Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.596exploits catalogados
36.656CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.475Referência 23.212GitHub PoC 15.164VulnCheck XDB 8.883Nuclei 4.369Metasploit 3.493✓ só verificadosrecentespopularesrisco
14.991 exploits
GitHub PoC★ 6
Termux Privilege Escalation Tool & Root Manager - CVE-2026-43501
ipv6: rpl: reserve mac_len headroom when recompressed SRH grows
48RISCO
abrir ↗GitHub PoC
MW-HF/Drupal-CVE-2026-9082
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISCO
abrir ↗GitHub PoC
An unauthenticated SQL injection vulnerability exists in the Vendure Shop API. A user-controlled query string parameter is interpolated directly into a raw SQL expression without parameterization or validation, allowing an attacker to execute arbitrary SQL against the database.
@vendure/core has a SQL Injection vulnerability
43RISCO
abrir ↗GitHub PoC
jini135wii/CVE-2019-15107
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir ↗GitHub PoC
Reproducer for CVE-2026-42527 — Apache Camel permissive default ObjectInputFilter admits java.net.URL, enabling a DNS-based out-of-band side channel
Apache Camel: Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based information disclosure
41RISCO
abrir ↗GitHub PoC★ 1
RustDesk < 1.4.9 - Missing Session-Scope Enforcement Allows Out-of-Scope Control Message Injection
RustDesk Missing Session Scope Enforcement Allows Out-of-Scope Control Message Injection
41RISCO
abrir ↗GitHub PoC
OS Command Injection in Health Check → Remote Code Execution
Coolify: OS Command Injection in Health Check Configuration Allows Remote Code Execution
41RISCO
abrir ↗GitHub PoC
A PoC script for CVE-2026-38526, RCE via a file upload vulnerability in the /admin/tinymce/upload endpoint of webkul krayin 2.2.x
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RISCO
abrir ↗GitHub PoC
WHS 4기 이희수. kr-vulhub 과제 제출물
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗GitHub PoC
Cybersecurity Capstone Project completed during the NCSC Nashama CyberCamp 11, delivered in collaboration with IT Security C&T. The project demonstrates vulnerability assessment, exploitation, mitigation, and SIEM detection for Oracle WebLogic (CVE-2017-10271) and Apache Druid (CVE-2021-25646).
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir ↗GitHub PoC★ 1
CVE-2026-46242
eventpoll: fix ep_remove struct eventpoll / struct file UAF
41RISCO
abrir ↗GitHub PoC★ 2
Balbooa Forms (com_baforms) < 2.4.1 — Unauthenticated File Upload to RCE via form.uploadAttachmentFile | CVSS 9.8 | CISA KEV
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
98RISCO
abrir ↗GitHub PoC★ 1
Dahua CVE-2026-29114
A vulnerability has been found in some Dahua products. An attacker
may obtain the device’s CA root certificate. If that
28RISCO
abrir ↗GitHub PoC
Web application security assessment of DVWA using OWASP ZAP — vulnerability scanning, RCE (CVE-2012-1823) analysis, and remediation report.
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RISCO
abrir ↗GitHub PoC★ 3
This is an exploit for CVE-2026-46215 (Linux Kernel Use After Free) Adapted for Linux 7.0 !!! by Antonius (ev1lut10n / sw0rdm4n)
drm: Set old handle to NULL before prime swap in change_handle
41RISCO
abrir ↗GitHub PoC
1beelze/CVE-2026-14894
Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)
63RISCO
abrir ↗GitHub PoC
Instant Appointment <= 1.2 — Unauthenticated Arbitrary File Upload to RCE via add_service_front AJAX | CVSS 9.8
Instant Appointment <= 1.2 - Unauthenticated Arbitrary File Upload
48RISCO
abrir ↗GitHub PoC★ 1
Azure IoT Hub where exposure of an owner-level Shared Access Key enables unauthenticated remote code execution (RCE) against connected IoT devices. Proof-Of-Concept
Gardyn IoT Hub Use of Hard-coded Credentials
48RISCO
abrir ↗GitHub PoC★ 4
CVE-2026-46331 act_pedit page-cache corruption exploit, with Alpine PIE fix
net/sched: fix pedit partial COW leading to page cache corruption
41RISCO
abrir ↗GitHub PoC
PoC for jenkins 2.63 CVE-2019-1003030
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/
100RISCO
abrir ↗GitHub PoC★ 1
Dahua CVE-2026-29116
A vulnerability has been found in some Dahua products could
allow an unauthenticated remote attacker to send a specially
41RISCO
abrir ↗GitHub PoC
[AI-assisted] Root method for Lenovo IdeaTab A1000G (MT8317, kernel 3.4.0, Android 4.1) via CVE-2016-5195 (Dirty COW)
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir ↗GitHub PoC★ 1
CVE-2026-23744 MCPJam Inspector unauthenticated RCE PoC
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir ↗GitHub PoC★ 1
PoC untuk CVE-2026-0740: Ninja Forms File Uploads <= 3.3.26 — Unauthenticated Arbitrary File Upload yang dapat mengarah ke RCE.
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RISCO
abrir ↗GitHub PoC
[AI-assisted] Root method for Lenovo IdeaTab A1000G (MT8317, kernel 3.4.0, Android 4.1) via CVE-2016-5195 (Dirty COW)
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir ↗GitHub PoC
Exploitability PoC for CVE-2026-9558 (SSTI Mautic Theme)
A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twi
48RISCO
abrir ↗GitHub PoC
Exploit for CVE-2022-26134
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir ↗GitHub PoC
oPanel Authanticated Remote Code Execution via 'advenced/curl' Component
A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allow
41RISCO
abrir ↗GitHub PoC
Reproducer for CVE-2026-40859 — Apache Camel camel-netty-http / camel-vertx-http producer-side unsafe deserialization of HTTP response bodies (RCE)
Apache Camel: Camel-Vertx-Http: Unsafe Java deserialization of HTTP response bodies via a raw ObjectInputStream when transferException is enabled
41RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.