Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8.829Nuclei 4.350Metasploit 3.489✓ só verificadosrecentespopularesrisco
14.946 exploits
GitHub PoC★ 1
4gaBoards < 3.3.9 - User Information Disclosure
4gaBoards: Mass Information Disclosure (Internal PII Leakage) on /api/users to any authenticated user
33RISCO
abrir ↗GitHub PoC
Oracle OID LDAP Server Privileges Management Exploit
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Suppor
28RISCO
abrir ↗GitHub PoC
fork and edits from https://github.com/aniqfakhrul/CVE-2026-54121
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISCO
abrir ↗GitHub PoC★ 1
halo cms plugin 1-request rce from a url, PoC + exploit chain
An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri m
48RISCO
abrir ↗GitHub PoC
CVE-2026-64849 PoC
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
98RISCO
abrir ↗GitHub PoC
CVE-2026-18504, CVE-2026-16732 - Draft or TODO
fastify vulnerable to schema validation bypass via root primitive coercion mismatch
33RISCO
abrir ↗GitHub PoC★ 1
0xdeadroot/SCTPhantom-CVE-2026-64564
sctp: don't free the ASCONF's own transport in DEL-IP processing
48RISCO
abrir ↗GitHub PoC★ 1
renzi25031469/CVE-2026-19478
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir ↗GitHub PoC★ 1
Begitdj/cve-2019-2215-markw
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir ↗GitHub PoC
zavisco/CVE-2026-64849.yaml
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
98RISCO
abrir ↗GitHub PoC★ 1
Ring0-level process killer leveraging CVE-2026-0828 (BYOVD). Designed to demonstrate kernel-level process termination via a vulnerable signed driver, highlighting the security risks of Bring Your Own Vulnerable Driver attacks and the importance of driver trust, monitoring, and endpoint protection.
Kernel driver vulnerability in Safetica Endpoint Client
41RISCO
abrir ↗GitHub PoC
andreamammano89-maker/CVE-2021-42013_821311
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir ↗GitHub PoC★ 531
A cPanel and WHM authentication bypassing tool
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir ↗GitHub PoC
codeb0ssx/CVE-2026-64849-PoC
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
98RISCO
abrir ↗GitHub PoC★ 1
PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.
Portainer: Missing authorization on Docker plugin endpoints allows host RCE
48RISCO
abrir ↗GitHub PoC
TP-Link Archer BE800 V1 — Parental Control LAN RCE
Command Injection Vulnerability in Parent Control of Multiple TP-Link Archer Devices
41RISCO
abrir ↗GitHub PoC★ 11
CVE-2026-19478 PoC . Unauthenticated remote code-injection in GitLab's GraphQL layer
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir ↗GitHub PoC
IhsSpotlight/HeartBleed-CVE-2014-0160--SCRIPTS-python3
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir ↗GitHub PoC★ 2
CVE-2026-14669 - PostgreSQL to_char() timezone abbreviation heap buffer overflow PoC; for authorized security testing
PostgreSQL to_char heap buffer overflow executes arbitrary code
41RISCO
abrir ↗GitHub PoC
CVE-2026-43499 (GhostLock) — Linux kernel futex PI rt_mutex UAF ARM32 privilege escalation research targeting Huawei Watch 4 Pro (kernel 5.4.210)
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir ↗GitHub PoC★ 1
CVE-2026-19500 poc
SureForms contains an uncontrolled resource consumption vulnerability
41RISCO
abrir ↗GitHub PoC★ 3
CVE-2026-15748 - Unauthenticated RCE exploit for WordPress Forminator plugin (≤1.56.1). Automated detection, deep crawl, nonce extraction, and safe upload test. For authorized testing only.
Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration
48RISCO
abrir ↗GitHub PoC★ 10
Reproducible A/B lab + safe PoC for GitLab CVE-2026-19478 / CVE-2026-19650 (GraphQL @gl_introduced)
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir ↗GitHub PoC★ 3
CVE-2026-65400
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS
78RISCO
abrir ↗GitHub PoC
Technical analysis and clean Java Thread Echo PoC for Oracle WebLogic Server vulnerability chain.
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir ↗GitHub PoC★ 1
Windows Defender 0day vulnerability CVE-2026-69414 ShieldBreak
Microsoft Defender Elevation of Privilege Vulnerability
41RISCO
abrir ↗GitHub PoC
kaleth4/CVE-2026-64638
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.