Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.526exploits catalogados
36.593CVEs com exploração pública
24.695testados em laboratório
14.991 exploits
GitHub PoC
CVE-2026-15410 - More: https://github.com/HORKimhab/poc-cve-collection
CVE-2026-15410HIGHsob ataqueransomware15 jul 2026
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the S
76RISCO
abrir
GitHub PoC2
Raimu0x19/CVE-2026-13001
CVE-2026-13001CRITICAL15 jul 2026
Podlove Podcast Publisher <= 4.5.1 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter
63RISCO
abrir
GitHub PoC4
Pix for WooCommerce Unauthenticated File Upload via certificate_crt_path Parameter | CVSS 9.8
CVE-2026-3891CRITICAL15 jul 2026
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RISCO
abrir
GitHub PoC1
罗技云掌机 · GhostLock CVE-2026-43499 root 尝试
CVE-2026-43499HIGH15 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC1
ctn-Qvo/CVE-2026-43499-so-build
CVE-2026-43499HIGH15 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
WhatsWrongAndWhy/CVE-2016-8655
CVE-2016-865515 jul 2026
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cau
43RISCO
abrir
GitHub PoC
Kanak-CypherX/cve-2024-4577-lab
CVE-2024-4577CRITICALsob ataqueransomware15 jul 2026
Argument Injection in PHP-CGI
100RISCO
abrir
GitHub PoC3
CvE-2026-43499偏移量计算
CVE-2026-43499HIGH15 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-46587: Apache Camel camel-couchbase CCB_* header injection enabling document disclosure, tampering, and TTL-forced data destruction (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-46587HIGH15 jul 2026
Apache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
41RISCO
abrir
GitHub PoC
My portfolio showcasing vulnerability research (CVE-2026-11989, CVE-2026-11395) and automated threat orchestration engineering (Lucius Engine, TalonVigil).
CVE-2026-11989MEDIUM15 jul 2026
Bit integrations <= 2.8.7 - Unauthenticated Server-Side Request Forgery via Form Field Upload Mapping
33RISCO
abrir
GitHub PoC
WhatsWrongAndWhy/CVE-2016-9793
CVE-2016-979315 jul 2026
The sock_setsockopt function in net/core/sock.c in the Linux kernel before 4.8.14 mishandles negative values of sk_sndbu
23RISCO
abrir
GitHub PoC
NeseOS-Corp/CVE-2026-50657
CVE-2026-50657MEDIUM15 jul 2026
Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability
33RISCO
abrir
GitHub PoC
CVE-2025-60357- NoSQL(MongoDB) Injection POC
CVE-2025-60357HIGH15 jul 2026
AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability via the eventlog/agentEv
41RISCO
abrir
GitHub PoC29
PoC for CVE-2026-58635: Windows Narrator Braille Local Privilege Escalation
CVE-2026-58635HIGH15 jul 2026
Windows Narrator Braille Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC
arpit-bansal15/cve-2026-48282-pentest-lab
CVE-2026-48282CRITICAL15 jul 2026
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
75RISCO
abrir
GitHub PoC
Panduan mitigasi Januscape (CVE-2026-53359) AlmaLinux 9.5 production-safe + scripts
CVE-2026-53359HIGH15 jul 2026
KVM: x86: Fix shadow paging use-after-free due to unexpected role
41RISCO
abrir
GitHub PoC
Blog on CVE-2026-59827, Unsafe H2 query ouput deserialization
CVE-2026-59827CRITICAL15 jul 2026
Metabase: Unsafe Deserialization of H2 Query Results
48RISCO
abrir
GitHub PoC2
CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie deserialization to write webshell via Joomla FormattedtextLogger gadget chain. Includes interactive shell, path discovery, and cleanup. For authorized security testing only.
CVE-2026-48909CRITICAL15 jul 2026
Joomla Extension - joomshaper.com - PHP Object injection in SP LMS extension for Joomla < 4.1.4
63RISCO
abrir
GitHub PoC
FzRsLLaSheR/CVE-2026-14960-CVE-2026-14961
CVE-2026-14960CRITICAL15 jul 2026
CVE-2026-14960
48RISCO
abrir
GitHub PoC
A 16-year-old bug in the Linux kernel lets a rented VM break out and attack the host it runs on. Intel and AMD alike. Januscape is a use-after-free vulnerability in the KVM code that has been sitting there since 2010.
CVE-2026-53359HIGH15 jul 2026
KVM: x86: Fix shadow paging use-after-free due to unexpected role
41RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-46590: Apache Camel camel-pqc key-lifecycle unsafe deserialization (FileBasedKeyLifecycleManager legacy .key migration via ObjectInputStream), incomplete remediation of CVE-2026-40048 (fixed in 4.18.3/4.21.0)
CVE-2026-46590HIGH15 jul 2026
Apache Camel: Camel-PQC: The HashiCorp Vault and AWS Secrets Manager key-lifecycle managers deserialize persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter (incomplete remediation of CVE-2026-40048)
41RISCO
abrir
GitHub PoC
Technical analysis and safety-conscious research harness for CVE-2019-6447 in ES File Explorer for Android
CVE-2019-644715 jul 2026
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISCO
abrir
GitHub PoC
A containerized enterprise-style lab for researching and defending against CVE-2026-27483.
CVE-2026-27483HIGH15 jul 2026
MindsDB has Path Traversal in /api/files Leading to Remote Code Execution
61RISCO
abrir
GitHub PoC1
Samsung libimagecodec.quram.so OOB Write PoC
CVE-2026-21045HIGH15 jul 2026
Out-of-bounds write in parsing TIFF format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote
41RISCO
abrir
GitHub PoC10
CvE-2026-43499偏移量计算
CVE-2026-43499HIGH15 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
The GREENDARK hospital infrastructure was configured by Dr. Gusto Rogue prior to his termination. No further details are provided.
CVE-2021-41773HIGHsob ataqueransomware15 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
lamaper/CVE-2026-52199
CVE-2026-52199CRITICAL15 jul 2026
An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/
48RISCO
abrir
GitHub PoC
exploit for CVE-2022-42889
CVE-2022-4288915 jul 2026
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC
JohannesLks/CVE-2026-50338
CVE-2026-50338HIGH14 jul 2026
Azure Spring Apps Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC
Log4j Vulnerability homelab
CVE-2021-44228CRITICALsob ataqueransomware14 jul 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
anteriorpágina 39 / 500próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.