Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.278exploits catalogados
36.463CVEs com exploração pública
24.695testados em laboratório
79.279 exploits
GitHub PoC
Read-only CLI to check whether a WordPress site is exposed to WP2Shell (CVE-2026-63030 / CVE-2026-60137)
CVE-2026-63030CRITICALsob ataque30 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-6440CRITICAL30 ago 2026
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISCO
abrir
GitHub PoC
CVE-2026-12513 Vulnerability Advisory & PoC — Discovered by Huynh Kien Minh (MinhHK).
CVE-2026-12513MEDIUM30 ago 2026
Shared Files < 1.7.68 - Unauthenticated Arbitrary File Deletion via Path Traversal
33RISCO
abrir
GitHub PoC1
Public PoC for CVE-2026-82222
CVE-2026-82222CRITICAL30 ago 2026
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RISCO
abrir
GitHub PoC1
Automated PoC for CVE-2026-48611 — phpBB OAuth login_link authentication bypass
CVE-2026-48611CRITICAL30 ago 2026
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or
63RISCO
abrir
GitHub PoC2
Offensive Research & Exploit Development. Vulnerability research, PoC development, and offensive tooling for financial infrastructure.
CVE-2026-78903LOW30 ago 2026
Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromise
28RISCO
abrir
GitHub PoC
rmhowe425/POC-CVE-2026-18729
CVE-2026-18729HIGH29 ago 2026
Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement
41RISCO
abrir
GitHub PoC
CVE-2026-82286 — gpt-crawler <=1.5.1 unauthenticated arbitrary file write via outputFileName (POST /crawl). PoC + self-contained Docker lab. CVSS 8.6, CWE-22.
CVE-2026-82286HIGH29 ago 2026
gpt-crawler Arbitrary File Write via outputFileName Parameter
41RISCO
abrir
GitHub PoC2
Security research tool for PaperCut CVE-2026-81578 & CVE-2026-82078
CVE-2026-81578HIGHsob ataque29 ago 2026
PaperCut MF/NG: Authentication Bypass
86RISCO
abrir
GitHub PoC
rmhowe425/POC-CVE-2026-19286
CVE-2026-19286CRITICAL29 ago 2026
Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement
48RISCO
abrir
GitHub PoC
morzelowski/CVE-2026-12243-NLTK-PoC
CVE-2026-1224329 ago 2026
23RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-1357CRITICAL29 ago 2026
Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload
75RISCO
abrir
GitHub PoC1
#PaperCut CVE-2026-81578 + CVE-2026-82078 Defense Toolkit 2 3 A **defensive** toolkit to check and understand exposure to the chained
CVE-2026-81578HIGHsob ataque29 ago 2026
PaperCut MF/NG: Authentication Bypass
86RISCO
abrir
GitHub PoC
Hunt-Benito/your-bot-my-inbox-cve-2026-68929-fastgpt-unauthenticated-wechat-channel-hijack
CVE-2026-68929CRITICAL29 ago 2026
FastGPT: Unauthenticated WeChat channel hijack and denial of service via shareId-only authorization
48RISCO
abrir
GitHub PoC
FranklinF25/cve-2026-42533
CVE-2026-42533CRITICAL29 ago 2026
NGINX Map directive and Regex matching vulnerability
48RISCO
abrir
GitHub PoC2
Learn how I found my first two CVEs by pure accident.
CVE-2026-19745MEDIUM29 ago 2026
Calix GigaSpire Web Management utilities_configurationsave.cgi denial of service
33RISCO
abrir
GitHub PoC
joaovicdev/EXPLOIT-CVE-2026-9198
CVE-2026-9198CRITICALsob ataque29 ago 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISCO
abrir
GitHub PoC
CVE-2026-47884:覆盖 15 条 Spring / Tomcat 官方安全公告,8 条被 NVD 报成 CRITICAL 9.x 而厂商官方评 LOW/MEDIUM,另 7 条两边一致 —— 差别只在厂商有没有自己提交 CVSS。工具告诉你中了哪几条、官方评多少分、是否真满足触发条件,以及官方叫你升的版本 Maven Central 上有没有。
CVE-2026-47884CRITICAL29 ago 2026
Spring Framework Improper Path Limitation in XsltView
48RISCO
abrir
GitHub PoC
SOC investigation of a CVE-2024-49138 exploitation alert using log analysis, threat intelligence, and endpoint containment.
CVE-2024-49138HIGHsob ataque29 ago 2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC
Static XML fixtures for authorized bug bounty testing of XML parser behaviour (CVE-2026-45071).
CVE-2026-45071HIGH29 ago 2026
Symfony: XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse = true
41RISCO
abrir
GitHub PoC
Hari-v542/CVE-2026-52923
CVE-2026-52923HIGH28 ago 2026
ipc: limit next_id allocation to the valid ID range
41RISCO
abrir
GitHub PoC
CVE-2023-27350, CVE-2023-27351 - PaperCut - Draft or TODO
CVE-2023-27350CRITICALsob ataqueransomware28 ago 2026
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir
GitHub PoC
A specialized Python framework that executes unauthenticated remote code execution via the 9Router Model Context Protocol (MCP) bridge by deploying a 33-layer temporal phase cascade, Riemann-Hadamard dispersion, and an 11 ns wedge filter to bypass traditional proxy and process-monitoring defenses.
CVE-2026-46339CRITICAL28 ago 2026
9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
63RISCO
abrir
GitHub PoC
fastjson-cve-2026-16723
CVE-2026-16723CRITICAL28 ago 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISCO
abrir
GitHub PoC
CVE-2026-33017 - Langflow Unauthenticated RCE Exploit
CVE-2026-33017CRITICALsob ataque28 ago 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir
GitHub PoC
CVE-2026-33017 PoC Reverse Shell
CVE-2026-33017CRITICALsob ataque28 ago 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir
GitHub PoC
IKEv1 VPN scanners, attempts a Check Point authentication-bypass exploit, and includes internal network scanning and reverse-shell features.
CVE-2026-50751CRITICALsob ataqueransomware28 ago 2026
User Authentication Bypass in VPN Remote Access and Mobile Access
100RISCO
abrir
GitHub PoC
Cacti 1.2.22 unauthenticated command injection
CVE-2022-46169CRITICALsob ataque28 ago 2026
Unauthenticated Command Injection
100RISCO
abrir
GitHub PoC1
hideki233/CVE-2025-3248-Langflow-RCE
CVE-2025-3248CRITICALsob ataqueransomware28 ago 2026
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISCO
abrir
GitHub PoC
I know you are probably here from Hack the Box, if so, yes this one actually works.
CVE-2025-55182CRITICALsob ataqueransomware28 ago 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
anteriorpágina 4 / 2.643próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.