Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.386exploits catalogados
36.533CVEs com exploração pública
24.695testados em laboratório
14.991 exploits
GitHub PoC
Unauthenticated RCE in DBGate <= 7.1.8
CVE-2026-47668CRITICAL31 jul 2026
DbGate: Unauthenticated Remote Code Execution via JSON Script Runner
63RISCO
abrir
GitHub PoC
CVE-2026-8337 is an Insecure Direct Object Reference (IDOR) vulnerability in Concrete CMS that affects the Survey feature. Unlike CVE-2026-8347 (which involved Express associations), this vulnerability allows an unauthenticated attacker to participate in a restricted/private survey under specific site configurations.
CVE-2026-8337MEDIUM31 jul 2026
Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys when sites are running concurrent public surveys and private surveys
33RISCO
abrir
GitHub PoC1
This is N-day patch we releasing by testing our model capabilities
CVE-2026-16723CRITICAL31 jul 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISCO
abrir
GitHub PoC
Unauthenticated Address Book Modification on Sharp MX/BP Multifunction Printers
CVE-2026-63563MEDIUM31 jul 2026
Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication
33RISCO
abrir
GitHub PoC2
CVE-2026-66066 + File Read, RCE, Scanner, Lab
CVE-2026-66066CRITICAL31 jul 2026
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RISCO
abrir
GitHub PoC
CVE-2026-8347 is an Insecure Direct Object Reference (IDOR) combined with a wrong authorization level vulnerability in Concrete CMS versions 9.5.0 and earlier. The flaw exists in the Express association Reorder dialog, allowing a user with only view permissions on an Express entry to modify the ordering of associations for another entity.
CVE-2026-8347LOW31 jul 2026
Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in Express association Reorder dialog
28RISCO
abrir
GitHub PoC
VampSecure Labs: FortiOS CVE scanner (CVE-2018-13379, CVE-2022-40684, CVE-2023-27997, CVE-2024-21762)
CVE-2022-40684CRITICALsob ataqueransomware31 jul 2026
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir
GitHub PoC1
Gitea diffpatch RCE
CVE-2026-60004CRITICAL30 jul 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISCO
abrir
GitHub PoC
Security Advisory: Unauthenticated Stored Cross-Site Scripting Leading To Administrator Account Takeover (openclaw-dashboard)
CVE-2026-66418CRITICAL30 jul 2026
OpenClaw Dashboard v3.0.0 Stored XSS via Failed Login Username Field
48RISCO
abrir
GitHub PoC2
Security research tool for FortiWeb CVE-2025-64446 vulnerability. Automated exploitation framework with advanced logging, real-time metrics, proxy debugging, and professional reporting. Includes retry logic, multi-threading, and configurable settings. For authorized security testing only. CVSS 9.8 Critical.
CVE-2025-64446CRITICALsob ataque30 jul 2026
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISCO
abrir
GitHub PoC
CVE-2026-59726 - Draft or Todo
CVE-2026-59726CRITICAL30 jul 2026
Ruflo: Unauthenticated RCE in MCP bridge default docker-compose deployment
48RISCO
abrir
GitHub PoC1
CVE-2026-10702
CVE-2026-10702MEDIUM30 jul 2026
JIT miscompilation in the JavaScript Engine: JIT component
33RISCO
abrir
GitHub PoC
Security Advisory: Stored Cross-Site Scripting Via Agent Messages Leading To Session Token Theft (openclaw-dashboard)
CVE-2026-66421HIGH30 jul 2026
OpenClaw Dashboard Stored XSS via lastMessage Session Field
41RISCO
abrir
GitHub PoC
shootcannon/CVE-2026-61511
CVE-2026-61511CRITICAL30 jul 2026
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
85RISCO
abrir
GitHub PoC1
CVE-2026-60004
CVE-2026-60004CRITICAL30 jul 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISCO
abrir
GitHub PoC2
A critical vulnerability affecting Fastjson versions 1.2.68 – 1.2.83.
CVE-2026-16723CRITICAL30 jul 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISCO
abrir
GitHub PoC1
JetBrains TeamCity On-Premises CVE-2026-63077 Emergency Hardening & Patch Runbook Package
CVE-2026-63077CRITICALsob ataque30 jul 2026
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
100RISCO
abrir
GitHub PoC
nawalacheker1/CVE-2026-46331
CVE-2026-46331HIGH30 jul 2026
net/sched: fix pedit partial COW leading to page cache corruption
41RISCO
abrir
GitHub PoC
DJ-Classifieds Joomla Component Unauthenticated File Upload RCE. 3-string filter bypass via PHP short tags. CVSS 10.0 | CWE-434 | com_djclassifieds < 3.11.2
CVE-2026-61424CRITICAL30 jul 2026
Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2
48RISCO
abrir
GitHub PoC
Demonstrate the unauthenticated remote code execution vulnerability in the RSFiles! Joomla component through an arbitrary file upload.
CVE-2026-57827CRITICAL30 jul 2026
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12
63RISCO
abrir
GitHub PoC
CVE-2026-63030 Exploit | by gr1tx
CVE-2026-63030CRITICALsob ataque30 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC2
Nowafen/CVE-2026-16723
CVE-2026-16723CRITICAL30 jul 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISCO
abrir
GitHub PoC1
Fastjson RCE
CVE-2026-16723CRITICAL30 jul 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISCO
abrir
GitHub PoC26
rails/rails-forensics-CVE-2026-66066
CVE-2026-66066CRITICAL30 jul 2026
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RISCO
abrir
GitHub PoC
Hands-on exploit lab for CVE-2024-28000 — unauthenticated privilege escalation in LiteSpeed Cache (WordPress plugin, <=6.3.0.1). Spins up a vulnerable environment with Docker and includes a Go-based brute-forcer that cracks the weak mt_rand hash to create an administrator account.
CVE-2024-28000CRITICAL30 jul 2026
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISCO
abrir
GitHub PoC
HeltonPojo/CVE-2025-32432
CVE-2025-32432CRITICALsob ataque30 jul 2026
Craft CMS Allows Remote Code Execution
100RISCO
abrir
GitHub PoC
KunalKhandelwal-dev/cve-2021-41773-lab
CVE-2021-41773HIGHsob ataqueransomware30 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
Aimy Captcha-Less Form Guard Joomla Component PHP Object Injection RCE. clfgd XOR keystream recovery + unserialize(). CVSS 10.0 | CWE-502 | aimy_captcha-less_form_guard < 20.1
CVE-2026-65883CRITICAL30 jul 2026
Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0
48RISCO
abrir
GitHub PoC
Reproducible SOC lab for CVE-2024-4577 detection and response
CVE-2024-4577CRITICALsob ataqueransomware29 jul 2026
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
CamilleGR/CVE-2026-73292
CVE-2026-73292HIGH29 jul 2026
Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation
41RISCO
abrir
anteriorpágina 24 / 500próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.