Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.095exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
80.095 exploits
GitHub PoC
jenniferreire26/CVE-2024-21182
CVE-2024-21182HIGHsob ataque09 jun 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
93RISCO
abrir
GitHub PoC1
CVE-2026-48907: Unauthenticated RCE in JCE (Proof Of Concept)
CVE-2026-48907CRITICALsob ataque09 jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISCO
abrir
GitHub PoC
CVE-2026-45247 - Mirasvit Full Page Cache Warmer for Magento 2 Unauthenticated PHP Object Injection -> Remote Code Execution
CVE-2026-45247CRITICALsob ataque09 jun 2026
Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection
83RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-48907CRITICALsob ataque09 jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2025-11262HIGH09 jun 2026
Link Whisper Free <= 0.9.0 - Unauthenticated Stored Cross-Site Scripting
41RISCO
abrir
GitHub PoC
jenniferreire26/CVE-2026-45659
CVE-2026-45659HIGHsob ataqueransomware09 jun 2026
Microsoft SharePoint Remote Code Execution Vulnerability
93RISCO
abrir
GitHub PoC
jenniferreire26/CVE-2026-41089
CVE-2026-41089CRITICAL09 jun 2026
Windows Netlogon Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC1
PoC de CVE-2025-48595: desbordamiento de entero en multiples ubicaciones del Framework de Android.
CVE-2025-48595HIGHsob ataque09 jun 2026
In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to
71RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-10520CRITICAL09 jun 2026
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RISCO
abrir
GitHub PoC
v3s9er/CVE-2026-52885
CVE-2026-52885HIGH09 jun 2026
Notepad++ TOCTOU: HMAC Checks Disk, Executes from Memory
41RISCO
abrir
GitHub PoC
fevar54/CVE-2024-21182---Oracle-WebLogic-Server-JNDI-Injection-RCE
CVE-2024-21182HIGHsob ataque09 jun 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
93RISCO
abrir
GitHub PoC
Go Proof of Concept (PoC) exploit for Flowise CustomMCP Remote Code Execution (RCE) CVE-2025-59528
CVE-2025-59528CRITICAL09 jun 2026
Flowise has Remote Code Execution vulnerability
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-8054CRITICAL09 jun 2026
Unauthenticated SQL Injection in dotCMS Publish Audit API
63RISCO
abrir
GitHub PoC
Patched google_gax 0.4.1 for Tesla 1.18.3+ compatibility (CVE-2026-48598)
CVE-2026-48598LOW09 jun 2026
CRLF injection in Tesla.Multipart disposition parameters allows multipart part header injection
28RISCO
abrir
GitHub PoC
kennedy-aikohi/mcpjam-cve-2026-23744-validator
CVE-2026-23744CRITICAL09 jun 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2023-21716CRITICAL08 jun 2026
Microsoft Word Remote Code Execution Vulnerability
70RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-7465HIGH08 jun 2026
Spectra Gutenberg Blocks <= 2.19.25 - Authenticated (Contributor+) Remote Code Execution via Arbitrary PHP Function Call via Block Attributes
41RISCO
abrir
GitHub PoC
carlosalbertotuma/cve-2026-3180-poc
CVE-2026-3180HIGH08 jun 2026
Contest Gallery <= 28.1.4 - Unauthenticated SQL Injection
41RISCO
abrir
GitHub PoC
GNU-InetUtils-telnetd-Authentication-Bypass-Vulnerability
CVE-2026-24061CRITICALsob ataque08 jun 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC3
A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass
CVE-2026-24061CRITICALsob ataque08 jun 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-57819CRITICALsob ataque08 jun 2026
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir
GitHub PoC2
Disclosed on June 3, 2026, the "HTTP/2 Bomb" is an unauthenticated remote DoS that combines an HPACK compression bomb with a Slowloris-style hold to exhaust server memory. It affects default HTTP/2 configurations of **nginx, Apache httpd, Microsoft IIS, Envoy, and Cloudflare Pingora**.
CVE-2026-49975HIGH08 jun 2026
Apache HTTP Server: mod_http2 denial of service
53RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-1676308 jun 2026
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir
GitHub PoC
YellowKey | BitLocker Bypass CVE-2026-45585 | Detect & Fix Automatically via Microsoft Intune
CVE-2026-45585MEDIUM08 jun 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALsob ataque08 jun 2026
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
GitHub PoC
rootdirective-sec/CVE-2026-7465-Lab
CVE-2026-7465HIGH08 jun 2026
Spectra Gutenberg Blocks <= 2.19.25 - Authenticated (Contributor+) Remote Code Execution via Arbitrary PHP Function Call via Block Attributes
41RISCO
abrir
GitHub PoC1
smb spooler to RCE
CVE-2026-4480CRITICAL08 jun 2026
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RISCO
abrir
GitHub PoC
Python tool for analyzing CVE-2018-16763 in FUEL CMS with cleaner response parsing and interactive vulnerability checking.
CVE-2018-1676308 jun 2026
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir
GitHub PoC
Exploitability PoC for CVE-2026-43512 (Apache Tomcat Digest Authentication Bypass)
CVE-2026-43512CRITICAL08 jun 2026
Apache Tomcat: Digest authenticator will authenticate any unknown user
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALsob ataque08 jun 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
anteriorpágina 101 / 2.670próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.