Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
79.900 exploits
VulnCheck XDB
initial-access
CVE-2026-60137MEDIUMsob ataque20 jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISCO
abrir
GitHub PoC
unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)
CVE-2026-63030CRITICALsob ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC2
noLKM,5.10 use CVE-2026-52910.
CVE-2026-52910HIGH20 jul 2026
bpf: Free reuseport cBPF prog after RCU grace period.
41RISCO
abrir
GitHub PoC4
WordPress REST API SQLi to RCE (CVE-2026-63030)
CVE-2026-63030CRITICALsob ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-23550CRITICAL20 jul 2026
WordPress Modular DS plugin <= 2.5.1 - Privilege Escalation vulnerability
68RISCO
abrir
GitHub PoC5
PoC for CVE-2026-12191
CVE-2026-12191HIGH20 jul 2026
Comma AI Openpilot Pickle modeld.py pickle.loads deserialization
41RISCO
abrir
VulnCheck XDB
info-leak
CVE-2026-63030CRITICALsob ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
VulnCheck XDB
info-leak
CVE-2026-63030CRITICALsob ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
VulnCheck XDB
info-leak
CVE-2024-23897CRITICALsob ataqueransomware20 jul 2026
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
GitHub PoC
CVE-2026-4858 research
CVE-2026-4858HIGH20 jul 2026
Path traversal in integration action URL leading to arbitrary API execution via system admin’s auth token.
21RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-57819CRITICALsob ataque20 jul 2026
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir
VulnCheck XDB
info-leak
CVE-2026-60137MEDIUMsob ataque20 jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISCO
abrir
GitHub PoC16
YellowKey BitLocker CVE-2026-45585 is an open-source utility to extract, backup, and organize BitLocker recovery keys on Windows encrypted drives. Automate volume decryption, manage drive encryption states via command-line tools, export secure configuration files, and track recovery key logs. Download direct repository setup files.
CVE-2026-45585MEDIUM20 jul 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RISCO
abrir
GitHub PoC
0x00phantom-hat/CVE-2026-5029-Exploit
CVE-2026-5029HIGH20 jul 2026
RCE in Code Runner MCP Server
41RISCO
abrir
VulnCheck XDB
info-leak
CVE-2026-60137MEDIUMsob ataque20 jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISCO
abrir
GitHub PoC313
A cPanel and WHM authentication bypassing tool
CVE-2026-41940CRITICALsob ataqueransomware20 jul 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISCO
abrir
GitHub PoC
CVE-2026-60121, CVE-2026-61498 - Draft
CVE-2026-60121CRITICAL20 jul 2026
Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via ping.php
48RISCO
abrir
GitHub PoC206
Docker labs + defensive scanner for fastjson remote-class-load RCE. fastjson 1.2.66-1.2.83: @JSONType resource probe (CVE-2026-16723). fastjson2 2.0.57: attacker @type reaches loadClass with autoType DISABLED via polymorphic types (@JSONType(seeAlso) / Jackson @JsonSubTypes). Marker-only payloads; safeMode + JDK17 controls.
CVE-2026-16723CRITICAL20 jul 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALsob ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
VulnCheck XDB
info-leak
CVE-2026-63030CRITICALsob ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC1
Detection script for CVE-2026-11374
CVE-2026-11374CRITICAL20 jul 2026
Account Takeover via Predictable SSO Ticket Generation
48RISCO
abrir
GitHub PoC1
WordPress Core Unauthenticated RCE (CVE-2026-63030, CVE-2026-60137)
CVE-2026-63030CRITICALsob ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-9242CRITICALsob ataque20 jul 2026
WatchGuard Firebox iked Out of Bounds Write Vulnerability
100RISCO
abrir
GitHub PoC
PoC reproducer for CVE-2026-49097 (Apache Camel camel-irc): the non-Camel-prefixed irc.sendTo header escapes the HTTP header filter and overrides the producer's configured channel, redirecting an IRC message to an attacker-chosen destination. Fixed in 4.14.8/4.18.3/4.21.0.
CVE-2026-49097MEDIUM20 jul 2026
Apache Camel: Camel-IRC: The irc.sendTo (and other irc.*) Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to redirect outgoing IRC messages to arbitrary channels or users
33RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-16723CRITICAL20 jul 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISCO
abrir
GitHub PoC
PoC reproducer for CVE-2026-49086 (Apache Camel camel-dapr): the pub/sub consumer copies the untrusted CloudEvent's pubsubName/topic into producer-routing headers, letting an attacker redirect a republished message to an arbitrary Dapr pub/sub component+topic (confused deputy). Fixed in 4.14.8/4.18.3/4.21.0.
CVE-2026-49086MEDIUM20 jul 2026
Apache Camel Dapr: Pub/Sub consumer copied the inbound CloudEvent's pub/sub-name and topic into producer-direction routing headers, allowing an actor who can publish to the subscribed topic to influence internal behaviour
33RISCO
abrir
GitHub PoC
TheLiimbo/CVE-2026-51992
CVE-2026-5199220 jul 2026
23RISCO
abrir
GitHub PoC1
An isolated Vagrant testbed designed to simulate a complete attack chain: Initial access via the Nginx heap buffer overflow (CVE-2026-42533) followed by root privilege escalation using the Ghostlock kernel vulnerability (CVE-2026-43449).
CVE-2026-42533CRITICAL20 jul 2026
NGINX Map directive and Regex matching vulnerability
48RISCO
abrir
GitHub PoC
Dungsocool/CVE-2024-23897
CVE-2024-23897CRITICALsob ataqueransomware20 jul 2026
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISCO
abrir
GitHub PoC1
PoC tool for CVE-2026-44680 affecting MikroORM ≤7.0.13. Exploits JSON path injection to extract database contents via UNION-based attacks. Features vulnerability detection, automated data extraction, table enumeration, and blind injection support. Includes proxy integration for Burp Suite and WAF evasion techniques.
CVE-2026-44680HIGH20 jul 2026
MikroORM: SQL injection via runtime-controlled identifiers and JSON-path keys
41RISCO
abrir
anteriorpágina 54 / 2.664próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.