Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
79.305 exploits
GitHub PoC1
React2Shell is a proof-of-concept exploit for CVE-2025-55182 affecting vulnerable React Server Components (RSC) implementations in Next.js
CVE-2025-55182CRITICALsob ataqueransomware24 jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Security Advisory: Infinite Loop DoS in facil.io MIME Parser (Partial Boundary)
CVE-2026-66730HIGH24 jul 2026
facil.io 0.6.0 - 0.7.6 Infinite Loop DoS via Multipart MIME Body Parser
41RISCO
abrir
GitHub PoC
risorse di ricerca per cve-2026-7228
CVE-2026-7228MEDIUM24 jul 2026
SourceCodester Pizzafy Ecommerce System ajax.php get_cart_count sql injection
33RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALsob ataque24 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC
Lite-os15/Lab-001-Gitea-CVE-2026-20896-
CVE-2026-20896CRITICAL24 jul 2026
Gitea Docker image trusts spoofable reverse-proxy headers by default
63RISCO
abrir
GitHub PoC
Reproduction of cve-2024-23897-jenkins_lfi_reproduction
CVE-2024-23897CRITICALsob ataqueransomware24 jul 2026
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
GitHub PoC
Reproduction of cve-2024-3400-panos_rce_reproduction
CVE-2024-3400CRITICALsob ataqueransomware24 jul 2026
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISCO
abrir
GitHub PoC
kxom9ks/CVE-2024-27198-TeamCity
CVE-2024-27198CRITICALsob ataqueransomware24 jul 2026
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir
GitHub PoC
Legacy HPE iMC vuln
CVE-2019-539223 jul 2026
A disclosure of information vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than ve
23RISCO
abrir
GitHub PoC
CVE Reproduction: cve-2025-5777-citrixbleed2_reproduction
CVE-2025-5777CRITICALsob ataqueransomware23 jul 2026
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
GitHub PoC
Initialized & connected PostgreSQL to Metasploit. Reconnoitered 10.1.16.0/24 with Nmap and imported results. Enumerated hosts/services using SYN, SMB & LDAP scanners. Exploited DC10 via ZeroLogon (CVE-2020-1472), dumped AD NTLM hashes with Impacket, performed Pass-the-Hash, then gained a Meterpreter reverse shell.
CVE-2020-1472MEDIUMsob ataqueransomware23 jul 2026
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC
CVE Reproduction: cve-2025-2783-chrome_sandbox_escape_reproduction
CVE-2025-2783HIGHsob ataque23 jul 2026
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
71RISCO
abrir
GitHub PoC
CVE Reproduction: cve-2025-55182-react2shell_reproduction
CVE-2025-55182CRITICALsob ataqueransomware23 jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Tproot es una máquina de nivel Muy Fácil de DockerLabs centrada en la explotación manual del servicio vsftpd 2.3.4 (CVE-2011-2523).
CVE-2011-252323 jul 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL23 jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
GitHub PoC
finding by nvth
CVE-2026-59880HIGH23 jul 2026
Immutable.js: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
21RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALsob ataqueransomware23 jul 2026
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISCO
abrir
GitHub PoC
CVE Reproduction: cve-2026-0770-langflow_rce_reproduction
CVE-2026-0770CRITICALsob ataque23 jul 2026
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
info-leak
CVE-2024-43451MEDIUMsob ataque23 jul 2026
NTLM Hash Disclosure Spoofing Vulnerability
85RISCO
abrir
GitHub PoC1
CVE Reproduction: cve-2026-41940-cpanel_authbypass_reproduction
CVE-2026-41940CRITICALsob ataqueransomware23 jul 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC
Security analysis and report of CVE-2024-6387 OpenSSH vulnerability, including vulnerability details, CVSS evaluation, and mitigation recommendations.
CVE-2024-6387HIGH23 jul 2026
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir
GitHub PoC
Proof-of-concept and offensive security research analyzing CVE-2026-23744 (MCPJam Inspector Unauthenticated RCE, Patched in v1.4.3+).
CVE-2026-23744CRITICAL23 jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
GitHub PoC
Metabase CVE-2026-59827 Vulnerability Scanner
CVE-2026-59827CRITICAL23 jul 2026
Metabase: Unsafe Deserialization of H2 Query Results
48RISCO
abrir
GitHub PoC326
Certighost POC
CVE-2026-54121HIGH23 jul 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC
CVE Reproduction: cve-2026-63030_60137-wordpress_rce_reproduction
CVE-2026-63030CRITICALsob ataque23 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC5
CVE-2026-43499 exploit configuration for realme RMX3888 (Android 16) - 20 verified kernel offsets
CVE-2026-43499HIGH23 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
ghostpels/CVE-2026-13001
CVE-2026-13001CRITICAL23 jul 2026
Podlove Podcast Publisher <= 4.5.1 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter
63RISCO
abrir
GitHub PoC
CVE-2026-66374: Knot Resolver 6.3.0 DNS-over-QUIC heap overflow (RCE)
CVE-2026-66374HIGH23 jul 2026
Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) rece
41RISCO
abrir
GitHub PoC
CVE Reproduction: cve-2024-4577-phpcgi_rce_reproduction
CVE-2024-4577CRITICALsob ataqueransomware23 jul 2026
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC1
CVE-2021-41773 Apache
CVE-2021-41773HIGHsob ataqueransomware23 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
anteriorpágina 42 / 2.644próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.