Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.596exploits catalogados
36.656CVEs com exploração pública
24.695testados em laboratório
14.991 exploits
GitHub PoC
CVE-2026-50746... - Draft
CVE-2026-50746CRITICAL09 jul 2026
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Conne
48RISCO
abrir
GitHub PoC154
yellow key bitlocker yellow screen bitlocker bitlocker recovery key CVE-2026-45585 microsoft account secure boot bypass command prompt windows 11 windows 10 surface pro uefi firmware encryption key data recovery troubleshoot boot loop cmd unlock drive setup guide tutorial
CVE-2026-45585MEDIUM09 jul 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RISCO
abrir
GitHub PoC
Whitehat School 4기 CVE-2021-4034 분석 및 POC 작성
CVE-2021-4034HIGHsob ataqueransomware09 jul 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC9
tc3650/CVE-2026-43499-armv7
CVE-2026-43499HIGH09 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC1
CVE-2026-50131 / GHSA-xw9q-2mv6-9fr8: Fedify incomplete SSRF mitigation advisory landing page
CVE-2026-50131HIGH09 jul 2026
Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges
41RISCO
abrir
GitHub PoC
cazzysoci/cve-2026-48908
CVE-2026-48908CRITICAL09 jul 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
68RISCO
abrir
GitHub PoC
包括能执行的命令探测和一键getshell(需要服务器部署服务)
CVE-2026-8037CRITICALsob ataque09 jul 2026
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
100RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-40473: Apache Camel camel-mina MinaConverter.toObjectInput unsafe deserialization (RCE over TCP/UDP)
CVE-2026-40473HIGH09 jul 2026
Apache Camel Mina: Unsafe Deserialization in MinaConverter.toObjectInput() via TCP/UDP
41RISCO
abrir
GitHub PoC1
lieehrdiansyah12/CVE-2026-43503
CVE-2026-43503HIGH09 jul 2026
net: skbuff: propagate shared-frag marker through frag-transfer helpers
41RISCO
abrir
GitHub PoC
endusdksla/xwiki-cve-2025-24893
CVE-2025-24893CRITICALsob ataque09 jul 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC1
CVE-2026-50181 / GHSA-fg23-3346-88f5: Langroid path traversal advisory landing page
CVE-2026-50181HIGH09 jul 2026
Langroid: Path traversal in the file tools allows read/write outside configured current directory
41RISCO
abrir
GitHub PoC
CVE-2026-41089 checker: unauthenticated, non-destructive detection for the Netlogon CLDAP stack buffer overflow (CVSS 9.8). Reports whether a domain controller's domain is long enough to crash, without sending the overflow. The binary-verified analysis the public PoCs got wrong.
CVE-2026-41089CRITICAL09 jul 2026
Windows Netlogon Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC61
OPPO Find N2 GhostLock (CVE-2026-43499) exploit adaptation
CVE-2026-43499HIGH09 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
Control Web Panel (CWP) vulnerability scenario related to CVE-2026-57517
CVE-2026-57517CRITICAL09 jul 2026
Control Web Panel < 0.9.8.1225 Blind SQL Injection via userRes Parameter
48RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-40453: Apache Camel case-variant Camel header injection (incomplete fix of CVE-2025-27636)
CVE-2026-40453CRITICAL08 jul 2026
Apache Camel JMS, Apache Camel CoAP, Apache Camel Google PubSub: Incomplete fix for CVE-2025-27636 in non-HTTP HeaderFilterStrategies (camel-jms, camel-sjms, camel-coap, camel-google-pubsub) allows case-variant header injection
48RISCO
abrir
GitHub PoC1
CVE-2026-49777 - WooCommerce Product Slider Pro Malicious Software Implantation RCE - PoC & Analysis | CVSS 10.0 CRITICAL | AMN SECURITY
CVE-2026-49777CRITICAL08 jul 2026
WordPress Product Slider Pro for WooCommerce plugin < 3.5.4 - Backdoor vulnerability
63RISCO
abrir
GitHub PoC1
CVE-2026-8206 - Kirki WordPress Plugin Unauthenticated Account Takeover - PoC & Analysis | CVSS 9.8 CRITICAL | AMN SECURITY
CVE-2026-8206CRITICAL08 jul 2026
Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'
48RISCO
abrir
GitHub PoC1
CVE-2026-0257 - Palo Alto PAN-OS GlobalProtect Auth Override Cookie Forgery - PoC & Analysis | CVSS 9.1 CRITICAL CISA KEV | AMN SECURITY
CVE-2026-0257HIGHsob ataqueransomware08 jul 2026
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
100RISCO
abrir
GitHub PoC
CVE-2026-33017 - Langflow < 1.9.0 Unauthenticated RCE PoC
CVE-2026-33017CRITICALsob ataque08 jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir
GitHub PoC2
Verificador de Vulnerabilidad: Bad Epoll (CVE-2026-46242)
CVE-2026-46242HIGH08 jul 2026
eventpoll: fix ep_remove struct eventpoll / struct file UAF
41RISCO
abrir
GitHub PoC
junghyeonkum/CVE-2022-24706
CVE-2022-24706CRITICALsob ataque08 jul 2026
Remote Code Execution Vulnerability in Packaging
100RISCO
abrir
GitHub PoC
CVE-2026-43499 - Draft
CVE-2026-43499HIGH08 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC7
CVE-2026-43499
CVE-2026-43499HIGH08 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
Automated exploit for Krayin CRM ≤ 2.2.x.
CVE-2026-38526CRITICAL08 jul 2026
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RISCO
abrir
GitHub PoC16
Proof of concept exploit for CVE-2026-3775/CVE-2026-3780 and CVE-2026-57239 which lets you obtain NT AUTHORITY\SYSTEM rights via the Foxit PDF Reader updater service.
CVE-2026-57239HIGH08 jul 2026
Foxit PDF Editor/Reader Local Privilege Escalation
41RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-40048: Apache Camel camel-pqc FileBasedKeyLifecycleManager unsafe deserialization (RCE)
CVE-2026-40048HIGH08 jul 2026
Apache Camel PQC: Unsafe Deserialization from FileBasedKeyLifecycleManager
41RISCO
abrir
GitHub PoC
Automated exploit for Krayin CRM ≤ 2.2.x.
CVE-2026-38526CRITICAL08 jul 2026
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RISCO
abrir
GitHub PoC12
Apache Solr instances that may be affected by CVE-2026-44825, related to Velocity Template Remote Code Execution (RCE) conditions.
CVE-2026-44825HIGH08 jul 2026
Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users
56RISCO
abrir
GitHub PoC1
Blocking the DirtyFrag Linux LPE chain (CVE-2026-43284 / CVE-2026-43500) at runtime with a Cilium Tetragon TracingPolicy
CVE-2026-43284HIGH08 jul 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISCO
abrir
GitHub PoC
Tracking Januscape (CVE-2026-53359), the KVM/x86 guest-to-host escape
CVE-2026-53359HIGH08 jul 2026
KVM: x86: Fix shadow paging use-after-free due to unexpected role
41RISCO
abrir
anteriorpágina 44 / 500próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.