Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.275exploits catalogados
36.462CVEs com exploração pública
24.695testados em laboratório
79.274 exploits
GitHub PoC
AJCloud AJY IPC Firmware Path Traversal via jdbhttpd
CVE-2026-56718HIGH03 set 2026
AJCloud AJY IPC Firmware Path Traversal via jdbhttpd
41RISCO
abrir
GitHub PoC
PoC for CVE-2026-4813
CVE-2026-4813CRITICAL03 set 2026
Code injection in the Lutece Core
48RISCO
abrir
GitHub PoC
🧰 CVE-2026-65643 – cPanel Domain Parking RCE Toolkit (CVSS 8.7) | Red/Blue Team suite for unpatched cPanel & WHM 11.x (110,134,136,138). 2 tools: Full Exploit (reverse shell, webshell, persistence, root passwd, file R/W, mass scan, Tor), Blue Team PoC (detection, reporting, audit). w/Python. 🦾 Only Use Ethically, Stay Legal <3
CVE-2026-65643HIGH03 set 2026
Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
41RISCO
abrir
GitHub PoC
CVE‑2026‑82329 is a critical authentication bypass in JFrog Artifactory (CVSS 9.8) allowing unauthenticated attackers to obtain full administrative privileges. Actively exploited in the wild. Affects self‑hosted versions before patches. PoC for authorized testing only.
CVE-2026-82329CRITICALsob ataque03 set 2026
Potential authentication bypass leading to administrative access in Artifactory
93RISCO
abrir
GitHub PoC
Stored XSS via Location Title in DPCalendar Free
CVE-2026-78071HIGH03 set 2026
Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0 - 10.11.2
41RISCO
abrir
GitHub PoC
Recovery notes for proxmox advisory ID: PSA-2026-00043-1 (CVE-2023-54391)
CVE-2023-54391CRITICAL03 set 2026
Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter
48RISCO
abrir
GitHub PoC
SQL Injection via ORDER BY Shortcode in plg_content_dpcalendar — DPCalendar Free ≤ 10.11.2
CVE-2026-78070MEDIUM03 set 2026
Joomla Extension - digital-peak.com - Authenticated, privileged blind SQL injection in DP Calendar 5.5.0 - 10.11.2
33RISCO
abrir
GitHub PoC
CVE-2026-80428 PoC
CVE-2026-80428CRITICAL03 set 2026
ILIAS before 9.22, 10.10 and 11.3 Unauthenticated PHP Object Injection via Shibboleth Logout Endpoint
48RISCO
abrir
GitHub PoC
Vulnerability Analysis of CVE-2026-83548 affecting SonicWall SMA1000 security systems.
CVE-2026-83548CRITICALsob ataque03 set 2026
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended altern
78RISCO
abrir
GitHub PoC
Research lab and exploit chain for CVE-2026-75604: path traversal in the Next.js incremental cache, to RCE on Windows.
CVE-2026-75604CRITICAL03 set 2026
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
48RISCO
abrir
GitHub PoC
CVE-2026-80428 PoC
CVE-2026-80428CRITICAL03 set 2026
ILIAS before 9.22, 10.10 and 11.3 Unauthenticated PHP Object Injection via Shibboleth Logout Endpoint
48RISCO
abrir
GitHub PoC
CVE-2026-20212 - Draft or TODO
CVE-2026-20212CRITICAL03 set 2026
Cisco Nexus 3000 and 9000 Series Switches Silicon One Hardware Abstraction Layer Remote Code Execution Vulnerability
48RISCO
abrir
GitHub PoC
CVE-2026-73296
CVE-2026-73296CRITICAL02 set 2026
Microsoft UFO: Unauthenticated Mobile MCP access allows remote Android device control and screen disclosure
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-82329CRITICALsob ataque02 set 2026
Potential authentication bypass leading to administrative access in Artifactory
93RISCO
abrir
GitHub PoC
byt3l0rd/CVE-2026-73570
CVE-2026-73570HIGHsob ataque02 set 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-0768CRITICAL02 set 2026
Langflow code Code Injection Remote Code Execution Vulnerability
48RISCO
abrir
GitHub PoC
Bypassing connect()-based syscall rules using TCP Fast Open (CVE-2026-63828 PoC)
CVE-2026-63828HIGH02 set 2026
apparmor: mediate the implicit connect of TCP fast open sendmsg
41RISCO
abrir
GitHub PoC
CVE-2026-9586 - Draft or TODO
CVE-2026-9586CRITICALsob ataque02 set 2026
Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB
83RISCO
abrir
Exploit-DB
Langflow 1.10.0 - RCE
CVE-2026-9198CRITICALsob ataquewebappsmultiple02 set 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISCO
abrir
GitHub PoC
SAP-system-update/CVE-2026-58231
CVE-2026-58231CRITICAL02 set 2026
Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
48RISCO
abrir
GitHub PoC1
CVE-2026-65343 PoC — AppleKeyStore OOB read → KASLR defeat (iOS 26.6 / 23G71)
CVE-2026-65343HIGH02 set 2026
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.
41RISCO
abrir
GitHub PoC1
CVE-2026-64788 PoC — IOGPUFamily Use-After-Free (iOS 26.6 / 23G71)
CVE-2026-64788MEDIUM02 set 2026
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe
33RISCO
abrir
GitHub PoC1
CVE-2026-65330 PoC — setxattr PAC bypass via fixed #0x307a diversifier (iOS 26.6 / 23G71)
CVE-2026-65330MEDIUM02 set 2026
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe
33RISCO
abrir
GitHub PoC1
NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC
CVE-2026-19490CRITICAL02 set 2026
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
48RISCO
abrir
GitHub PoC
CVE-2026-9335: KerasFileEditor and load_weights follow h5py ExternalLinks, disclosing arbitrary local HDF5 file contents in keras ≤ 3.14.0. Advisory + verified PoCs.
CVE-2026-9335MEDIUM02 set 2026
Improper Handling of HDF5 ExternalLinks in keras-team/keras
33RISCO
abrir
GitHub PoC1
CVE-2026-65349 PoC — getattrlist OOB write in vfs_attr_pack_internal (iOS 26.6 / 23G71)
CVE-2026-65349MEDIUM02 set 2026
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1,
33RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-39987CRITICALsob ataque02 set 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISCO
abrir
GitHub PoC
CVE-2026-0828
CVE-2026-0828HIGH02 set 2026
Kernel driver vulnerability in Safetica Endpoint Client
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-18963CRITICAL02 set 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-0920CRITICAL02 set 2026
LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter
48RISCO
abrir
página 1 / 2.643próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.