Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
79.900 exploits
GitHub PoC325
Android complete exploit chain that enables privilege escalation from a local untrusted app to root/kernel, combination of CVE-2026-49881 and CVE-2026-43284
CVE-2026-49881HIGH23 jul 2026
In serviceClassExists of InCallController.java, there is a possible arbitrary code execution due to a logic error in the
41RISCO
abrir
GitHub PoC
CVE Reproduction: cve-2025-5777-citrixbleed2_reproduction
CVE-2025-5777CRITICALsob ataqueransomware23 jul 2026
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
GitHub PoC
CVE-2026-41940 & CVE-2026-41948 — cPanel & WHM Auth Bypass
CVE-2026-41940CRITICALsob ataqueransomware23 jul 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC5
soralis0912/CVE-2026-43499-aristotle-apk
CVE-2026-43499HIGH23 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC1
0xdak/CVE-2026-56121_exploit
CVE-2026-56121CRITICAL23 jul 2026
Feast < 0.63.0 Unauthenticated RCE via ApplyFeatureView gRPC Deserialization
48RISCO
abrir
GitHub PoC
GitHub Actions workflow sandbox (CVE-2026-48546 reproduction)
CVE-2026-48546HIGH23 jul 2026
KanaDojo < 0.1.18 Sandbox Escape RCE via messages.cjs
21RISCO
abrir
GitHub PoC
GitHub Actions workflow sandbox for CVE-2026-45132 reproduction
CVE-2026-45132CRITICAL23 jul 2026
CloudPirates Open Source Helm Charts: GitHub Actions workflow leaks PAT and SSH signing key via unsafe credential handling
48RISCO
abrir
GitHub PoC28
YellowKey free tool for the CVE-2026-45585 BitLocker bypass vulnerability on Windows 10/11. Covered on Tom's Hardware: extract recovery keys, apply remediation, test bypass mitigation and manage BitLocker encryption state. Download YellowKey
CVE-2026-45585MEDIUM23 jul 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RISCO
abrir
VulnCheck XDB
local
CVE-2021-3493HIGHsob ataque23 jul 2026
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALsob ataque23 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC
Initialized & connected PostgreSQL to Metasploit. Reconnoitered 10.1.16.0/24 with Nmap and imported results. Enumerated hosts/services using SYN, SMB & LDAP scanners. Exploited DC10 via ZeroLogon (CVE-2020-1472), dumped AD NTLM hashes with Impacket, performed Pass-the-Hash, then gained a Meterpreter reverse shell.
CVE-2020-1472MEDIUMsob ataqueransomware23 jul 2026
Netlogon Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC12
DavidCarliez/CVE-2026-66804-CrossDevice-LPE
CVE-2026-66804HIGH23 jul 2026
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC
CVE-2026-42533 Nginx
CVE-2026-42533CRITICAL23 jul 2026
NGINX Map directive and Regex matching vulnerability
48RISCO
abrir
VulnCheck XDB
info-leak
CVE-2024-43451MEDIUMsob ataque23 jul 2026
NTLM Hash Disclosure Spoofing Vulnerability
85RISCO
abrir
GitHub PoC1
CVE-2021-41773 Apache
CVE-2021-41773HIGHsob ataqueransomware23 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
0xdak/CVE-2026-63766_exploit
CVE-2026-63766CRITICAL23 jul 2026
GPT-SoVITS 20250606v2pro OS Command Injection via webui.py
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL23 jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
GitHub PoC1
Metabase CVE-2026-59827 Vulnerability Scanner
CVE-2026-59827CRITICAL23 jul 2026
Metabase: Unsafe Deserialization of H2 Query Results
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALsob ataqueransomware23 jul 2026
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISCO
abrir
GitHub PoC
finding by nvth
CVE-2026-59880HIGH23 jul 2026
Immutable.js: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
21RISCO
abrir
VulnCheck XDB
info-leak
CVE-2025-5777CRITICALsob ataqueransomware23 jul 2026
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALsob ataqueransomware23 jul 2026
Argument Injection in PHP-CGI
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHsob ataqueransomware23 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALsob ataque23 jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-32432CRITICALsob ataque23 jul 2026
Craft CMS Allows Remote Code Execution
100RISCO
abrir
GitHub PoC4
soralis0912/CVE-2026-43499-aristotle
CVE-2026-43499HIGH23 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
Scan WordPress installations for wp2shell vulnerabilities (CVE-2026-63030 + CVE-2026-60137). Identifies full RCE and SQL injection risks across multiple sites with severity classification and CSV reporting.
CVE-2026-63030CRITICALsob ataque22 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC
CVE-2026-50522
CVE-2026-50522CRITICALsob ataque22 jul 2026
Microsoft SharePoint Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC1
CVE-2026-16540 — Simply Schedule Appointments < 1.6.12.6 Unauthenticated Appointment Data Disclosure and Mass Deletion
CVE-2026-16540HIGH22 jul 2026
Simply Schedule Appointments < 1.6.12.6 - Unauthenticated Appointment Data Disclosure and Mass Deletion via purge Endpoint
41RISCO
abrir
GitHub PoC
Full ML-KEM-1024 key recovery from a partial Fujisaki-Okamoto comparison in wolfSSL (CVE-2026-6330 NEON, CVE-2026-10097 AVX2)
CVE-2026-6330MEDIUM22 jul 2026
ML-KEM ARM64 NEON ciphertext comparison only compares half of the input
33RISCO
abrir
anteriorpágina 50 / 2.664próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.