Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.858exploits catalogados
36.825CVEs com exploração pública
24.695testados em laboratório
79.858 exploits
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL10 ago 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
Exploit-DB
Microsoft Edge 150.0.4078.48 - RCE
CVE-2026-58289CRITICALlocalmultiple10 ago 2026
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-63077CRITICALsob ataque10 ago 2026
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-63077CRITICALsob ataque10 ago 2026
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
100RISCO
abrir
GitHub PoC
Proof of Concept (PoC) WebSocket client for CVE-2026-39987 (Marimo Pre-Auth RCE), intended for authorized security testing.
CVE-2026-39987CRITICALsob ataque10 ago 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISCO
abrir
VulnCheck XDB
local
CVE-2024-30088HIGHsob ataqueransomware10 ago 2026
Windows Kernel Elevation of Privilege Vulnerability
83RISCO
abrir
GitHub PoC
my poc for CVE-2026-53787
CVE-2026-53787CRITICAL10 ago 2026
Amasty Order Attributes for Magento 2 < 4.0.0 Unauthenticated Arbitrary File Upload
63RISCO
abrir
GitHub PoC
The poc of CVE-2026-23744
CVE-2026-23744CRITICAL10 ago 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
GitHub PoC
CVE-2026-65891 PoC — Joomla Content Editor file rename vulnerability (auth required, fixed in JCE 2.20.2)
CVE-2026-65891MEDIUM10 ago 2026
Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.9.99.10
33RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALsob ataqueransomware10 ago 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALsob ataque10 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
Exploit-DB
OrkesConductor 3.30.2 - Unauthenticated Remote Code Execution
CVE-2026-58138CRITICALwebappsmultiple10 ago 2026
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
63RISCO
abrir
GitHub PoC1
CVE-2026-64747 AGXG14P count-bitmask OOB trigger probe (A15/iOS 26.5.2)
CVE-2026-64747HIGH10 ago 2026
A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iO
41RISCO
abrir
GitHub PoC1
CVE-2026-64824 — Home Assistant backup-restore symlink path traversal → root RCE. First working PoC, verified on real HA 2026.5.4 (sitecustomize.py overwrite). GHSA-cwh8-w64c-4j5h
CVE-2026-64824CRITICAL10 ago 2026
Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore
48RISCO
abrir
GitHub PoC1
Saku0512/CVE-2026-9086-poc
CVE-2026-9086HIGH10 ago 2026
Keycloak: keycloak: cross-site scripting (xss) via case-insensitive uri validation bypass
41RISCO
abrir
GitHub PoC
unpredictable21/CVE-2026-75430_PowerJob_worker_deployContainer_RCE
CVE-2026-75430CRITICAL10 ago 2026
PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without au
48RISCO
abrir
GitHub PoC5
Community-maintained fork of image-size with fixes for CVE-2025-71329 and CVE-2025-71330
CVE-2025-71329HIGH10 ago 2026
image-size 2.0.2 Denial of Service via Infinite Loop in JXL/HEIF Parser
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-21839HIGHsob ataque10 ago 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISCO
abrir
GitHub PoC1
IamDremig/CVE-2026-15598
CVE-2026-15598MEDIUM10 ago 2026
antv layout object.js setNestedValue prototype pollution
33RISCO
abrir
GitHub PoC
spring retry 1.3.x fix with niche toolkit for CVE-2026-41710
CVE-2026-41710MEDIUM10 ago 2026
Cache Exhaustion in Stateful Retries leads to Denial of Service
33RISCO
abrir
GitHub PoC
CVE-2026-34348 - Draft or TODO
CVE-2026-34348MEDIUM10 ago 2026
Windows Event Logging Service Information Disclosure Vulnerability
33RISCO
abrir
GitHub PoC
unpredictable21/CVE-2026-75429_PowerJob_friend_process_RCE
CVE-2026-7542910 ago 2026
PowerJob versions 4.x through 5.1.2 contain an unauthenticated remote code execution vulnerability in the /friend/proces
23RISCO
abrir
GitHub PoC
CVE-2026-20685 - Draft or TODO
CVE-2026-20685MEDIUM10 ago 2026
An attacker in a privileged network position may be able to leak sensitive information. A path handling issue was addres
33RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-39987CRITICALsob ataque10 ago 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISCO
abrir
Exploit-DB
Joomla 2.9.99.4 - Unauthenticated Remote Code Execution
CVE-2026-48907CRITICALsob ataquewebappsmultiple10 ago 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISCO
abrir
GitHub PoC2
CVE-2026-23744 is an unauthenticated command injection in MCPJam Inspector ≤1.4.2 via /api/mcp/connect. This POC exploits it by sending a crafted JSON payload to execute arbitrary commands, granting a reverse shell with PTY.
CVE-2026-23744CRITICAL10 ago 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
GitHub PoC25
CVE-2026-53361 AF_UNIX GC vs MSG_PEEK use-after-free container escape
CVE-2026-53361HIGH10 ago 2026
af_unix: Set gc_in_progress to true in unix_gc().
41RISCO
abrir
GitHub PoC
Authorized Kali–Metasploitable2 lab using Python and Nmap NSE to validate CVE-2011-2523 in vsFTPd 2.3.4.
CVE-2011-252310 ago 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
GitHub PoC
unpredictable21/halo-cors-csrf-CVE-2026-67921
CVE-2026-67921CRITICAL10 ago 2026
Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the CorsConfigurer.java and
48RISCO
abrir
GitHub PoC20
ThrottleStop.sys Arbitrary Physical Memory R/W
CVE-2025-7771HIGH10 ago 2026
Code Execution / Escalation of Privileges in ThrottleStop
41RISCO
abrir
anteriorpágina 28 / 2.662próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.