Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.781exploits catalogados
36.771CVEs com exploração pública
24.695testados em laboratório
79.526 exploits
VulnCheck XDB
initial-access
CVE-2026-10520CRITICAL24 ago 2026
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RISCO
abrir
GitHub PoC
CVE-2025-48595 Android Framework Integer Overflow PoC - 优化版
CVE-2025-48595HIGHsob ataque24 ago 2026
In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to
71RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-9198CRITICALsob ataque24 ago 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISCO
abrir
GitHub PoC2
T0w0T/POC-CVE-2026-18963
CVE-2026-18963CRITICAL24 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-78329 (Apache Camel camel-undertow header filter strategy not applied, websocket.* injection) — Camel Spring Boot
CVE-2026-78329CRITICAL24 ago 2026
Apache Camel: Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes
48RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-66907 (Apache Camel camel-google-storage downloadFileName path traversal) — Camel Spring Boot + Camel Quarkus
CVE-2026-66907HIGH24 ago 2026
Apache Camel: Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result
41RISCO
abrir
GitHub PoC
SIMPLE EXPOIT FOR CVE-2025-55182 FOR RCE , COMMAND INJECTIONS AND OTHER VULNERABILITIES
CVE-2025-55182CRITICALsob ataqueransomware24 ago 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-71300 (Apache Camel camel-atmosphere-websocket dispatch header injection) — Camel Spring Boot
CVE-2026-71300CRITICAL24 ago 2026
Apache Camel: Camel-Atmosphere-Websocket: WebSocket dispatch header injection
48RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-28672 (Apache Ranger UnixUserGroupBuilder OS command injection via username in the unixusersync module)
CVE-2026-28672CRITICAL24 ago 2026
Apache Ranger: OS Command Injection via Username in UnixUserGroupBuilder
48RISCO
abrir
GitHub PoC2
CVE-2026-77806漏洞检测代码
CVE-2026-77806CRITICAL24 ago 2026
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August
63RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-59230 (Apache Camel camel-mail MimeMultipart headersInline header injection) — Camel Spring Boot + Camel Quarkus
CVE-2026-59230MEDIUM24 ago 2026
Apache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled
33RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-66906 (Apache Camel camel-azure-storage-blob downloadBlobToFile path traversal) — Camel Spring Boot + Camel Quarkus
CVE-2026-66906CRITICAL24 ago 2026
Apache Camel: Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir
48RISCO
abrir
GitHub PoC1
Firefox content-to-parent IPDL privilege escalation (N-day, bug 2054416): forged PDocumentChannel with RemoteTypeOverride -> privilegedabout process placement, via mojo-port send-path injection from a compromised content process
CVE-2026-74939HIGH24 ago 2026
Privilege escalation in the DOM: Navigation component
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware24 ago 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2025-20333CRITICALsob ataque24 ago 2026
A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secu
100RISCO
abrir
GitHub PoC
Demostración práctica y bitácora técnica de explotación de BlueKeep (CVE-2019-0708) en RDP usando Nmap y Metasploit, documentando la resolución de errores en el entorno virtual.
CVE-2019-0708CRITICALsob ataqueransomware24 ago 2026
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC
Patch: Heap overflow in SSL-VPN (Fortinet FortiOS)
CVE-2026-12087CRITICAL24 ago 2026
Socket versions before 2.041 for Perl have an out-of-bounds heap read
48RISCO
abrir
GitHub PoC
Patch: Command injection in GlobalProtect (Palo Alto PAN-OS)
CVE-2026-14290MEDIUM24 ago 2026
Embed Google Photos Album Easily <= 2.2.1 - Contributor+ Stored XSS via link Shortcode Attribute
33RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-63621 (Apache Camel camel-knative structured CloudEvent header injection) — Camel Spring Boot + Camel Quarkus
CVE-2026-63621MEDIUM24 ago 2026
Apache Camel: Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy
33RISCO
abrir
GitHub PoC
CVE-2026-73570 PoC
CVE-2026-73570HIGHsob ataque24 ago 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RISCO
abrir
GitHub PoC
h00die/POC-CVE-2026-19679
CVE-2026-19679HIGH24 ago 2026
Improper Input Validation
41RISCO
abrir
GitHub PoC
Demostracion educativa de mitigacion de CVE-2026-68820: Use-After-Free en afd.sys de Windows.
CVE-2026-68820HIGHsob ataque24 ago 2026
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
71RISCO
abrir
GitHub PoC
Password-Protected Category Bypass via JSON Format in JoomGallery
CVE-2026-66916MEDIUM23 ago 2026
Joomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON Format in JoomGallery < 4.4.0
33RISCO
abrir
GitHub PoC
IDOR + Stored XSS via Broken Object-Level Authorization in JoomGallery
CVE-2026-66917HIGH23 ago 2026
Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery < 4.4.0
41RISCO
abrir
GitHub PoC1
Legendile7/CVE-2026-78122-POC
CVE-2026-78122HIGH23 ago 2026
docker-socket-proxy through 0.5.0 Insufficient Access Control Granularity Exposes Container Filesystems
41RISCO
abrir
GitHub PoC
Professional PHPMyAdmin 5.0.0 SQL Injection (CVE-2020-5504) exploitation framework with automated database enumeration, table extraction, and data dumping capabilities. Features blind injection, proxy support, JSON output, and comprehensive error handling for authorized penetration testing and security research. Author: Sudeepa Wanigarathna
CVE-2020-550423 ago 2026
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could
35RISCO
abrir
GitHub PoC4
Reproducible lab for CVE-2026-10053 (GitLab npm package-registry path traversal -> arbitrary file write as git). Vulnerable 19.2.1 vs patched 19.2.2, deterministic oracle.
CVE-2026-10053HIGH23 ago 2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
41RISCO
abrir
GitHub PoC
h00die/POC-CVE-2026-19681
CVE-2026-19681CRITICAL23 ago 2026
Command Injection
63RISCO
abrir
GitHub PoC
chessalekin/cve-2026-9198_exploit
CVE-2026-9198CRITICALsob ataque23 ago 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISCO
abrir
GitHub PoC
CVSS v3.1 assessment of CVE-2009-0658 (Adobe Acrobat Buffer Overflow), including Base, Temporal, and Environmental scoring and remediation recommendations.
CVE-2009-065823 ago 2026
Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitra
60RISCO
abrir
anteriorpágina 12 / 2.651próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.