Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
14.991 exploits
GitHub PoC
Isolated regression and security-control lab for CVE-2026-59891 in @sigstore/oci
CVE-2026-59891CRITICAL28 jul 2026
Credential confusion in  @sigstore/oci  can leak registry credentials to an attacker-controlled registry
48RISCO
abrir
GitHub PoC10
KSU installer for supported firmware with CVE-2026-43499
CVE-2026-43499HIGH28 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC1
A PoC for CVE-2026-64725
CVE-2026-64725HIGH28 jul 2026
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS
41RISCO
abrir
GitHub PoC
Simulated a real-world attack (CVE-2011-2523) against a vulnerable host, then cross-checked detection coverage against an existing Wazuh/Suricata/Zeek SOC — uncovering and fixing 5 real monitoring pipeline bugs along the way.
CVE-2011-252328 jul 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
GitHub PoC
CVE-2026-61511 - Draft or Todo
CVE-2026-61511CRITICAL28 jul 2026
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
85RISCO
abrir
GitHub PoC
Clickbait. The CVE is AI slop.
CVE-2026-5130228 jul 2026
23RISCO
abrir
GitHub PoC3
cve-2026-61511
CVE-2026-61511CRITICAL28 jul 2026
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
85RISCO
abrir
GitHub PoC11
A proof-of-concept script to exploit CVE-2026-16232, an authentication bypass via the SmartConsole login process using an application token.
CVE-2026-16232CRITICALsob ataque28 jul 2026
Authentication Bypass in the SmartConsole Login Process Using an Application Token
100RISCO
abrir
GitHub PoC
CyberVinner/CP-PLUS-EZ-P21-CVE-2026-65893-65894
CVE-2026-65893HIGH28 jul 2026
Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera
41RISCO
abrir
GitHub PoC
0xdak/CVE-2025-71389_exploit
CVE-2025-71389CRITICAL28 jul 2026
Cal.com before 5.9.9 Remote Code Execution via RSC
48RISCO
abrir
GitHub PoC
CVE-2026-14856 TastyIgniter v4.3.0
CVE-2026-14856MEDIUM28 jul 2026
Stored Cross-Site Scripting (XSS) in TastyIgniter Media Manager
33RISCO
abrir
GitHub PoC3
CVE-2026-53264 - Draft or Todo
CVE-2026-53264HIGH28 jul 2026
net/sched: act_api: use RCU with deferred freeing for action lifecycle
41RISCO
abrir
GitHub PoC4
Fastjson 1.2.83 RCE 靶场环境 (CVE-2026-16723)
CVE-2026-16723CRITICAL28 jul 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISCO
abrir
GitHub PoC
bha-vin/CVE-2026-64600-Exploit
CVE-2026-64600HIGH28 jul 2026
xfs: resample the data fork mapping after cycling ILOCK
41RISCO
abrir
GitHub PoC
letsr00t/RefluxFS_CVE-2026-64600
CVE-2026-64600HIGH28 jul 2026
xfs: resample the data fork mapping after cycling ILOCK
41RISCO
abrir
GitHub PoC
Proof of Concept for CVE-2026-65761 - EasyStore Pro Unauthenticated SQL Injection via `filter_sortby`
CVE-2026-65761CRITICAL28 jul 2026
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1
63RISCO
abrir
GitHub PoC
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVE-2026-50522CRITICALsob ataque27 jul 2026
Microsoft SharePoint Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC12
Unprivileged user to root on macOS Sonoma, Sequoia, and Tahoe. Patched in macOS 26.6 / 15.7.8 / 14.8.8.
CVE-2026-39875HIGH27 jul 2026
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonom
41RISCO
abrir
GitHub PoC1
A poc for a vulnerability in ZTE File Manager (zte.com.cn.filer) which allows to read arbitrary files from other apps as the privileges of this file manager
CVE-2026-40000LOW27 jul 2026
Path Traversal Vulnerability in ZTE Blade A75 5G
28RISCO
abrir
GitHub PoC
Phucc29/CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware27 jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
jelasin/CVE-2026-42533
CVE-2026-42533CRITICAL27 jul 2026
NGINX Map directive and Regex matching vulnerability
48RISCO
abrir
GitHub PoC
Procjevt/CVE-2026-58138
CVE-2026-58138CRITICAL27 jul 2026
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
63RISCO
abrir
GitHub PoC1
CVE-2026-65008
CVE-2026-65008CRITICAL27 jul 2026
Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData
48RISCO
abrir
GitHub PoC
The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings.
CVE-2026-9830HIGH27 jul 2026
BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback Bug
41RISCO
abrir
GitHub PoC
PoC and analysis of CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware27 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC2
Read-only WordPress security scanner for HestiaCP servers. Detects wp2shell compromise indicators (CVE-2026-63030 / CVE-2026-60137) across all hosted sites — per-user email reports, core file diff against clean WordPress, PHP/JS/htaccess/image analysis, and optional AI evaluation via Claude API.
CVE-2026-63030CRITICALsob ataque27 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC3
A POC for the recently discovered Qualys bug on COW with XFS
CVE-2026-64600HIGH27 jul 2026
xfs: resample the data fork mapping after cycling ILOCK
41RISCO
abrir
GitHub PoC1
CVE-2026-43499: Linux kernel futex PI use-after-free research package
CVE-2026-43499HIGH27 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC1
CVE-2026-15013
CVE-2026-15013CRITICAL27 jul 2026
SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm Confusion
48RISCO
abrir
GitHub PoC1
soralis0912/CVE-2026-43499-pmg110-root
CVE-2026-43499HIGH27 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
anteriorpágina 26 / 500próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.