverse-shell features.
User Authentication Bypass in VPN Remote Access and Mobile Access
100RISCO
abrir ↗GitHub PoC
Cacti 1.2.22 unauthenticated command injection
Unauthenticated Command Injection
100RISCO
abrir ↗GitHub PoC★ 1
hideki233/CVE-2025-3248-Langflow-RCE
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir ↗GitHub PoC
I know you are probably here from Hack the Box, if so, yes this one actually works.
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.