Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
14.991 exploits
GitHub PoC
My portfolio showcasing vulnerability research (CVE-2026-11989, CVE-2026-11395) and automated threat orchestration engineering (Lucius Engine, TalonVigil).
CVE-2026-11989MEDIUM15 jul 2026
Bit integrations <= 2.8.7 - Unauthenticated Server-Side Request Forgery via Form Field Upload Mapping
33RISCO
abrir
GitHub PoC
Blog on CVE-2026-59827, Unsafe H2 query ouput deserialization
CVE-2026-59827CRITICAL15 jul 2026
Metabase: Unsafe Deserialization of H2 Query Results
48RISCO
abrir
GitHub PoC4
Pix for WooCommerce Unauthenticated File Upload via certificate_crt_path Parameter | CVSS 9.8
CVE-2026-3891CRITICAL15 jul 2026
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RISCO
abrir
GitHub PoC
CVE-2026-15410 - More: https://github.com/HORKimhab/poc-cve-collection
CVE-2026-15410HIGHsob ataqueransomware15 jul 2026
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the S
76RISCO
abrir
GitHub PoC
WhatsWrongAndWhy/CVE-2016-9793
CVE-2016-979315 jul 2026
The sock_setsockopt function in net/core/sock.c in the Linux kernel before 4.8.14 mishandles negative values of sk_sndbu
23RISCO
abrir
GitHub PoC
A containerized enterprise-style lab for researching and defending against CVE-2026-27483.
CVE-2026-27483HIGH15 jul 2026
MindsDB has Path Traversal in /api/files Leading to Remote Code Execution
61RISCO
abrir
GitHub PoC3
CvE-2026-43499偏移量计算
CVE-2026-43499HIGH15 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC29
PoC for CVE-2026-58635: Windows Narrator Braille Local Privilege Escalation
CVE-2026-58635HIGH15 jul 2026
Windows Narrator Braille Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC
ctnBobong32/CVE-2026-43499-so-build
CVE-2026-43499HIGH15 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
NeseOS-Corp/CVE-2026-50657
CVE-2026-50657MEDIUM15 jul 2026
Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability
33RISCO
abrir
GitHub PoC
The GREENDARK hospital infrastructure was configured by Dr. Gusto Rogue prior to his termination. No further details are provided.
CVE-2021-41773HIGHsob ataqueransomware15 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
Cxyofficial/x200-cve-2026-43499
CVE-2026-43499HIGH15 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
CVE-2026-43499 Implementation for 6.12.23-android16-5-g75e9b1c7ae7c-abogki463945075-4k
CVE-2026-43499HIGH15 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC13
CVE-2026-56164 EOP Exploit
CVE-2026-56164MEDIUMsob ataque15 jul 2026
Microsoft SharePoint Server Elevation of Privilege Vulnerability
68RISCO
abrir
GitHub PoC2
CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).
CVE-2026-58138CRITICAL15 jul 2026
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
63RISCO
abrir
GitHub PoC1
罗技云掌机 · GhostLock CVE-2026-43499 root 尝试
CVE-2026-43499HIGH15 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
A 16-year-old bug in the Linux kernel lets a rented VM break out and attack the host it runs on. Intel and AMD alike. Januscape is a use-after-free vulnerability in the KVM code that has been sitting there since 2010.
CVE-2026-53359HIGH15 jul 2026
KVM: x86: Fix shadow paging use-after-free due to unexpected role
41RISCO
abrir
GitHub PoC
Podlove Podcast Publisher Unauthenticated File Upload RCE via is_image() vs extract_file_extension() Mismatch | CVSS 9.8
CVE-2026-13001CRITICAL15 jul 2026
Podlove Podcast Publisher <= 4.5.1 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter
63RISCO
abrir
GitHub PoC1
ctn-Qvo/CVE-2026-43499-so-build
CVE-2026-43499HIGH15 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC1
A modified method to root Android device with locked bootloader via new exploit. (Only for Samsung now or smthing like that devices cuz i ported it to N970U1), Fork of https://github.com/localhosts-A/CyberMeowfia
CVE-2026-43499HIGH15 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
firstlax6t/CVE-2026-36669-FengOffice
CVE-2026-36669CRITICAL15 jul 2026
An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote
48RISCO
abrir
GitHub PoC
Technical analysis and safety-conscious research harness for CVE-2019-6447 in ES File Explorer for Android
CVE-2019-644715 jul 2026
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-46585: Apache Camel camel-lucene QUERY header injection enabling authorization bypass / index data exfiltration (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-46585HIGH15 jul 2026
Apache Camel Lucene: The query control headers used non-Camel-prefixed names (QUERY, RETURN_LUCENE_DOCS) that bypass the HTTP header filter, allowing an HTTP client to inject the full-text search query
41RISCO
abrir
GitHub PoC
CVE-2025-60357- NoSQL(MongoDB) Injection POC
CVE-2025-60357HIGH15 jul 2026
AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability via the eventlog/agentEv
41RISCO
abrir
GitHub PoC
exploit for CVE-2022-42889
CVE-2022-4288915 jul 2026
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC10
CvE-2026-43499偏移量计算
CVE-2026-43499HIGH15 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC3
A lightweight, fast tool to scan and detect the "regreSSHion" OpenSSH remote code execution vulnerability (CVE-2024-6387).
CVE-2024-6387HIGH15 jul 2026
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir
GitHub PoC
Kanak-CypherX/cve-2024-4577-lab
CVE-2024-4577CRITICALsob ataqueransomware15 jul 2026
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
asoka666/Cve-2020-11023
CVE-2020-11023MEDIUMsob ataque14 jul 2026
Potential XSS vulnerability in jQuery
85RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-46457 — Apache Camel camel-nats inbound header injection (Camel control-header injection via a NATS publisher; CamelHttpUri -> SSRF)
CVE-2026-46457HIGH14 jul 2026
Apache Camel: Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilterStrategy, allowing a client that can publish to the subject to inject Camel control headers
41RISCO
abrir
anteriorpágina 39 / 500próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.