Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
14.946 exploits
GitHub PoC
MinhHK68/CVE-2026-13736
CVE-2026-13736MEDIUM22 ago 2026
NewPath WildApricotPress Add-on – Member Directory <= 1.0.0 - Unauthenticated Member PII Disclosure via REST API
33RISCO
abrir
GitHub PoC1
CVE-2026-9198 - IBM Langflow OSS Unauthenticated Remote Code Execution (RCE)
CVE-2026-9198CRITICALsob ataque22 ago 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISCO
abrir
GitHub PoC
Metasploit-based penetration test on an isolated Metasploitable2 lab VM — remote exploitation via DistCC (CVE-2004-2687), privilege escalation via udev netlink (CVE-2009-1185), and vsftpd 2.3.4 backdoor analysis (CVE-2011-2523), with firewall mitigation validated end-to-end.
CVE-2009-118522 ago 2026
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to ga
60RISCO
abrir
GitHub PoC
llaytynher/CVE-2026-0740-upload-template
CVE-2026-0740CRITICAL22 ago 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RISCO
abrir
GitHub PoC
Metasploit-based penetration test on an isolated Metasploitable2 lab VM — remote exploitation via DistCC (CVE-2004-2687), privilege escalation via udev netlink (CVE-2009-1185), and vsftpd 2.3.4 backdoor analysis (CVE-2011-2523), with firewall mitigation validated end-to-end.
CVE-2011-252322 ago 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
GitHub PoC
ts zeroday exp made by nullsec white team
CVE-2026-41940CRITICALsob ataqueransomware22 ago 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC
Stored XSS in J2Commerce Guest Checkout via Cookie Filter Bypass
CVE-2026-74252HIGH22 ago 2026
Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5
41RISCO
abrir
GitHub PoC141
POC pre-auth RCE on Exchange
CVE-2026-62911HIGH22 ago 2026
Microsoft Exchange Server Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC
Metasploit-based penetration test on an isolated Metasploitable2 lab VM — remote exploitation via DistCC (CVE-2004-2687), privilege escalation via udev netlink (CVE-2009-1185), and vsftpd 2.3.4 backdoor analysis (CVE-2011-2523), with firewall mitigation validated end-to-end.
CVE-2004-268722 ago 2026
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote at
60RISCO
abrir
GitHub PoC
Copy Fail CVE-2016-5195
CVE-2016-5195HIGHsob ataque22 ago 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC2
Apple MacOS Screen Sharing Arbitrary File read/write -> RCE
CVE-2026-65400CRITICALsob ataque22 ago 2026
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS
78RISCO
abrir
GitHub PoC
CVE-2026-47630 — NVIDIA Triton Inference Server: arbitrary dlopen via TRITON_BATCH_STRATEGY_PATH
CVE-2026-47630MEDIUM22 ago 2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path travers
33RISCO
abrir
GitHub PoC
Investigation and Incident Response report for LetsDefend Alert SOC335 (CVE-2024-49138 Exploitation)
CVE-2024-49138HIGHsob ataque22 ago 2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC
Hands-on reproduction of CVE-2024-28000 in LiteSpeed Cache using an isolated WordPress lab. Includes reconnaissance, vulnerable hash recovery, Administrator privilege escalation proof, cleanup, and remediation-focused documentation.
CVE-2024-28000CRITICAL22 ago 2026
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISCO
abrir
GitHub PoC
Educational proof-of-concept automation for CVE-2022-22963, demonstrated in an authorized Hack The Box lab environment.
CVE-2022-22963CRITICALsob ataque22 ago 2026
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISCO
abrir
GitHub PoC
Detection & precondition-verification tool for CVE-2026-58231 (SAP Commerce Cloud Data Hub Adapter)
CVE-2026-58231CRITICAL22 ago 2026
Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
48RISCO
abrir
GitHub PoC
CVE-2026-32475
CVE-2026-32475CRITICAL22 ago 2026
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RISCO
abrir
GitHub PoC1
Exploit Title: Unauthenticated SQL Injection on CMS Made Simple <= 2.2.9
CVE-2019-905322 ago 2026
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
GitHub PoC
Gitlab-CVE-2026-19478
CVE-2026-19478CRITICAL22 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISCO
abrir
GitHub PoC
PoC for CVE-2026-75616, an authenticated OS command injection in TP-Link Archer C20 v6 firmware
CVE-2026-75616HIGH22 ago 2026
Command Injection in Router Web Management Interface
41RISCO
abrir
GitHub PoC
CPTS HackTheBox - Penetration Test Report: WordPress Path Traversal CVE-2019-11447
CVE-2019-1144722 ago 2026
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RISCO
abrir
GitHub PoC3
내 공유기가 Zbtlink ENDLESSDOORS 백도어(CVE-2026-66747) 대상인지 클릭 한 번으로 검사하는 Windows 프로그램
CVE-2026-66747CRITICAL22 ago 2026
ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant
48RISCO
abrir
GitHub PoC
CVE-2026-41567 1day
CVE-2026-41567HIGH21 ago 2026
Docker: `PUT /containers/{id}/archive` executes container binary on the host
41RISCO
abrir
GitHub PoC1
Educational use only!
CVE-2026-64638HIGH21 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RISCO
abrir
GitHub PoC
Reflected XSS via price_from & price_to Filter Parameters in PhocaCart
CVE-2026-76565MEDIUM21 ago 2026
Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7
33RISCO
abrir
GitHub PoC
JCEzploit is a powerful, fully-automated RCE exploit for Joomla JCE (CVE-2026-48907) featuring interactive shell, batch command execution, file download capability, and proxy support. Built with Python & Rich for penetration testers. Ethical use only. By Sudeepa Wanigarathna.
CVE-2026-48907CRITICALsob ataque21 ago 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISCO
abrir
GitHub PoC
wp2shell — WordPress Core Pre-Auth RCE Chain poc for CVE-2026-63030 and CVE-2026-60137
CVE-2026-63030CRITICALsob ataque21 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC
CVE-2026-39113: SQLite SQLAR heap-buffer-overflow advisory and reproducer
CVE-2026-3911321 ago 2026
Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3a
23RISCO
abrir
GitHub PoC1
CVE-2026-69836 — Unauthenticated RCE via Entra ID deserialization
CVE-2026-69836CRITICAL21 ago 2026
Microsoft Entra ID Remote Code Execution Vulnerability
48RISCO
abrir
GitHub PoC3
Read-only PoC for CVE-2026-65400 — macOS Screen Sharing (screensharingd) pre-auth SRP bypass giving root file read. Patched in macOS 26.6.1 / 15.7.9 / 14.8.9.
CVE-2026-65400CRITICALsob ataque21 ago 2026
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS
78RISCO
abrir

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.