Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.596exploits catalogados
36.656CVEs com exploração pública
24.695testados em laboratório
14.991 exploits
GitHub PoC6
Termux Privilege Escalation Tool & Root Manager - CVE-2026-43501
CVE-2026-43501CRITICAL11 jul 2026
ipv6: rpl: reserve mac_len headroom when recompressed SRH grows
48RISCO
abrir
GitHub PoC
MW-HF/Drupal-CVE-2026-9082
CVE-2026-9082CRITICALsob ataque11 jul 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISCO
abrir
GitHub PoC
An unauthenticated SQL injection vulnerability exists in the Vendure Shop API. A user-controlled query string parameter is interpolated directly into a raw SQL expression without parameterization or validation, allowing an attacker to execute arbitrary SQL against the database.
CVE-2026-40887CRITICAL11 jul 2026
@vendure/core has a SQL Injection vulnerability
43RISCO
abrir
GitHub PoC
jini135wii/CVE-2019-15107
CVE-2019-15107CRITICALsob ataqueransomware11 jul 2026
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-42527 — Apache Camel permissive default ObjectInputFilter admits java.net.URL, enabling a DNS-based out-of-band side channel
CVE-2026-42527HIGH11 jul 2026
Apache Camel: Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based information disclosure
41RISCO
abrir
GitHub PoC1
RustDesk < 1.4.9 - Missing Session-Scope Enforcement Allows Out-of-Scope Control Message Injection
CVE-2026-57850HIGH11 jul 2026
RustDesk Missing Session Scope Enforcement Allows Out-of-Scope Control Message Injection
41RISCO
abrir
GitHub PoC
OS Command Injection in Health Check → Remote Code Execution
CVE-2026-59734HIGH11 jul 2026
Coolify: OS Command Injection in Health Check Configuration Allows Remote Code Execution
41RISCO
abrir
GitHub PoC
A PoC script for CVE-2026-38526, RCE via a file upload vulnerability in the /admin/tinymce/upload endpoint of webkul krayin 2.2.x
CVE-2026-38526CRITICAL11 jul 2026
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RISCO
abrir
GitHub PoC
WHS 4기 이희수. kr-vulhub 과제 제출물
CVE-2021-41773HIGHsob ataqueransomware11 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
Cybersecurity Capstone Project completed during the NCSC Nashama CyberCamp 11, delivered in collaboration with IT Security C&T. The project demonstrates vulnerability assessment, exploitation, mitigation, and SIEM detection for Oracle WebLogic (CVE-2017-10271) and Apache Druid (CVE-2021-25646).
CVE-2017-10271HIGHsob ataqueransomware11 jul 2026
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir
GitHub PoC1
CVE-2026-46242
CVE-2026-46242HIGH11 jul 2026
eventpoll: fix ep_remove struct eventpoll / struct file UAF
41RISCO
abrir
GitHub PoC2
Balbooa Forms (com_baforms) < 2.4.1 — Unauthenticated File Upload to RCE via form.uploadAttachmentFile | CVSS 9.8 | CISA KEV
CVE-2026-56291CRITICALsob ataque11 jul 2026
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
98RISCO
abrir
GitHub PoC1
Dahua CVE-2026-29114
CVE-2026-29114LOW11 jul 2026
A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that
28RISCO
abrir
GitHub PoC
Web application security assessment of DVWA using OWASP ZAP — vulnerability scanning, RCE (CVE-2012-1823) analysis, and remediation report.
CVE-2012-1823CRITICALsob ataque11 jul 2026
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RISCO
abrir
GitHub PoC3
This is an exploit for CVE-2026-46215 (Linux Kernel Use After Free) Adapted for Linux 7.0 !!! by Antonius (ev1lut10n / sw0rdm4n)
CVE-2026-46215HIGH11 jul 2026
drm: Set old handle to NULL before prime swap in change_handle
41RISCO
abrir
GitHub PoC
1beelze/CVE-2026-14894
CVE-2026-14894CRITICAL11 jul 2026
Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)
63RISCO
abrir
GitHub PoC
Instant Appointment <= 1.2 — Unauthenticated Arbitrary File Upload to RCE via add_service_front AJAX | CVSS 9.8
CVE-2026-15282CRITICAL11 jul 2026
Instant Appointment <= 1.2 - Unauthenticated Arbitrary File Upload
48RISCO
abrir
GitHub PoC1
Azure IoT Hub where exposure of an owner-level Shared Access Key enables unauthenticated remote code execution (RCE) against connected IoT devices. Proof-Of-Concept
CVE-2026-13768CRITICAL11 jul 2026
Gardyn IoT Hub Use of Hard-coded Credentials
48RISCO
abrir
GitHub PoC4
CVE-2026-46331 act_pedit page-cache corruption exploit, with Alpine PIE fix
CVE-2026-46331HIGH11 jul 2026
net/sched: fix pedit partial COW leading to page cache corruption
41RISCO
abrir
GitHub PoC
PoC for jenkins 2.63 CVE-2019-1003030
CVE-2019-1003030CRITICALsob ataque11 jul 2026
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/
100RISCO
abrir
GitHub PoC1
Dahua CVE-2026-29116
CVE-2026-29116HIGH11 jul 2026
A vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker to send a specially
41RISCO
abrir
GitHub PoC
[AI-assisted] Root method for Lenovo IdeaTab A1000G (MT8317, kernel 3.4.0, Android 4.1) via CVE-2016-5195 (Dirty COW)
CVE-2016-5195HIGHsob ataque11 jul 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC1
CVE-2026-23744 MCPJam Inspector unauthenticated RCE PoC
CVE-2026-23744CRITICAL11 jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
GitHub PoC1
PoC untuk CVE-2026-0740: Ninja Forms File Uploads <= 3.3.26 — Unauthenticated Arbitrary File Upload yang dapat mengarah ke RCE.
CVE-2026-0740CRITICAL11 jul 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RISCO
abrir
GitHub PoC
[AI-assisted] Root method for Lenovo IdeaTab A1000G (MT8317, kernel 3.4.0, Android 4.1) via CVE-2016-5195 (Dirty COW)
CVE-2016-5195HIGHsob ataque11 jul 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC
Lim-ahmin/CVE-2021-43798
CVE-2021-43798HIGHsob ataque11 jul 2026
Grafana path traversal
100RISCO
abrir
GitHub PoC
Exploitability PoC for CVE-2026-9558 (SSTI Mautic Theme)
CVE-2026-9558CRITICAL10 jul 2026
A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twi
48RISCO
abrir
GitHub PoC
Exploit for CVE-2022-26134
CVE-2022-26134CRITICALsob ataqueransomware10 jul 2026
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC
oPanel Authanticated Remote Code Execution via 'advenced/curl' Component
CVE-2026-50979HIGH10 jul 2026
A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allow
41RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-40859 — Apache Camel camel-netty-http / camel-vertx-http producer-side unsafe deserialization of HTTP response bodies (RCE)
CVE-2026-40859HIGH10 jul 2026
Apache Camel: Camel-Vertx-Http: Unsafe Java deserialization of HTTP response bodies via a raw ObjectInputStream when transferException is enabled
41RISCO
abrir
anteriorpágina 42 / 500próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.