Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
79.900 exploits
GitHub PoC
VampSecure Labs: FortiOS CVE scanner (CVE-2018-13379, CVE-2022-40684, CVE-2023-27997, CVE-2024-21762)
CVE-2018-13379CRITICALsob ataqueransomware31 jul 2026
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISCO
abrir
GitHub PoC
VampSecure Labs: FortiOS CVE scanner (CVE-2018-13379, CVE-2022-40684, CVE-2023-27997, CVE-2024-21762)
CVE-2022-40684CRITICALsob ataqueransomware31 jul 2026
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISCO
abrir
VulnCheck XDB
info-leak
CVE-2024-23897CRITICALsob ataqueransomware31 jul 2026
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-20896CRITICAL31 jul 2026
Gitea Docker image trusts spoofable reverse-proxy headers by default
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-16723CRITICAL31 jul 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-16723CRITICAL31 jul 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISCO
abrir
GitHub PoC
HeltonPojo/CVE-2025-32432
CVE-2025-32432CRITICALsob ataque30 jul 2026
Craft CMS Allows Remote Code Execution
100RISCO
abrir
GitHub PoC
Hands-on exploit lab for CVE-2024-28000 — unauthenticated privilege escalation in LiteSpeed Cache (WordPress plugin, <=6.3.0.1). Spins up a vulnerable environment with Docker and includes a Go-based brute-forcer that cracks the weak mt_rand hash to create an administrator account.
CVE-2024-28000CRITICAL30 jul 2026
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISCO
abrir
GitHub PoC2
Security research tool for FortiWeb CVE-2025-64446 vulnerability. Automated exploitation framework with advanced logging, real-time metrics, proxy debugging, and professional reporting. Includes retry logic, multi-threading, and configurable settings. For authorized security testing only. CVSS 9.8 Critical.
CVE-2025-64446CRITICALsob ataque30 jul 2026
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-16723CRITICAL30 jul 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISCO
abrir
GitHub PoC
Security Advisory: Stored Cross-Site Scripting Via Agent Messages Leading To Session Token Theft (openclaw-dashboard)
CVE-2026-66421HIGH30 jul 2026
OpenClaw Dashboard Stored XSS via lastMessage Session Field
41RISCO
abrir
GitHub PoC
shootcannon/CVE-2026-61511
CVE-2026-61511CRITICAL30 jul 2026
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
85RISCO
abrir
GitHub PoC2
A critical vulnerability affecting Fastjson versions 1.2.68 – 1.2.83.
CVE-2026-16723CRITICAL30 jul 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-60004CRITICALsob ataque30 jul 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
100RISCO
abrir
GitHub PoC
nawalacheker1/CVE-2026-46331
CVE-2026-46331HIGH30 jul 2026
net/sched: fix pedit partial COW leading to page cache corruption
41RISCO
abrir
GitHub PoC
KunalKhandelwal-dev/cve-2021-41773-lab
CVE-2021-41773HIGHsob ataqueransomware30 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
Aimy Captcha-Less Form Guard Joomla Component PHP Object Injection RCE. clfgd XOR keystream recovery + unserialize(). CVSS 10.0 | CWE-502 | aimy_captcha-less_form_guard < 20.1
CVE-2026-65883CRITICAL30 jul 2026
Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0
48RISCO
abrir
GitHub PoC
CVE-2026-59726 - Draft or Todo
CVE-2026-59726CRITICAL30 jul 2026
Ruflo: Unauthenticated RCE in MCP bridge default docker-compose deployment
48RISCO
abrir
GitHub PoC26
rails/rails-forensics-CVE-2026-66066
CVE-2026-66066CRITICAL30 jul 2026
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RISCO
abrir
GitHub PoC2
Nowafen/CVE-2026-16723
CVE-2026-16723CRITICAL30 jul 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-28000CRITICAL30 jul 2026
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISCO
abrir
GitHub PoC1
CVE-2026-10702
CVE-2026-10702MEDIUM30 jul 2026
JIT miscompilation in the JavaScript Engine: JIT component
33RISCO
abrir
GitHub PoC1
Fastjson RCE
CVE-2026-16723CRITICAL30 jul 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISCO
abrir
GitHub PoC1
Security Advisory: Unauthenticated Stored Cross-Site Scripting Leading To Administrator Account Takeover (openclaw-dashboard)
CVE-2026-66418CRITICAL30 jul 2026
OpenClaw Dashboard v3.0.0 Stored XSS via Failed Login Username Field
48RISCO
abrir
GitHub PoC
JetBrains TeamCity On-Premises CVE-2026-63077 Emergency Hardening & Patch Runbook Package
CVE-2026-63077CRITICALsob ataque30 jul 2026
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
100RISCO
abrir
GitHub PoC1
Gitea diffpatch RCE
CVE-2026-60004CRITICALsob ataque30 jul 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
100RISCO
abrir
GitHub PoC
DJ-Classifieds Joomla Component Unauthenticated File Upload RCE. 3-string filter bypass via PHP short tags. CVSS 10.0 | CWE-434 | com_djclassifieds < 3.11.2
CVE-2026-61424CRITICAL30 jul 2026
Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2
48RISCO
abrir
GitHub PoC3
CVE-2026-60004
CVE-2026-60004CRITICALsob ataque30 jul 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-64446CRITICALsob ataque30 jul 2026
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISCO
abrir
GitHub PoC
Demonstrate the unauthenticated remote code execution vulnerability in the RSFiles! Joomla component through an arbitrary file upload.
CVE-2026-57827CRITICAL30 jul 2026
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12
63RISCO
abrir
anteriorpágina 42 / 2.664próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.