Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.386exploits catalogados
36.533CVEs com exploração pública
24.695testados em laboratório
14.991 exploits
GitHub PoC
Slidev presentation for Certighost (CVE-2026-54121), with Mermaid diagrams and exported assets.
CVE-2026-54121HIGH26 jul 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC6
A C-based Linux security utility for detecting, safely verifying (Proof of Concept), and mitigating CVE-2026-64600 (RefluXFS). It provides kernel vulnerability assessment, XFS reflink detection, a safe race-condition PoC, and layered mitigation using SystemTap and XFS hardening.
CVE-2026-64600HIGH26 jul 2026
xfs: resample the data fork mapping after cycling ILOCK
41RISCO
abrir
GitHub PoC23
基于内核漏洞CVE-2026-43499的本地提权适配,集成嵌入式 KernelSU.CVE-2026-43499+KernelSU越狱模式
CVE-2026-43499HIGH26 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
Manage BitLocker encrypted drives on Windows 10 and 11. Extract recovery keys, check encryption status, and apply security mitigations for CVE-2026-45585.
CVE-2026-45585MEDIUM25 jul 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RISCO
abrir
GitHub PoC1
CypherHippie/CVE-2026-66804
CVE-2026-66804HIGH25 jul 2026
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC
CVE-2026-54121 - Draft
CVE-2026-54121HIGH25 jul 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC2
7-Zip XZ Decoder Heap Buffer Overflow - Full analysis, root cause, PoC, and RCE exploitation roadmap
CVE-2026-14266HIGH25 jul 2026
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability
41RISCO
abrir
GitHub PoC40
CVE-2026-50522 PoC
CVE-2026-50522CRITICALsob ataque25 jul 2026
Microsoft SharePoint Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC3
Technical analysis, root cause breakdown, and non-destructive detection methodology for CVE-2026-63030.
CVE-2026-63030CRITICALsob ataque25 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC
Security Advisory for CVE-2026-51564
CVE-2026-51564MEDIUM25 jul 2026
An issue in the redirect parameter in Milk admin <=0.9.8 allows remote attackers to redirect users to arbitrary external
33RISCO
abrir
GitHub PoC
CVE-2026-12960 - Improper Export of Android Application Components in the ASUS Router app (com.asus.aihome). PoC, exploit APK, video, and vendor report. Fixed in 1.0.0.9.74.
CVE-2026-12960MEDIUM25 jul 2026
An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application o
33RISCO
abrir
GitHub PoC
Security Advisory for CVE-2026-51565
CVE-2026-51565MEDIUM25 jul 2026
Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php in Milk admin <=0.9.8 allows remote attacker
33RISCO
abrir
GitHub PoC2
CVE-2026-54121
CVE-2026-54121HIGH25 jul 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC
CVE-2026-54900, CVE-2026-54902 - Draft
CVE-2026-54900MEDIUM25 jul 2026
Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling
33RISCO
abrir
GitHub PoC1
CVE-2026-16723
CVE-2026-16723CRITICAL25 jul 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISCO
abrir
GitHub PoC
CVE-2026-61946: Unauthenticated IDOR in Easy Appointments <= 3.12.27
CVE-2026-61946MEDIUM25 jul 2026
WordPress Easy Appointments plugin <= 3.12.27 - Insecure Direct Object References (IDOR) vulnerability
33RISCO
abrir
GitHub PoC
Auth Bypass in inetutils-telnetd
CVE-2026-24061CRITICALsob ataque25 jul 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC2
Technical analysis and advisory for CVE-2026-48908: Unauthenticated Arbitrary File Upload to RCE in JoomShaper SP Page Builder.
CVE-2026-48908CRITICAL25 jul 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
68RISCO
abrir
GitHub PoC27
👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework | Advanced toolkit with rogue DC/LDAP servers, certificate abuse, PKINIT hash extraction. Features: detect safe check, exploit full multi-threaded. 🛡️ CVSS 8.8 High - Use Ethically, Stay Legal. 🔒
CVE-2026-54121HIGH25 jul 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC
Technical analysis and Proof-of-Concept for CVE-2026-60206, a critical Oracle WebLogic Server SAML authentication bypass vulnerability.
CVE-2026-60206CRITICAL25 jul 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
48RISCO
abrir
GitHub PoC17
(CVE-2026-43499)内核漏洞利用程序,适用于未解锁 Bootloader 的一加15T.
CVE-2026-43499HIGH25 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC1
PoC for CVE-2026-65694 — Microweber CMS (<=2.0.20) unauthenticated path traversal → arbitrary file read (.env / secrets)
CVE-2026-65694HIGH25 jul 2026
Microweber CMS 2.0.20 Path Traversal via ServeStaticFileController
56RISCO
abrir
GitHub PoC5
CVE-2026-43499 per-boot root exploit — core logic (arm64 Android GKI 6.6)
CVE-2026-43499HIGH25 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
Manage BitLocker encrypted drives on Windows. Extract recovery keys, check encryption status, and apply security mitigations for CVE-2026-45585.
CVE-2026-45585MEDIUM25 jul 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RISCO
abrir
GitHub PoC
EasyStore Joomla Pre-Auth SQL Injection via filter_sortby Direction (CVE-2026-65761, CVSS 9.3)
CVE-2026-65761CRITICAL24 jul 2026
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1
63RISCO
abrir
GitHub PoC
manfredgabriel/cve-2021-43798-lab
CVE-2021-43798HIGHsob ataque24 jul 2026
Grafana path traversal
100RISCO
abrir
GitHub PoC
Security Advisory: Negative Chunk-Size Parsing Causes Memory Corruption in facil.io
CVE-2026-66731HIGH24 jul 2026
facil.io 0.7.5 - 0.7.6 HTTP/1.1 Chunked Transfer Encoding Parser Crash DoS
41RISCO
abrir
GitHub PoC
kxom9ks/CVE-2024-27198-TeamCity
CVE-2024-27198CRITICALsob ataqueransomware24 jul 2026
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir
GitHub PoC
Security Advisory: Camaleon CMS - Authenticated RCE via `select_eval` Custom Field
CVE-2026-66748HIGH24 jul 2026
Camaleon CMS 2.1.1 - 2.9.1 Authenticated RCE via select_eval Custom Field
41RISCO
abrir
GitHub PoC1
CVE-2026-41940
CVE-2026-41940CRITICALsob ataqueransomware24 jul 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
anteriorpágina 28 / 500próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.