Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.386exploits catalogados
36.533CVEs com exploração pública
24.695testados em laboratório
14.991 exploits
GitHub PoC5
soralis0912/CVE-2026-43499-aristotle-apk
CVE-2026-43499HIGH23 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC28
YellowKey free tool for the CVE-2026-45585 BitLocker bypass vulnerability on Windows 10/11. Covered on Tom's Hardware: extract recovery keys, apply remediation, test bypass mitigation and manage BitLocker encryption state. Download YellowKey
CVE-2026-45585MEDIUM23 jul 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RISCO
abrir
GitHub PoC1
CVE Reproduction: cve-2026-41940-cpanel_authbypass_reproduction
CVE-2026-41940CRITICALsob ataqueransomware23 jul 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC
theeomega/CVE-2025-32432-POC
CVE-2025-32432CRITICALsob ataque23 jul 2026
Craft CMS Allows Remote Code Execution
100RISCO
abrir
GitHub PoC
CVE Reproduction: cve-2026-63030_60137-wordpress_rce_reproduction
CVE-2026-63030CRITICALsob ataque23 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC
Security analysis and report of CVE-2024-6387 OpenSSH vulnerability, including vulnerability details, CVSS evaluation, and mitigation recommendations.
CVE-2024-6387HIGH23 jul 2026
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir
GitHub PoC
GitHub Actions workflow sandbox for CVE-2026-45132 reproduction
CVE-2026-45132CRITICAL23 jul 2026
CloudPirates Open Source Helm Charts: GitHub Actions workflow leaks PAT and SSH signing key via unsafe credential handling
48RISCO
abrir
GitHub PoC
Tproot es una máquina de nivel Muy Fácil de DockerLabs centrada en la explotación manual del servicio vsftpd 2.3.4 (CVE-2011-2523).
CVE-2011-252323 jul 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
GitHub PoC
0xdak/CVE-2026-63766_exploit
CVE-2026-63766CRITICAL23 jul 2026
GPT-SoVITS 20250606v2pro OS Command Injection via webui.py
48RISCO
abrir
GitHub PoC
ghostpels/CVE-2026-13001
CVE-2026-13001CRITICAL23 jul 2026
Podlove Podcast Publisher <= 4.5.1 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter
63RISCO
abrir
GitHub PoC1
0xdak/CVE-2026-56121_exploit
CVE-2026-56121CRITICAL23 jul 2026
Feast < 0.63.0 Unauthenticated RCE via ApplyFeatureView gRPC Deserialization
48RISCO
abrir
GitHub PoC
GitHub Actions workflow sandbox (CVE-2026-48546 reproduction)
CVE-2026-48546HIGH23 jul 2026
KanaDojo < 0.1.18 Sandbox Escape RCE via messages.cjs
41RISCO
abrir
GitHub PoC1
CVE-2021-41773 Apache
CVE-2021-41773HIGHsob ataqueransomware23 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC4
soralis0912/CVE-2026-43499-aristotle
CVE-2026-43499HIGH23 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC5
CVE-2026-43499 exploit configuration for realme RMX3888 (Android 16) - 20 verified kernel offsets
CVE-2026-43499HIGH23 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
Initialized & connected PostgreSQL to Metasploit. Reconnoitered 10.1.16.0/24 with Nmap and imported results. Enumerated hosts/services using SYN, SMB & LDAP scanners. Exploited DC10 via ZeroLogon (CVE-2020-1472), dumped AD NTLM hashes with Impacket, performed Pass-the-Hash, then gained a Meterpreter reverse shell.
CVE-2020-1472MEDIUMsob ataqueransomware23 jul 2026
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC
CVE Reproduction: cve-2025-55182-react2shell_reproduction
CVE-2025-55182CRITICALsob ataqueransomware23 jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
CVE Reproduction: cve-2025-5777-citrixbleed2_reproduction
CVE-2025-5777CRITICALsob ataqueransomware23 jul 2026
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
GitHub PoC
Legacy HPE iMC vuln
CVE-2019-539223 jul 2026
A disclosure of information vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than ve
23RISCO
abrir
GitHub PoC
CVE-2026-41940 & CVE-2026-41948 — cPanel & WHM Auth Bypass
CVE-2026-41940CRITICALsob ataqueransomware23 jul 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC
Proof-of-concept and offensive security research analyzing CVE-2026-23744 (MCPJam Inspector Unauthenticated RCE, Patched in v1.4.3+).
CVE-2026-23744CRITICAL23 jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
GitHub PoC325
Certighost POC
CVE-2026-54121HIGH23 jul 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC1
Flowise Windows RCE exploit for CVE-2026-58057. Bypasses environment variable validation via case-sensitive flaw. Uses node_options to inject arbitrary code through MCP stdio. Supports reverse shell, persistence, file upload, credential dumping. For authorized security testing only.
CVE-2026-58057LOW23 jul 2026
Flowise - Custom MCP Environment Variable Denylist Bypass via Case Sensitivity
28RISCO
abrir
GitHub PoC
FernandoCassioDev/CVE-2015-1328
CVE-2015-132823 jul 2026
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISCO
abrir
GitHub PoC
Metabase CVE-2026-59827 Vulnerability Scanner
CVE-2026-59827CRITICAL23 jul 2026
Metabase: Unsafe Deserialization of H2 Query Results
48RISCO
abrir
GitHub PoC
finding by nvth
CVE-2026-59880HIGH23 jul 2026
Immutable.js: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
21RISCO
abrir
GitHub PoC
CVE-2026-42533 Nginx
CVE-2026-42533CRITICAL23 jul 2026
NGINX Map directive and Regex matching vulnerability
48RISCO
abrir
GitHub PoC12
DavidCarliez/CVE-2026-66804-CrossDevice-LPE
CVE-2026-66804HIGH23 jul 2026
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC
CVE Reproduction: cve-2026-0770-langflow_rce_reproduction
CVE-2026-0770CRITICALsob ataque23 jul 2026
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
Dynamo2k1/CVE-2026-33017
CVE-2026-33017CRITICALsob ataque23 jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir
anteriorpágina 30 / 500próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.