Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
14.986 exploits
GitHub PoC
CVE-2026-9806 is a Stored Cross-Site Scripting (Stored XSS) vulnerability affecting CTI Transmute versions prior to the patched release.
CVE-2026-9806MEDIUM02 ago 2026
Stored Cross-Site Scripting (XSS) in CTI Transmute Notification Panel via Malicious Convert Names
33RISCO
abrir
GitHub PoC
CVE-2026-9811 is a Stored Cross-Site Scripting (Stored XSS) vulnerability affecting Mautic 7 (versions 7.0.0 through 7.1.1).
CVE-2026-9811MEDIUM02 ago 2026
A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering s
33RISCO
abrir
GitHub PoC
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
CVE-2026-59941MEDIUM02 ago 2026
Dompdf: Uncontrolled resource consumption based on declared BMP dimensions
33RISCO
abrir
GitHub PoC
Python implementation/PoC for CVE-2024-40422. Exploits a critical directory traversal vulnerability in Devika v1's /api/get-browser-snapshot endpoint to read arbitrary system files.
CVE-2024-40422CRITICAL02 ago 2026
The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path tr
68RISCO
abrir
GitHub PoC20
the CVE-2026-43499 by iqooneo11
CVE-2026-43499HIGH02 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC1
Mass vulnerability scanner for CVE-2026-49049 – Unauthenticated Remote Code Execution in Joomla Helix3 plugin. Multi‑threaded, detects both executed and raw PHP payloads.
CVE-2026-49049HIGH02 ago 2026
Joomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler
56RISCO
abrir
GitHub PoC3
WordPress CVE-2026-63030 and CVE-2026-60137 security tool for detecting exposure to the WP2Shell pre-authentication RCE chain.
CVE-2026-63030CRITICALsob ataque02 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC
CVE-2026-9809 is a Stored Cross-Site Scripting (Stored XSS) vulnerability affecting Mautic 7 (versions 7.0.0 through 7.1.1).
CVE-2026-9809HIGH02 ago 2026
A stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project
41RISCO
abrir
GitHub PoC
Log4Shell (CVE-2021-44228) research report — technical breakdown, root cause analysis, and end-to-end lab-reproduced exploit chain with evidence screenshots.
CVE-2021-44228CRITICALsob ataqueransomware02 ago 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
VMware vCenter Server CVE-2021-21972 (RCE) — vulnerability analysis, detection, and mitigation
CVE-2021-21972CRITICALsob ataqueransomware02 ago 2026
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir
GitHub PoC3
CVE-2026-43499 for the Meta Quest
CVE-2026-43499HIGH02 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC1
TryHackMe Dirty Frag (CVE-2026-43284) — Linux LPE writeup
CVE-2026-43284HIGH02 ago 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISCO
abrir
GitHub PoC
RichardKabuto/CVE-2026-52370
CVE-2026-52370MEDIUM01 ago 2026
A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execu
13RISCO
abrir
GitHub PoC
My write-ups from CyberDefenders' Blue Team labs, solved using Wireshark. Covers TeamCity RCE (CVE-2024-27198), XSS session hijacking, and LLMNR/NBT-NS credential poisoning — each with step-by-step packet analysis, screenshots, and a full Wireshark filter/command reference. Personal SOC Analyst Tier 1 learning log.
CVE-2024-27198CRITICALsob ataqueransomware01 ago 2026
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir
GitHub PoC
Read-only-by-default WordPress incident-response scanner for the “wp2shell” attack chain (CVE-2026-60137 / CVE-2026-63030): detects shadow-admin, database and filesystem IOCs, verifies core integrity, and exports evidence. Optional controlled account cleanup; does not remove malware.
CVE-2026-60137MEDIUMsob ataque01 ago 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISCO
abrir
GitHub PoC7
Root prototype for Galaxy S26 (SM-S942U) that is very much indev
CVE-2026-43499HIGH01 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC168
YellowKey BitLocker CVE-2026-45585 free open-source utility to extract, backup and view BitLocker recovery keys on Windows 10/11. BitLocker bypass vulnerability tool, remediation and mitigation. Tom's Hardware coverage. Check TPM status, protector types, encryption state. Download YellowKey free, portable, no install needed.
CVE-2026-45585MEDIUM01 ago 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RISCO
abrir
GitHub PoC
CVE-2026-8237 is an Insecure Direct Object Reference (IDOR) vulnerability caused by missing authorization checks in Concrete CMS 9.5.0 and earlier.
CVE-2026-8237MEDIUM01 ago 2026
Concrete CMS 9.5.0 and below is vulnerable to IDOR in the`/ccm/frontend/conversations/message_detail` endpoint
48RISCO
abrir
GitHub PoC
Consul Template's writeToFile helper opened an operator-supplied destination directly and followed linked path components, allowing rendered output to escape the intended directory and overwrite a preexisting file.
CVE-2026-14361MEDIUM01 ago 2026
Consul-template is vulnerable to path redirection in writeToFile through symlink attack
33RISCO
abrir
GitHub PoC1
Standalone CVE-2026-43499 port for Galaxy A36 5G SM-A366W A366WVLS3AYG1 with KernelSU late-load
CVE-2026-43499HIGH01 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC1
Advanced CVE-2023-44487 HTTP/2 Rapid Reset vulnerability exploitation framework. Features multi-connection concurrent attacks, adaptive rate control, stealth mode with randomized headers, real-time metrics, and risk assessment reporting. For authorized penetration testing only. By Sudeepa Wanigarathna
CVE-2023-44487HIGHsob ataque01 ago 2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISCO
abrir
GitHub PoC
CVE-2026-8239 is an Insecure Direct Object Reference (IDOR) vulnerability affecting Concrete CMS 9.5.0 and earlier.
CVE-2026-8239MEDIUM01 ago 2026
Concrete CMS 9.5.0 and below is vulnerable to IDOR in '/ccm/frontend/conversations/get_rating'
33RISCO
abrir
GitHub PoC
raihants/cve-2026-10702
CVE-2026-10702MEDIUM01 ago 2026
JIT miscompilation in the JavaScript Engine: JIT component
33RISCO
abrir
GitHub PoC1
Wolf CMS <= 0.8.3.1 - RCE via Arbitrary File Write
CVE-2026-67206HIGH01 ago 2026
Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Upload
41RISCO
abrir
GitHub PoC
Kestra Unauthenticated RCE Exploit (CVE-2026-53576)
CVE-2026-53576CRITICAL01 ago 2026
Kestra: Unauthenticated RCE via /configs path-suffix auth-filter bypass
63RISCO
abrir
GitHub PoC
PD2229B的43499(ghostlock)可行性研究
CVE-2026-43499HIGH01 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
CVE-2026-67595 — Embedded malicious JavaScript (spyware) in VaahCMS 2.0.0–2.3.4 official releases. CVSS 8.1. Advisory + detection.
CVE-2026-67595CRITICAL01 ago 2026
VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php
48RISCO
abrir
GitHub PoC
Vulnerability research write-ups — CVE-2026-12478 (libsoup), Apple WebKit, Google VRP
CVE-2026-12478MEDIUM01 ago 2026
Libsoup: incomplete fix for cve-2026-0716: out-of-bounds read in libsoup websocket frame processing (unmasked path)
33RISCO
abrir
GitHub PoC
Full-lifecycle vulnerability management on a live Log4Shell (CVE-2021-44228) target — scan, manual exploitation, network detection, and remediation verification. Nessus, Suricata, Wireshark, Docker.
CVE-2021-44228CRITICALsob ataqueransomware01 ago 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC1
PoC & checker for CVE-2026-15964 - unauthenticated password change in the WordPress plugin Single Sign On For TNG <= 2.0.0 (CVSS 9.8)
CVE-2026-15964CRITICAL01 ago 2026
Single Sign On For TNG <= 2.0.0 - Unauthenticated Privilege Escalation via Unverified Password Change
48RISCO
abrir
anteriorpágina 22 / 500próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.