Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
14.946 exploits
GitHub PoC1
4gaBoards < 3.3.9 - User Information Disclosure
CVE-2026-53959MEDIUM19 ago 2026
4gaBoards: Mass Information Disclosure (Internal PII Leakage) on /api/users to any authenticated user
33RISCO
abrir
GitHub PoC
Oracle OID LDAP Server Privileges Management Exploit
CVE-2026-61241CRITICAL19 ago 2026
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Suppor
28RISCO
abrir
GitHub PoC
fork and edits from https://github.com/aniqfakhrul/CVE-2026-54121
CVE-2026-54121HIGH19 ago 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC
fastjson jsontype利用
CVE-2026-16723CRITICAL19 ago 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISCO
abrir
GitHub PoC1
halo cms plugin 1-request rce from a url, PoC + exploit chain
CVE-2026-67919CRITICAL19 ago 2026
An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri m
48RISCO
abrir
GitHub PoC
CVE-2026-64849 PoC
CVE-2026-64849CRITICALsob ataque19 ago 2026
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
98RISCO
abrir
GitHub PoC
CVE-2026-18504, CVE-2026-16732 - Draft or TODO
CVE-2026-18504MEDIUM19 ago 2026
fastify vulnerable to schema validation bypass via root primitive coercion mismatch
33RISCO
abrir
GitHub PoC1
0xdeadroot/SCTPhantom-CVE-2026-64564
CVE-2026-64564CRITICAL19 ago 2026
sctp: don't free the ASCONF's own transport in DEL-IP processing
48RISCO
abrir
GitHub PoC1
renzi25031469/CVE-2026-19478
CVE-2026-19478CRITICAL19 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir
GitHub PoC1
Begitdj/cve-2019-2215-markw
CVE-2019-2215HIGHsob ataque19 ago 2026
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir
GitHub PoC
zavisco/CVE-2026-64849.yaml
CVE-2026-64849CRITICALsob ataque19 ago 2026
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
98RISCO
abrir
GitHub PoC1
Ring0-level process killer leveraging CVE-2026-0828 (BYOVD). Designed to demonstrate kernel-level process termination via a vulnerable signed driver, highlighting the security risks of Bring Your Own Vulnerable Driver attacks and the importance of driver trust, monitoring, and endpoint protection.
CVE-2026-0828HIGH19 ago 2026
Kernel driver vulnerability in Safetica Endpoint Client
41RISCO
abrir
GitHub PoC
andreamammano89-maker/CVE-2021-42013_821311
CVE-2021-42013CRITICALsob ataqueransomware19 ago 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC531
A cPanel and WHM authentication bypassing tool
CVE-2026-41940CRITICALsob ataqueransomware19 ago 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC
codeb0ssx/CVE-2026-64849-PoC
CVE-2026-64849CRITICALsob ataque18 ago 2026
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
98RISCO
abrir
GitHub PoC
0xROI/CVE-2026-77113
CVE-2026-77113MEDIUM18 ago 2026
Path Traversal Vulnerability in apport-unpack
33RISCO
abrir
GitHub PoC1
PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.
CVE-2026-44848CRITICAL18 ago 2026
Portainer: Missing authorization on Docker plugin endpoints allows host RCE
48RISCO
abrir
GitHub PoC
TP-Link Archer BE800 V1 — Parental Control LAN RCE
CVE-2026-9254HIGH18 ago 2026
Command Injection Vulnerability in Parent Control of Multiple TP-Link Archer Devices
41RISCO
abrir
GitHub PoC11
CVE-2026-19478 PoC . Unauthenticated remote code-injection in GitLab's GraphQL layer
CVE-2026-19478CRITICAL18 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir
GitHub PoC
IhsSpotlight/HeartBleed-CVE-2014-0160--SCRIPTS-python3
CVE-2014-0160HIGHsob ataque18 ago 2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
GitHub PoC2
CVE-2026-14669 - PostgreSQL to_char() timezone abbreviation heap buffer overflow PoC; for authorized security testing
CVE-2026-14669HIGH18 ago 2026
PostgreSQL to_char heap buffer overflow executes arbitrary code
41RISCO
abrir
GitHub PoC
CVE-2026-43499 (GhostLock) — Linux kernel futex PI rt_mutex UAF ARM32 privilege escalation research targeting Huawei Watch 4 Pro (kernel 5.4.210)
CVE-2026-43499HIGH18 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC1
CVE-2026-19500 poc
CVE-2026-19500HIGH18 ago 2026
SureForms contains an uncontrolled resource consumption vulnerability
41RISCO
abrir
GitHub PoC3
CVE-2026-15748 - Unauthenticated RCE exploit for WordPress Forminator plugin (≤1.56.1). Automated detection, deep crawl, nonce extraction, and safe upload test. For authorized testing only.
CVE-2026-15748CRITICAL18 ago 2026
Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration
48RISCO
abrir
GitHub PoC10
Reproducible A/B lab + safe PoC for GitLab CVE-2026-19478 / CVE-2026-19650 (GraphQL @gl_introduced)
CVE-2026-19478CRITICAL18 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir
GitHub PoC3
CVE-2026-65400
CVE-2026-65400CRITICALsob ataque18 ago 2026
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS
78RISCO
abrir
GitHub PoC
Technical analysis and clean Java Thread Echo PoC for Oracle WebLogic Server vulnerability chain.
CVE-2020-14882CRITICALsob ataque18 ago 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISCO
abrir
GitHub PoC1
Windows Defender 0day vulnerability CVE-2026-69414 ShieldBreak
CVE-2026-69414HIGH18 ago 2026
Microsoft Defender Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC
CVE-2026-19501 poc
CVE-2026-19501HIGH18 ago 2026
CVE-2026-19501
41RISCO
abrir
GitHub PoC
kaleth4/CVE-2026-64638
CVE-2026-64638HIGH18 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RISCO
abrir

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.