Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
14.946 exploits
GitHub PoC1
CVE-2026-69836 — Unauthenticated RCE via Entra ID deserialization
CVE-2026-69836CRITICAL21 ago 2026
Microsoft Entra ID Remote Code Execution Vulnerability
48RISCO
abrir
GitHub PoC
Stored XSS via User-Agent in Admin Order View in PhocaCart
CVE-2026-76564HIGH21 ago 2026
Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7
41RISCO
abrir
GitHub PoC1
Custom Content Types and Fields plugin for WordPress
CVE-2026-19598CRITICAL21 ago 2026
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
63RISCO
abrir
GitHub PoC3
Read-only PoC for CVE-2026-65400 — macOS Screen Sharing (screensharingd) pre-auth SRP bypass giving root file read. Patched in macOS 26.6.1 / 15.7.9 / 14.8.9.
CVE-2026-65400CRITICALsob ataque21 ago 2026
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS
78RISCO
abrir
GitHub PoC5
CVE-2026-32475 The Elementor Pro Forms File Upload field handles validation and file processing in two separate loops with different handling of empty upload entries (UPLOAD_ERR_NO_FILE). An unauthenticated attacker can submit a multipart
CVE-2026-32475CRITICAL21 ago 2026
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RISCO
abrir
GitHub PoC
CVE-2026-39113: SQLite SQLAR heap-buffer-overflow advisory and reproducer
CVE-2026-3911321 ago 2026
Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3a
23RISCO
abrir
GitHub PoC
JCEzploit is a powerful, fully-automated RCE exploit for Joomla JCE (CVE-2026-48907) featuring interactive shell, batch command execution, file download capability, and proxy support. Built with Python & Rich for penetration testers. Ethical use only. By Sudeepa Wanigarathna.
CVE-2026-48907CRITICALsob ataque21 ago 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISCO
abrir
GitHub PoC
wp2shell — WordPress Core Pre-Auth RCE Chain poc for CVE-2026-63030 and CVE-2026-60137
CVE-2026-63030CRITICALsob ataque21 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC
CVE-2026-41567 1day
CVE-2026-41567HIGH21 ago 2026
Docker: `PUT /containers/{id}/archive` executes container binary on the host
41RISCO
abrir
GitHub PoC
wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
CVE-2026-63030CRITICALsob ataque20 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC
Hunt-Benito/the-same-key-opens-every-box-cve-2026-71960-hard-coded-jwt-secret-in-cudy-wr3000-mesh-mqtt
CVE-2026-71960CRITICAL20 ago 2026
Cudy WR3000 2.0 Hard-coded JWT Secret Authentication Bypass via MQTT
48RISCO
abrir
GitHub PoC1
elkhaoudari/CVE-2018-7600-PoC
CVE-2018-7600CRITICALsob ataqueransomware20 ago 2026
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC
aarch64 race condition checker
CVE-2026-46242HIGH20 ago 2026
eventpoll: fix ep_remove struct eventpoll / struct file UAF
41RISCO
abrir
GitHub PoC
CVE-2026-19478: GitLab GraphQL Vulnerability PoC
CVE-2026-19478CRITICAL20 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir
GitHub PoC
Analyze and reproduce CVE-2025-55182.
CVE-2025-55182CRITICALsob ataqueransomware20 ago 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Deterministic memory-poisoning / prompt-injection measurement axis — CoSnitch (CVE-2026-24301) anchored. Inspect scorer, signed receipts. Measurement, not certification.
CVE-2026-24301HIGH20 ago 2026
Microsoft Copilot Information Disclosure Vulnerability
41RISCO
abrir
GitHub PoC
CVE-2026-18366: Events Manager < 7.4.1 — Unauthenticated Privilege Escalation to Administrator. Write-up and proof-of-concept (poc.py).
CVE-2026-18366CRITICAL20 ago 2026
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
48RISCO
abrir
GitHub PoC
Proof-of-concept for CVE-2026-18315 (TrueBooker WordPress Plugin): Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover
CVE-2026-18315CRITICAL20 ago 2026
TrueBooker <= 1.2.6 - Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover to 'truebooker_wp_user_id' Parameter
48RISCO
abrir
GitHub PoC
Controlled PenTest lab report for UnrealIRCd 3.2.8.1 backdoor (CVE-2010-2075) on Metasploitable3 with remediation steps.
CVE-2010-207520 ago 2026
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RISCO
abrir
GitHub PoC35
Exploit for KeyCloak CVE-2026-18963
CVE-2026-18963CRITICAL20 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISCO
abrir
GitHub PoC14
Hunt for CVE-2026-18963 exploitation traces (Keycloak unauthenticated account takeover) in the Keycloak database
CVE-2026-18963CRITICAL20 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISCO
abrir
GitHub PoC1
Safely detect Citrix NetScaler CVE-2026-8452
CVE-2026-8452HIGHsob ataque20 ago 2026
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
71RISCO
abrir
GitHub PoC
fork and edits from https://github.com/aniqfakhrul/CVE-2026-54121
CVE-2026-54121HIGH19 ago 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC1
Ring0-level process killer leveraging CVE-2026-0828 (BYOVD). Designed to demonstrate kernel-level process termination via a vulnerable signed driver, highlighting the security risks of Bring Your Own Vulnerable Driver attacks and the importance of driver trust, monitoring, and endpoint protection.
CVE-2026-0828HIGH19 ago 2026
Kernel driver vulnerability in Safetica Endpoint Client
41RISCO
abrir
GitHub PoC1
0xdeadroot/SCTPhantom-CVE-2026-64564
CVE-2026-64564CRITICAL19 ago 2026
sctp: don't free the ASCONF's own transport in DEL-IP processing
48RISCO
abrir
GitHub PoC1
Begitdj/cve-2019-2215-markw
CVE-2019-2215HIGHsob ataque19 ago 2026
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir
GitHub PoC
CVE-2026-18504, CVE-2026-16732 - Draft or TODO
CVE-2026-18504MEDIUM19 ago 2026
fastify vulnerable to schema validation bypass via root primitive coercion mismatch
33RISCO
abrir
GitHub PoC
Oracle OID LDAP Server Privileges Management Exploit
CVE-2026-61241CRITICAL19 ago 2026
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Suppor
28RISCO
abrir
GitHub PoC1
renzi25031469/CVE-2026-19478
CVE-2026-19478CRITICAL19 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir
GitHub PoC
CVE-2026-47858
CVE-2026-47858HIGH19 ago 2026
live information startup mode is vulnerable for remote code execution
41RISCO
abrir

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.