Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.858exploits catalogados
36.825CVEs com exploração pública
24.695testados em laboratório
79.858 exploits
VulnCheck XDB
initial-access
CVE-2026-33032CRITICAL21 ago 2026
Nginx UI: Unauthenticated MCP Endpoint Allows Remote Nginx Takeover
75RISCO
abrir
GitHub PoC1
Custom Content Types and Fields plugin for WordPress
CVE-2026-19598CRITICAL21 ago 2026
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
63RISCO
abrir
GitHub PoC1
Hunt-Benito/rendering-code-outside-the-sandbox-cve-2026-76036-dawn-webgpu-buffer-overflow-in-chrome-on-android
CVE-2026-76036CRITICAL21 ago 2026
Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbi
48RISCO
abrir
GitHub PoC
Reflected XSS via price_from & price_to Filter Parameters in PhocaCart
CVE-2026-76565MEDIUM21 ago 2026
Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7
33RISCO
abrir
GitHub PoC
JCEzploit is a powerful, fully-automated RCE exploit for Joomla JCE (CVE-2026-48907) featuring interactive shell, batch command execution, file download capability, and proxy support. Built with Python & Rich for penetration testers. Ethical use only. By Sudeepa Wanigarathna.
CVE-2026-48907CRITICALsob ataque21 ago 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISCO
abrir
GitHub PoC
CVE-2026-41567 1day
CVE-2026-41567HIGH21 ago 2026
Docker: `PUT /containers/{id}/archive` executes container binary on the host
41RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2022-36804HIGHsob ataque21 ago 2026
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
GitHub PoC
CVE-2026-39113: SQLite SQLAR heap-buffer-overflow advisory and reproducer
CVE-2026-39113MEDIUM21 ago 2026
Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3a
33RISCO
abrir
GitHub PoC1
CVE-2026-69836 — Unauthenticated RCE via Entra ID deserialization
CVE-2026-69836CRITICAL21 ago 2026
Microsoft Entra ID Remote Code Execution Vulnerability
48RISCO
abrir
GitHub PoC5
CVE-2026-73570
CVE-2026-73570HIGHsob ataque21 ago 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RISCO
abrir
GitHub PoC
CVE-2022-36804 Bitbucket command execution and file transfer tool
CVE-2022-36804HIGHsob ataque21 ago 2026
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISCO
abrir
GitHub PoC2
wp2shell — WordPress Core Pre-Auth RCE Chain poc for CVE-2026-63030 and CVE-2026-60137
CVE-2026-63030CRITICALsob ataque21 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
VulnCheck XDB
info-leak
CVE-2026-65400CRITICALsob ataque21 ago 2026
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS
78RISCO
abrir
GitHub PoC7
Read-only PoC for CVE-2026-65400 — macOS Screen Sharing (screensharingd) pre-auth SRP bypass giving root file read. Patched in macOS 26.6.1 / 15.7.9 / 14.8.9.
CVE-2026-65400CRITICALsob ataque21 ago 2026
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS
78RISCO
abrir
GitHub PoC
PoC for J2Store CVE-2026-67358–67362 (J2Commerce security advisory Aug 2026)
CVE-2026-67358MEDIUM21 ago 2026
Joomla Extension - j2commerce.com - Download quota manipulation in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5
33RISCO
abrir
GitHub PoC1
Educational use only!
CVE-2026-64638HIGH21 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RISCO
abrir
GitHub PoC40
Exploit for KeyCloak CVE-2026-18963
CVE-2026-18963CRITICAL20 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISCO
abrir
GitHub PoC
CVE-2026-19478: GitLab GraphQL Vulnerability PoC
CVE-2026-19478CRITICAL20 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir
GitHub PoC15
Hunt for CVE-2026-18963 exploitation traces (Keycloak unauthenticated account takeover) in the Keycloak database
CVE-2026-18963CRITICAL20 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISCO
abrir
GitHub PoC
This python script exploit the vulnerable marimo /terminal/ws endpoint and returns a interactive shell.
CVE-2026-39987CRITICALsob ataque20 ago 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-39987CRITICALsob ataque20 ago 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALsob ataqueransomware20 ago 2026
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC1
Safely detect Citrix NetScaler CVE-2026-8452
CVE-2026-8452HIGHsob ataque20 ago 2026
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
71RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-19478CRITICAL20 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir
VulnCheck XDB
local
CVE-2025-21479HIGHsob ataque20 ago 2026
Incorrect Authorization in Graphics
71RISCO
abrir
GitHub PoC1
elkhaoudari/CVE-2018-7600-PoC
CVE-2018-7600CRITICALsob ataqueransomware20 ago 2026
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC
aarch64 race condition checker
CVE-2026-46242HIGH20 ago 2026
eventpoll: fix ep_remove struct eventpoll / struct file UAF
41RISCO
abrir
GitHub PoC
Hunt-Benito/the-same-key-opens-every-box-cve-2026-71960-hard-coded-jwt-secret-in-cudy-wr3000-mesh-mqtt
CVE-2026-71960CRITICAL20 ago 2026
Cudy WR3000 2.0 Hard-coded JWT Secret Authentication Bypass via MQTT
48RISCO
abrir
GitHub PoC
Controlled PenTest lab report for UnrealIRCd 3.2.8.1 backdoor (CVE-2010-2075) on Metasploitable3 with remediation steps.
CVE-2010-207520 ago 2026
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RISCO
abrir
GitHub PoC
CVE-2026-18366: Events Manager < 7.4.1 — Unauthenticated Privilege Escalation to Administrator. Write-up and proof-of-concept (poc.py).
CVE-2026-18366CRITICAL20 ago 2026
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
48RISCO
abrir
anteriorpágina 18 / 2.662próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.