Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.386exploits catalogados
36.533CVEs com exploração pública
24.695testados em laboratório
14.991 exploits
GitHub PoC5
CVE-2026-61511 – vBulletin Pre-Auth RCE (CVSS 9.8). Vuln 5.x/6.x (unpatched). Multi-exploit via Endpoint Pool, AJAX, PHPFuck WAF bypass. Full toolkit: reverse shell, proxy, persistence, webshell, database operations, firewall control, log management, mass scanning. 2 versions: multi-exploit & safe-check. Python 3.8+ Use Ethically, Stay Legal. 🔒
CVE-2026-61511CRITICAL29 jul 2026
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
85RISCO
abrir
GitHub PoC
webshellseo8/CVE-2026-50522-Proof-of-Concept
CVE-2026-50522CRITICALsob ataque29 jul 2026
Microsoft SharePoint Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
Pravin761/CVE-2026-54107
CVE-2026-54107HIGH29 jul 2026
Windows Win32k Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC5
CVE-2026-49176 WalletService LPE — standalone PoC + Cobalt Strike BOF (SYSTEM command on interactive session)
CVE-2026-49176HIGH29 jul 2026
Windows WalletService Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC
webshellseo8/CVE-2026-57811-Proof-of-Concept
CVE-2026-57811CRITICAL29 jul 2026
WordPress Realtyna Organic IDX plugin plugin <= 5.2.0 - Remote Code Execution (RCE) vulnerability
28RISCO
abrir
GitHub PoC
Public technical advisory and reproduction evidence for CVE-2026-52134 affecting GOOSE replay handling in libiec61850 v1.6.
CVE-2026-52134CRITICAL29 jul 2026
An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass au
48RISCO
abrir
GitHub PoC1
CVE-2026-43499 exploit adapter for MT6985 MediaTek Dimensity 9300 (vivo PD2241)
CVE-2026-43499HIGH29 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC5
CVE-2026-58025 — MediaWiki Deserialization RCE via Log Entry Import. LogEntryBase::extractParams() unserialize() user-controlled log_params. CVSS 9.8 | CWE-502 | MediaWiki < 1.43.9, < 1.44.6, < 1.45.4, < 1.46.0
CVE-2026-58025MEDIUM29 jul 2026
Remote Code Execution via Unsafe Deserialization in LogItem Import
33RISCO
abrir
GitHub PoC9
CVE-2026-43813: CloudAttestation enforceEnvironment bypass
CVE-2026-43813HIGH29 jul 2026
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 and iPadOS 26.6, macO
41RISCO
abrir
GitHub PoC23
PoC for CVE-2026-66066 in Ruby on Rails
CVE-2026-66066CRITICAL29 jul 2026
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RISCO
abrir
GitHub PoC2
CVE-2026-45746, CVE-2026-45750, CVE-2026-53547 — three critical vulnerabilities in Termix: cross-tenant session hijacking, OS command injection, and account takeover
CVE-2026-45746CRITICAL29 jul 2026
Termix Vulnerable to Arbitrary Command Execution via Session Hijacking
48RISCO
abrir
GitHub PoC
manfredgabriel/cve-2021-41773-lab
CVE-2021-41773HIGHsob ataqueransomware29 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
webshellseo8/CVE-2026-61511-POC
CVE-2026-61511CRITICAL29 jul 2026
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
85RISCO
abrir
GitHub PoC1
Gitea Docker Image Authentication Bypass
CVE-2026-20896CRITICAL29 jul 2026
Gitea Docker image trusts spoofable reverse-proxy headers by default
63RISCO
abrir
GitHub PoC
Tracking OVSwrap (CVE-2026-64531), the Open vSwitch datapath netlink overflow
CVE-2026-64531HIGH29 jul 2026
net: openvswitch: reject oversized nested action attrs
41RISCO
abrir
GitHub PoC
Agent skill that audits a Rails codebase for CVE-2026-66066 (KindaRails2Shell) — Active Storage + libvips arbitrary file read / RCE, checking Rails and libvips versions and block-untrusted mitigations
CVE-2026-66066CRITICAL29 jul 2026
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RISCO
abrir
GitHub PoC
CVE-2026-2586 — Eclipse GlassFish EL injection to RCE
CVE-2026-2586CRITICAL29 jul 2026
An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user
48RISCO
abrir
GitHub PoC
Reproducible SOC lab for CVE-2024-4577 detection and response
CVE-2024-4577CRITICALsob ataqueransomware29 jul 2026
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC
vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code
CVE-2026-61511CRITICAL29 jul 2026
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
85RISCO
abrir
GitHub PoC4
CVE-2026-60004
CVE-2026-60004CRITICAL29 jul 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISCO
abrir
GitHub PoC15
CVE-2026-57827 — RSFiles! Joomla Component Unauthenticated File Upload RCE. Split-controller upload bypass. CVSS 9.8 | CWE-434 | com_rsfiles < 1.17.12
CVE-2026-57827CRITICAL29 jul 2026
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12
63RISCO
abrir
GitHub PoC
Simulated a real-world attack (CVE-2011-2523) against a vulnerable host, then cross-checked detection coverage against an existing Wazuh/Suricata/Zeek SOC — uncovering and fixing 5 real monitoring pipeline bugs along the way.
CVE-2011-252328 jul 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
GitHub PoC4
KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499
CVE-2026-43499HIGH28 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
CyberVinner/CP-PLUS-EZ-P21-CVE-2026-65893-65894
CVE-2026-65893HIGH28 jul 2026
Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera
41RISCO
abrir
GitHub PoC
IoT Security research conducted during my internship at IIIT Allahabad, leading to CVE-2026-65893, CVE-2026-65894, and the CERT-In Vulnerability Note CIVN-2026-0380.
CVE-2026-65893HIGH28 jul 2026
Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera
41RISCO
abrir
GitHub PoC4
Fastjson 1.2.83 RCE 靶场环境 (CVE-2026-16723)
CVE-2026-16723CRITICAL28 jul 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISCO
abrir
GitHub PoC11
A proof-of-concept script to exploit CVE-2026-16232, an authentication bypass via the SmartConsole login process using an application token.
CVE-2026-16232CRITICALsob ataque28 jul 2026
Authentication Bypass in the SmartConsole Login Process Using an Application Token
100RISCO
abrir
GitHub PoC
CVE-2026-61511 - Draft or Todo
CVE-2026-61511CRITICAL28 jul 2026
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
85RISCO
abrir
GitHub PoC
Perl Image::WebP library. Unofficial. CVE-2026-58586
CVE-2026-58586CRITICAL28 jul 2026
Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp
28RISCO
abrir
GitHub PoC3
Exploit code for CVE-2026-55040, it can create auth header for any validate account.
CVE-2026-55040CRITICALsob ataque28 jul 2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISCO
abrir
anteriorpágina 25 / 500próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.