Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8.829Nuclei 4.350Metasploit 3.489✓ só verificadosrecentespopularesrisco
14.497 exploits
GitHub PoC★ 2
Learn how I found my first two CVEs by pure accident.
Calix GigaSpire Web Management utilities_configurationsave.cgi denial of service
33RISCO
abrir ↗GitHub PoC
Static XML fixtures for authorized bug bounty testing of XML parser behaviour (CVE-2026-45071).
Symfony: XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse = true
41RISCO
abrir ↗GitHub PoC
joaovicdev/EXPLOIT-CVE-2026-9198
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISCO
abrir ↗GitHub PoC
FranklinF25/cve-2026-42533
NGINX Map directive and Regex matching vulnerability
48RISCO
abrir ↗GitHub PoC
Testing CVE-2026-70463 by Fyyre
rsync 3.1.0 < 3.5.0 Authorization Bypass via auth users Directive Parsing
41RISCO
abrir ↗GitHub PoC
CVE-2026-66384 - Draft or TODO
Authenticated users may write data outside the intended Docker cache path
33RISCO
abrir ↗GitHub PoC
Wazuh Rules for Detection Zimbra (CVE-2026-73570).
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
91RISCO
abrir ↗GitHub PoC
A specialized Python framework that executes unauthenticated remote code execution via the 9Router Model Context Protocol (MCP) bridge by deploying a 33-layer temporal phase cascade, Riemann-Hadamard dispersion, and an 11 ns wedge filter to bypass traditional proxy and process-monitoring defenses.
9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
63RISCO
abrir ↗GitHub PoC
IKEv1 VPN scanners, attempts a Check Point authentication-bypass exploit, and includes internal network scanning and reverse-shell features.
User Authentication Bypass in VPN Remote Access and Mobile Access
100RISCO
abrir ↗GitHub PoC
CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, CVE-2026-20313
Cisco Catalyst SD-WAN Security Hardening Release - Input Validation Vulnerabilities
48RISCO
abrir ↗GitHub PoC
CVE-2015-5287
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain perm
86RISCO
abrir ↗GitHub PoC
Writeup + CVE analysis + countermeasures for the Hacktivity 'Vulnerabilities, Exploits, and Remote Access Payloads' lab (netcat shells, Metasploit, CVE-2010-1240, CVE-2004-2687).
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote at
60RISCO
abrir ↗GitHub PoC
CVE-2026-55040
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISCO
abrir ↗GitHub PoC
CVE-2026-77542, CVE-2026-77543, CVE-2026-77545, CVE-2026-77550, CVE-2026-77551, CVE-2026-77552, CVE-2026-77553, CVE-2026-77554, CVE-2026-77557 - Draft or TODO
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit
48RISCO
abrir ↗GitHub PoC
Hunt-Benito/the-token-was-a-row-number-cve-2026-67602-phpipam-rest-api-authentication-bypass
phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cache
48RISCO
abrir ↗GitHub PoC
Gvln-S/CVE-2011-2523
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir ↗GitHub PoC★ 1
CVE-2026-18431 - Draft or TODO
Avada <= 7.16 and Fusion Builder <= 3.16 - Unauthenticated Remote Code Execution via Arbitrary File Write
48RISCO
abrir ↗GitHub PoC
Writeup + CVE analysis + countermeasures for the Hacktivity 'Vulnerabilities, Exploits, and Remote Access Payloads' lab (netcat shells, Metasploit, CVE-2010-1240, CVE-2004-2687).
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RISCO
abrir ↗GitHub PoC
CVE-2015-3246
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly mod
78RISCO
abrir ↗GitHub PoC
SneakyNachos/CVE-2026-74936-gc-potato
Use-after-free in the JavaScript: WebAssembly component
48RISCO
abrir ↗GitHub PoC★ 3
GitLab Code injection
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir ↗GitHub PoC
sahmsec/CVE-2026-32475
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RISCO
abrir ↗GitHub PoC★ 2
CVE-2026-18963 Keycloak Reset-Credentials State Bypass Detector
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISCO
abrir ↗GitHub PoC
A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISCO
abrir ↗GitHub PoC
Minimal reproduction for Spring AI ParagraphManager sibling self-loop OOM (incomplete fix of CVE-2026-47851)
Unbounded recursion over attacker-controlled PDF outline tree in Spring AI PDF Document Reader
41RISCO
abrir ↗GitHub PoC
Poc CVE-2026-18080
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.8 - Unauthenticated Arbitrary File Upload via CRM Email Connect IMAP Attachment
48RISCO
abrir ↗página 1 / 484próximo →
Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.