Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.781exploits catalogados
36.771CVEs com exploração pública
24.695testados em laboratório
79.386 exploits
GitHub PoC
Password-Protected Category Bypass via JSON Format in JoomGallery
CVE-2026-66916MEDIUM23 ago 2026
Joomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON Format in JoomGallery < 4.4.0
33RISCO
abrir
GitHub PoC4
Reproducible lab for CVE-2026-10053 (GitLab npm package-registry path traversal -> arbitrary file write as git). Vulnerable 19.2.1 vs patched 19.2.2, deterministic oracle.
CVE-2026-10053HIGH23 ago 2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
41RISCO
abrir
GitHub PoC
From MCPJam Inspector RCE to root — CVE-2026-23744, JupyterLab token disclosure, kernel execution, and OPSMCP privilege escalation
CVE-2026-23744CRITICAL23 ago 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
GitHub PoC
IDOR + Stored XSS via Broken Object-Level Authorization in JoomGallery
CVE-2026-66917HIGH23 ago 2026
Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery < 4.4.0
41RISCO
abrir
GitHub PoC
Exploiting the vsftpd 2.3.4 backdoor (CVE-2011-2523) on Metasploitable2 — a hands-on pentesting lab writeup covering recon, exploitation, and remediation.
CVE-2011-252323 ago 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
GitHub PoC1
PoC exploit chain for CVE-2026-15718: SpiderMonkey wasm baseline compiler array.fill missing-sync -> invalid pointer -> addrOf/fakeobj -> arbitrary R/W -> RCE
CVE-2026-15718MEDIUM23 ago 2026
Invalid pointer in the JavaScript: WebAssembly component
33RISCO
abrir
GitHub PoC
h00die/POC-CVE-2026-19681
CVE-2026-19681CRITICAL23 ago 2026
Command Injection
63RISCO
abrir
GitHub PoC
Copy Fail CVE-2016-5195
CVE-2016-5195HIGHsob ataque22 ago 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC
Detection & precondition-verification tool for CVE-2026-58231 (SAP Commerce Cloud Data Hub Adapter)
CVE-2026-58231CRITICAL22 ago 2026
Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
48RISCO
abrir
GitHub PoC174
POC pre-auth RCE on Exchange
CVE-2026-62911HIGH22 ago 2026
Microsoft Exchange Server Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC
MinhHK68/CVE-2026-13736
CVE-2026-13736MEDIUM22 ago 2026
NewPath WildApricotPress Add-on – Member Directory <= 1.0.0 - Unauthenticated Member PII Disclosure via REST API
33RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-13671HIGHsob ataque22 ago 2026
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as
83RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-13671HIGHsob ataque22 ago 2026
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as
83RISCO
abrir
GitHub PoC
Gitlab-CVE-2026-19478
CVE-2026-19478CRITICAL22 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir
GitHub PoC1
PoC for CVE-2026-75616, an authenticated OS command injection in TP-Link Archer C20 v6 firmware
CVE-2026-75616HIGH22 ago 2026
Command Injection in Router Web Management Interface
41RISCO
abrir
GitHub PoC
CVE-2026-32475
CVE-2026-32475CRITICAL22 ago 2026
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RISCO
abrir
GitHub PoC4
Apple MacOS Screen Sharing Arbitrary File read/write -> RCE
CVE-2026-65400CRITICALsob ataque22 ago 2026
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS
78RISCO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHsob ataque22 ago 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC3
내 공유기가 Zbtlink ENDLESSDOORS 백도어(CVE-2026-66747) 대상인지 클릭 한 번으로 검사하는 Windows 프로그램
CVE-2026-66747CRITICAL22 ago 2026
ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-65400CRITICALsob ataque22 ago 2026
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS
78RISCO
abrir
GitHub PoC
llaytynher/CVE-2026-0740-upload-template
CVE-2026-0740CRITICAL22 ago 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-19478CRITICAL22 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-28000CRITICAL22 ago 2026
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISCO
abrir
GitHub PoC
Metasploit-based penetration test on an isolated Metasploitable2 lab VM — remote exploitation via DistCC (CVE-2004-2687), privilege escalation via udev netlink (CVE-2009-1185), and vsftpd 2.3.4 backdoor analysis (CVE-2011-2523), with firewall mitigation validated end-to-end.
CVE-2011-252322 ago 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
VulnCheck XDB
info-leak
CVE-2026-34909CRITICALsob ataque22 ago 2026
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to a
90RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-0740CRITICAL22 ago 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RISCO
abrir
GitHub PoC
ts zeroday exp made by nullsec white team
CVE-2026-41940CRITICALsob ataqueransomware22 ago 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-34910CRITICALsob ataque22 ago 2026
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS
100RISCO
abrir
GitHub PoC
CVE-2026-47630 — NVIDIA Triton Inference Server: arbitrary dlopen via TRITON_BATCH_STRATEGY_PATH
CVE-2026-47630MEDIUM22 ago 2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path travers
33RISCO
abrir
GitHub PoC
Stored XSS in J2Commerce Guest Checkout via Cookie Filter Bypass
CVE-2026-74252HIGH22 ago 2026
Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5
41RISCO
abrir
anteriorpágina 11 / 2.647próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.