Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.095exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
80.095 exploits
GitHub PoC21
TheCyberGeek/CVE-2026-4480-PoC
CVE-2026-4480CRITICAL05 jun 2026
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RISCO
abrir
GitHub PoC
t1ckprivate/CVE-2026-31431-Copy-Fail
CVE-2026-31431HIGHsob ataque05 jun 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-3300CRITICAL05 jun 2026
Everest Forms Pro <= 1.9.12 - Unauthenticated Remote Code Execution via Calculation Field
75RISCO
abrir
GitHub PoC
cve-2026-23744 python exploit
CVE-2026-23744CRITICAL05 jun 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-4480CRITICAL05 jun 2026
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RISCO
abrir
GitHub PoC
Exploit for Copy-Fail Vulnerability - Python3 Version
CVE-2026-31431HIGHsob ataque05 jun 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC
This Python proof-of-concept targets a vulnerable MCP (Model Context Protocol) service exposed by the target application. The vulnerability allows an attacker to supply arbitrary server configuration parameters through the /api/mcp/connect endpoint.
CVE-2026-23744CRITICAL05 jun 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
GitHub PoC
CVE-2026-23631-Draft
CVE-2026-23631MEDIUM04 jun 2026
redis-server Lua use-after-free may allow remote code execution
33RISCO
abrir
VulnCheck XDB
info-leak
CVE-2013-611704 jun 2026
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive informatio
50RISCO
abrir
GitHub PoC29
HTTP/2 Bomb PoC — CVE-2026-49975 (HPACK indexed reference bomb + flow-control stall)
CVE-2026-49975HIGH04 jun 2026
Apache HTTP Server: mod_http2 denial of service
53RISCO
abrir
GitHub PoC2
Proof of Concept (PoC) exploit for CVE-2026-6815: Authenticated Path Traversal & Arbitrary File Write in Casdoor (< 3.54.1) leading to RCE/DoS.
CVE-2026-6815MEDIUM04 jun 2026
CVE-2026-6815
33RISCO
abrir
VulnCheck XDB
local
CVE-2026-31635HIGH04 jun 2026
rxrpc: fix oversized RESPONSE authenticator length check
41RISCO
abrir
GitHub PoC
PoC CVE-2026-8732 (WP Maps Pro <= 6.1.0)
CVE-2026-8732CRITICAL04 jun 2026
WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action
68RISCO
abrir
GitHub PoC
CVE-2026-35904 / CVE-2026-35905 / CVE-2026-35906 — Unauth RCE, Hardcoded Root Creds & Telnet Enable in T3 Technology CPE
CVE-2026-35904CRITICAL04 jun 2026
Incorrect access control in the web management interface of T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, an
48RISCO
abrir
GitHub PoC1
horrister/solarwinds-sunburst-cve-2020-10148
CVE-2020-10148CRITICALsob ataque04 jun 2026
SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
100RISCO
abrir
GitHub PoC1
Detect-only scanner for CVE-2026-42945 (NGINX Rift), a heap overflow in ngx_http_rewrite_module. Version detection + nginx.conf pattern analysis. Python 3 stdlib-only, no network calls.
CVE-2026-42945CRITICAL04 jun 2026
NGINX ngx_http_rewrite_module vulnerability
60RISCO
abrir
GitHub PoC
CVE-2026-23744
CVE-2026-23744CRITICAL04 jun 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
GitHub PoC
Improved Metasploit module for CVE-2013-6117 (Dahua DVR authentication bypass)
CVE-2013-611704 jun 2026
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive informatio
50RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-34234CRITICAL04 jun 2026
CtrlPanel: Unauthenticated RCE using installer script
48RISCO
abrir
GitHub PoC
CVE-2026-50142 — Heap allocation vulnerability in libheif HEIF sequence parser
CVE-2026-50142HIGH04 jun 2026
libheif: unbounded heap allocation in HEIF sequence parser (stsz fixed-size mode missing bound check)
41RISCO
abrir
VulnCheck XDB
info-leak
CVE-2024-1698CRITICAL04 jun 2026
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RISCO
abrir
GitHub PoC
CVE-2026-45247 - Draft
CVE-2026-45247CRITICALsob ataque04 jun 2026
Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection
83RISCO
abrir
GitHub PoC
HTB Facts is a Easy Linux box featuring Camaleon CMS and MinIO. Gain admin access via open registration and a mass assignment vulnerability, then extract MinIO credentials from admin settings. Use CVE-2024-46987 path traversal to steal an SSH private key, crack its passphrase, and escalate to root by abusing sudo permissions on facter via GTFOBins.
CVE-2024-46987HIGH04 jun 2026
Arbitrary path traversal in Camaleon CMS
61RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2026-41089CRITICAL04 jun 2026
Windows Netlogon Remote Code Execution Vulnerability
70RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2026-41089CRITICAL04 jun 2026
Windows Netlogon Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC
rootdirective-sec/CVE-2026-34234-Lab
CVE-2026-34234CRITICAL04 jun 2026
CtrlPanel: Unauthenticated RCE using installer script
48RISCO
abrir
GitHub PoC
Piotnet Forms Pro <= 2.1.40 - Unauthenticated Arbitrary File Upload → RCE
CVE-2026-4883CRITICAL04 jun 2026
Piotnet Forms <= 2.1.40 - Unauthenticated Arbitrary File Upload via Form File Upload
48RISCO
abrir
GitHub PoC13
Attack surface in the real-world environment of CVE-2026-41096
CVE-2026-41096CRITICAL04 jun 2026
Windows DNS Client Remote Code Execution Vulnerability
48RISCO
abrir
GitHub PoC
CVE-2026-5076 — ARMember Premium <= 7.3.1 Insecure Password Reset Mechanism → Full Admin Account Takeover | Proof of Concept
CVE-2026-5076CRITICAL04 jun 2026
ARMember Premium <= 7.3.1 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation
48RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2026-41089CRITICAL04 jun 2026
Windows Netlogon Remote Code Execution Vulnerability
70RISCO
abrir
anteriorpágina 105 / 2.670próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.