Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.386exploits catalogados
36.533CVEs com exploração pública
24.695testados em laboratório
14.991 exploits
GitHub PoC4
Fastjson 1.2.83 RCE 靶场环境 (CVE-2026-16723)
CVE-2026-16723CRITICAL28 jul 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISCO
abrir
GitHub PoC6
Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known CVE. Agentic loop-hunt: 25 generators, 22 judges, 9 live validators on Docker. Evidence trail + one-go checker included.
CVE-2020-7961CRITICALsob ataque28 jul 2026
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISCO
abrir
GitHub PoC
Simulated a real-world attack (CVE-2011-2523) against a vulnerable host, then cross-checked detection coverage against an existing Wazuh/Suricata/Zeek SOC — uncovering and fixing 5 real monitoring pipeline bugs along the way.
CVE-2011-252328 jul 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
GitHub PoC
IoT Security research conducted during my internship at IIIT Allahabad, leading to CVE-2026-65893, CVE-2026-65894, and the CERT-In Vulnerability Note CIVN-2026-0380.
CVE-2026-65893HIGH28 jul 2026
Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera
41RISCO
abrir
GitHub PoC
CyberVinner/CP-PLUS-EZ-P21-CVE-2026-65893-65894
CVE-2026-65893HIGH28 jul 2026
Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera
41RISCO
abrir
GitHub PoC1
A PoC for CVE-2026-64725
CVE-2026-64725HIGH28 jul 2026
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS
41RISCO
abrir
GitHub PoC1
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
CVE-2026-54121HIGH28 jul 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC1
CVE-2026-8206: Kirki Customizer Framework - Unauthenticated Account Takeover (CVSS 9.8)
CVE-2026-8206CRITICAL28 jul 2026
Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'
48RISCO
abrir
GitHub PoC
0xdak/CVE-2025-71389_exploit
CVE-2025-71389CRITICAL28 jul 2026
Cal.com before 5.9.9 Remote Code Execution via RSC
48RISCO
abrir
GitHub PoC
CVE-2026-61511 - Draft or Todo
CVE-2026-61511CRITICAL28 jul 2026
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
85RISCO
abrir
GitHub PoC
Clickbait. The CVE is AI slop.
CVE-2026-5130228 jul 2026
23RISCO
abrir
GitHub PoC
Proof of Concept for CVE-2026-65761 - EasyStore Pro Unauthenticated SQL Injection via `filter_sortby`
CVE-2026-65761CRITICAL28 jul 2026
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1
63RISCO
abrir
GitHub PoC1
IBM Langflow OSS 1.0.0 through 1.10.0 contains a remote code execution [RCE]
CVE-2026-9198CRITICALsob ataque28 jul 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISCO
abrir
GitHub PoC
Isolated regression and security-control lab for CVE-2026-59891 in @sigstore/oci
CVE-2026-59891CRITICAL28 jul 2026
Credential confusion in  @sigstore/oci  can leak registry credentials to an attacker-controlled registry
48RISCO
abrir
GitHub PoC3
cve-2026-61511
CVE-2026-61511CRITICAL28 jul 2026
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
85RISCO
abrir
GitHub PoC
Microsoft SharePoint CVE-2026-50522
CVE-2026-50522CRITICALsob ataque28 jul 2026
Microsoft SharePoint Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC35
nginx heap buffer overflow PoC — CVE-2026-42533 pre-auth RCE via two-pass capture clobbering. Crash confirmed on Ubuntu 24.04.
CVE-2026-42533CRITICAL27 jul 2026
NGINX Map directive and Regex matching vulnerability
48RISCO
abrir
GitHub PoC1
soralis0912/CVE-2026-43499-pmg110-root
CVE-2026-43499HIGH27 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
yuimamur/CVE-2024-4367-hands-on-01
CVE-2024-4367MEDIUM27 jul 2026
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir
GitHub PoC
Phucc29/CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware27 jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Dungsocool/CVE-2026-60137_CVE-2026-63030
CVE-2026-60137MEDIUMsob ataque27 jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISCO
abrir
GitHub PoC
CVE-2026-63030 + CVE-2026-60137+poc
CVE-2026-63030CRITICALsob ataque27 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC
jelasin/CVE-2026-42533
CVE-2026-42533CRITICAL27 jul 2026
NGINX Map directive and Regex matching vulnerability
48RISCO
abrir
GitHub PoC
PoC and analysis of CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware27 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
A Python-based static patch analysis tool for studying the root cause and remediation of CVE-2021-41773 (Apache HTTP Server Path Traversal) by comparing the vulnerable Apache HTTP Server 2.4.49 source code with the patched 2.4.51 implementation.
CVE-2021-41773HIGHsob ataqueransomware27 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC1
CVE-2026-65008
CVE-2026-65008CRITICAL27 jul 2026
Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData
48RISCO
abrir
GitHub PoC
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVE-2026-50522CRITICALsob ataque27 jul 2026
Microsoft SharePoint Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC10
CVE-2026-54121 (Certighost) AD CS DC-impersonation PoC. Patched SAN handling + MAQ-safe account reuse.
CVE-2026-54121HIGH27 jul 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC
CVE-2026-57973 is a medium-severity (CVSS 6.3) TOCTOU race condition flaw in Windows Subsystem for Linux (WSL2). It allows a local, low-privileged attacker to bypass security boundaries and perform unauthorized kernel-level tampering on the host machine without user interaction.
CVE-2026-57973MEDIUM27 jul 2026
Windows Subsystem for Linux (WSL2) Kernel Tampering Vulnerability
13RISCO
abrir
GitHub PoC1
CVE-2026-15013
CVE-2026-15013CRITICAL27 jul 2026
SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm Confusion
48RISCO
abrir
anteriorpágina 26 / 500próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.