Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
14.991 exploits
GitHub PoC205
Docker labs + defensive scanner for fastjson remote-class-load RCE. fastjson 1.2.66-1.2.83: @JSONType resource probe (CVE-2026-16723). fastjson2 2.0.57: attacker @type reaches loadClass with autoType DISABLED via polymorphic types (@JSONType(seeAlso) / Jackson @JsonSubTypes). Marker-only payloads; safeMode + JDK17 controls.
CVE-2026-16723CRITICAL20 jul 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISCO
abrir
GitHub PoC
HELLBOY3110/cve-2026-16219-croogo-lab
CVE-2026-16219MEDIUM20 jul 2026
Croogo CMS Admin File Manager FileManager.php isEditable path traversal
33RISCO
abrir
GitHub PoC
PoC reproducer for CVE-2026-49098 (Apache Camel camel-kafka): the non-Camel-prefixed kafka.OVERRIDE_TOPIC header escapes the upstream HTTP header filter and overrides the producer's configured topic, injecting an attacker-forged record onto a privileged Kafka topic (cross-topic injection). Fixed in 4.14.8/4.18.3/4.21.0.
CVE-2026-49098MEDIUM20 jul 2026
Apache Camel: Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-prefixed names that bypass the upstream HTTP header filter, allowing an HTTP client to redirect Kafka messages to an arbitrary topic
33RISCO
abrir
GitHub PoC1
WordPress wp2shell pre-auth RCE exploit kit (CVE-2026-63030 + CVE-2026-60137)
CVE-2026-63030CRITICALsob ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC
Defensive NGINX CVE-2026-42533 map regex risk audit with config scanner, Splunk/Defender notes, and lab evidence.
CVE-2026-42533CRITICAL20 jul 2026
NGINX Map directive and Regex matching vulnerability
48RISCO
abrir
GitHub PoC
PoC reproducer for CVE-2026-49097 (Apache Camel camel-irc): the non-Camel-prefixed irc.sendTo header escapes the HTTP header filter and overrides the producer's configured channel, redirecting an IRC message to an attacker-chosen destination. Fixed in 4.14.8/4.18.3/4.21.0.
CVE-2026-49097MEDIUM20 jul 2026
Apache Camel: Camel-IRC: The irc.sendTo (and other irc.*) Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to redirect outgoing IRC messages to arbitrary channels or users
33RISCO
abrir
GitHub PoC2
Unauthenticated Remote Code Execution (RCE) in WordPress Core allows attackers to execute arbitrary code without logging in by chaining CVE-2026-63030 and CVE-2026-60137, potentially leading to full site compromise.
CVE-2026-63030CRITICALsob ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC4
WordPress REST API SQLi to RCE (CVE-2026-63030)
CVE-2026-63030CRITICALsob ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC
PoC reproducer for CVE-2026-49086 (Apache Camel camel-dapr): the pub/sub consumer copies the untrusted CloudEvent's pubsubName/topic into producer-routing headers, letting an attacker redirect a republished message to an arbitrary Dapr pub/sub component+topic (confused deputy). Fixed in 4.14.8/4.18.3/4.21.0.
CVE-2026-49086MEDIUM20 jul 2026
Apache Camel Dapr: Pub/Sub consumer copied the inbound CloudEvent's pub/sub-name and topic into producer-direction routing headers, allowing an actor who can publish to the subscribed topic to influence internal behaviour
33RISCO
abrir
GitHub PoC
TheLiimbo/CVE-2026-51992
CVE-2026-5199220 jul 2026
23RISCO
abrir
GitHub PoC4
WordPress REST API SQLi to RCE PoC (CVE-2026-63030 & CVE-2026-60137)
CVE-2026-63030CRITICALsob ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC1
Apache Syncope: User self-service privilege escalation
CVE-2026-62183CRITICAL20 jul 2026
Apache Syncope: User self-service privilege escalation
48RISCO
abrir
GitHub PoC1
PoC tool for CVE-2026-44680 affecting MikroORM ≤7.0.13. Exploits JSON path injection to extract database contents via UNION-based attacks. Features vulnerability detection, automated data extraction, table enumeration, and blind injection support. Includes proxy integration for Burp Suite and WAF evasion techniques.
CVE-2026-44680HIGH20 jul 2026
MikroORM: SQL injection via runtime-controlled identifiers and JSON-path keys
41RISCO
abrir
GitHub PoC
wp2shell PoC with Cloudflare WAF bypass via body padding (CVE-2026-63030)
CVE-2026-63030CRITICALsob ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC
unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)
CVE-2026-63030CRITICALsob ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC
Dungsocool/CVE-2024-23897
CVE-2024-23897CRITICALsob ataqueransomware20 jul 2026
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
GitHub PoC313
A cPanel and WHM authentication bypassing tool
CVE-2026-41940CRITICALsob ataqueransomware20 jul 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC1
Proof-of-concept exploit for CVE-2026-63030, a pre-authentication vulnerability in WordPress (versions 6.9.0 through 7.0.1).
CVE-2026-63030CRITICALsob ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC2
CVE-2026-63030 - WordPress REST Batch Route-Confusion SQL Injection Proof of Concept
CVE-2026-63030CRITICALsob ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-48206: Apache Camel camel-jira IssueKey (and other non-Camel-prefixed) header injection driving arbitrary JIRA issue operations with the endpoint's service-account credentials (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-48206MEDIUM20 jul 2026
Apache Camel JIRA: A set of non-Camel-prefixed Exchange header constants bypass the HTTP header filter, allowing an HTTP client to drive arbitrary JIRA issue operations using the endpoint's configured credentials
33RISCO
abrir
GitHub PoC
Docker ortamında Apache HTTP Server 2.4.49 (CVE-2021-42013) zafiyetinin gösterildiği laboratuvar çalışması.
CVE-2021-42013CRITICALsob ataqueransomware20 jul 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC1
An isolated Vagrant testbed designed to simulate a complete attack chain: Initial access via the Nginx heap buffer overflow (CVE-2026-42533) followed by root privilege escalation using the Ghostlock kernel vulnerability (CVE-2026-43449).
CVE-2026-42533CRITICAL20 jul 2026
NGINX Map directive and Regex matching vulnerability
48RISCO
abrir
GitHub PoC1
joaovicdev/EXPLOIT-CVE-2026-63030
CVE-2026-63030CRITICALsob ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC
CVE-2026-60121, CVE-2026-61498 - Draft
CVE-2026-60121CRITICAL20 jul 2026
Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via ping.php
48RISCO
abrir
GitHub PoC1
PoC reproducer for CVE-2026-49042 (Apache Camel camel-langchain4j-tools): a prompt-injected LLM's tool-call arguments become unfiltered Exchange headers, hijacking the tool route's exec: sink for RCE. Fixed in 4.14.8/4.18.3/4.21.0.
CVE-2026-49042HIGH20 jul 2026
Apache Camel: langchain4j-tools: filter tool argument headers against declared parameters
41RISCO
abrir
GitHub PoC1
Detection script for CVE-2026-11374
CVE-2026-11374CRITICAL20 jul 2026
Account Takeover via Predictable SSO Ticket Generation
48RISCO
abrir
GitHub PoC2
noLKM,5.10 use CVE-2026-52910.
CVE-2026-52910HIGH20 jul 2026
bpf: Free reuseport cBPF prog after RCU grace period.
41RISCO
abrir
GitHub PoC5
PoC for CVE-2026-12191
CVE-2026-12191HIGH20 jul 2026
Comma AI Openpilot Pickle modeld.py pickle.loads deserialization
41RISCO
abrir
GitHub PoC
CVE-2026-4858 research
CVE-2026-4858HIGH20 jul 2026
Path traversal in integration action URL leading to arbitrary API execution via system admin’s auth token.
21RISCO
abrir
GitHub PoC16
YellowKey BitLocker CVE-2026-45585 is an open-source utility to extract, backup, and organize BitLocker recovery keys on Windows encrypted drives. Automate volume decryption, manage drive encryption states via command-line tools, export secure configuration files, and track recovery key logs. Download direct repository setup files.
CVE-2026-45585MEDIUM20 jul 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RISCO
abrir
anteriorpágina 33 / 500próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.