Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
24.466 exploits
Exploit-DB
Hydra - Stack Buffer Overflow
CVE-2026-56766HIGHremotelinux07 jul 2026
Hydra - Stack Buffer Overflow in NTLM Authentication Handler
41RISCO
abrir
Exploit-DB
Tenable Nessus 10.12.1 - SQL Injection
CVE-2026-57588LOWwebappsmultiple07 jul 2026
SQL Injection in Nessus via Malicious Scan Result File Import
28RISCO
abrir
Exploit-DB
WordPress Bricks Builder Theme - RCE
CVE-2024-25600CRITICALwebappsmultiple07 jul 2026
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir
Exploit-DB
WordPress Plugin WPZOOM Portfolio 1.4.21 - Reflected Cross-Site Scripting (XSS)
CVE-2026-49069HIGHwebappsmultiple06 jul 2026
WordPress WPZOOM Portfolio plugin <= 1.4.21 - Cross Site Scripting (XSS) vulnerability
56RISCO
abrir
Exploit-DB
MEmu Android Emulator 9.2.7.0 - Local Privilege Escalation
CVE-2026-36213HIGHlocalwindows06 jul 2026
An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges via the MemuService.e
41RISCO
abrir
Exploit-DB
Joomla Extension 4.1.4 - PHP Object injection
CVE-2026-48909CRITICALwebappsphp06 jul 2026
Joomla Extension - joomshaper.com - PHP Object injection in SP LMS extension for Joomla < 4.1.4
63RISCO
abrir
Exploit-DB
Pulpy 0.1.1-Beta - Filesystem Sandbox Bypass
CVE-2026-44225CRITICALwebappsmultiple06 jul 2026
Pulpy: Incomplete filesystem sandbox in pulpy.fs bridge allows packaged web apps to read arbitrary user files
48RISCO
abrir
Exploit-DB
KeepInMind 0.8.4.2 - Stored XSS
CVE-2026-9271MEDIUMwebappsmultiple06 jul 2026
KeepInMind - Dashboard Notes < 0.8.4.2 - Contributor+ Stored XSS
33RISCO
abrir
Exploit-DB
OpenEMR 7.0.2 - Arbitrary File Read
CVE-2026-24849CRITICALwebappsmultiple08 jun 2026
OpenEMR Arbitrary File Read Vulnerability
48RISCO
abrir
Exploit-DB
WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection
CVE-2026-3180HIGHwebappsmultiple05 jun 2026
Contest Gallery <= 28.1.4 - Unauthenticated SQL Injection
41RISCO
abrir
Exploit-DB
Drupal Core 10.5.5 - Error-Based SQL Injection
CVE-2026-9082CRITICALsob ataquewebappsphp01 jun 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISCO
abrir
Exploit-DB
WordPress OrderConvo 14 - Path Traversal
CVE-2025-10162HIGHwebappsmultiple01 jun 2026
OrderConvo < 14 - Unauthenticated Arbitrary File Read
56RISCO
abrir
Exploit-DB
YAMCS yamcs-core 5.12.7 - LDAP Injection
CVE-2026-42568MEDIUMwebappsmultiple30 mai 2026
Yamcs Vulnerable to LDAP Injection in LdapAuthModule
33RISCO
abrir
Exploit-DB
YAMCS yamcs-core 5.12.7 - No Rate Limiting
CVE-2026-44596MEDIUMwebappsmultiple30 mai 2026
Yamcs: No Rate Limiting on Authentication Endpoint
33RISCO
abrir
Exploit-DB
YAMCS yamcs-core 5.12.7 - User Enumeration
CVE-2026-44595MEDIUMwebappsmultiple30 mai 2026
Yamcs: Unauthorized user enumeration via IAM API endpoints
33RISCO
abrir
Exploit-DB
Notepad++ 8.9.6 - Arbitrary Code Execution
CVE-2026-48778HIGHremotewindows30 mai 2026
Notepad++: Arbitrary Code Execution via config.xml commandLineInterpreter
41RISCO
abrir
Exploit-DB
Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code Execution
CVE-2026-1830CRITICALwebappsmultiple29 mai 2026
Quick Playground <= 1.3.1 - Missing Authorization to Unauthenticated Arbitrary File Upload
63RISCO
abrir
Exploit-DB
ZTE H298A / H108N - Unauthenticated Credential Exposure
CVE-2026-34474HIGHlocalmultiple29 mai 2026
Sensitive data exposure leading to admin/WLAN credential leak in ZTE ZXHN H298A 1.1 and H108N 2.6. A crafted request to
46RISCO
abrir
Exploit-DB
ZTE ZXHN H188A V6 - Authentication Bypass
CVE-2026-34472HIGHlocalmultiple29 mai 2026
Unauthenticated credential disclosure in the wizard interface in ZTE ZXHN H188A V6.0.10P2_TE and V6.0.10P3N3_TE allows u
41RISCO
abrir
Exploit-DB
Linux Kernel - Local Privilege Escalation
CVE-2026-43284HIGHlocallinux29 mai 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISCO
abrir
Exploit-DB
ZTE Routers - Unauthenticated Denial of Service
CVE-2026-34473HIGHlocalmultiple29 mai 2026
Unauthenticated DoS in ZTE H8102E, H168N, H167A, H199A, H288A, H198A, H267A, H267N, H268A, H388X, H196A, H369A, H268N, H
41RISCO
abrir
Exploit-DB
CubeCart < 6.7.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated)
CVE-2026-44376MEDIUMwebappsmultiple29 mai 2026
CubeCart: Reflected XSS in Store Search Bar
33RISCO
abrir
Exploit-DB
Microsoft - NTLMv2 Hash Capture
CVE-2026-32202MEDIUMsob ataqueremotewindows29 mai 2026
Windows Shell Spoofing Vulnerability
75RISCO
abrir
Exploit-DB
ImageMagick - Infinite Loop in the MIFF decoder can lead to CPU exhaustion
CVE-2026-46522HIGHlocalmultiple29 mai 2026
ImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustion
41RISCO
abrir
Exploit-DB
Wing FTP Server 8.1.3 - Authenticated Remote Code Execution
CVE-2026-44403HIGHremotemultiple29 mai 2026
Wing FTP Server < 8.1.3 Authenticated Remote Code Execution via Session Serialization
41RISCO
abrir
Exploit-DB
Linux Kernel - Local Privilege Escalation
CVE-2026-43500HIGHlocallinux29 mai 2026
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
78RISCO
abrir
Exploit-DB
Langflow 1.3.0 - Remote Code Execution
CVE-2026-0770CRITICALsob ataquewebappsmultiple29 mai 2026
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
100RISCO
abrir
Exploit-DB
Prodigy Commerce 3.3.0 - Local File Inclusion
CVE-2026-0926CRITICALwebappsmultiple29 mai 2026
Prodigy Commerce <= 3.3.0 - Unauthenticated Local File Inclusion via parameters[template_name]
63RISCO
abrir
Exploit-DB
MixPHP Framework 2.2.17 - Unsafe Deserialization Remote Code Execution
CVE-2026-42471HIGHwebappsphp29 mai 2026
Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke client (Connection.php:76) cal
41RISCO
abrir
Exploit-DB
Linux Kernel - Local Privilege Escalation
CVE-2026-46300HIGHlocallinux29 mai 2026
net: skbuff: preserve shared-frag marker during coalescing
56RISCO
abrir

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.