Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.781exploits catalogados
36.771CVEs com exploração pública
24.695testados em laboratório
15.172 exploits
GitHub PoC11
app that ports CVE-2019-2215 to arm32 and mounts a su binary to /sbin with denylist + root app installer. firehose/Magisk guide included
CVE-2019-2215HIGHsob ataque30 jun 2026
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir
GitHub PoC1
POC for CVE-2026-48907
CVE-2026-48907CRITICALsob ataque30 jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISCO
abrir
GitHub PoC
Defensive validation of CVE-2026-46331 / pedit COW with auditd, AppArmor, mitigation comparison and detection logic.
CVE-2026-46331HIGH30 jun 2026
net/sched: fix pedit partial COW leading to page cache corruption
41RISCO
abrir
GitHub PoC
CVE-2026-46490 — samlify <2.13.0 SAML AttributeValue XML injection -> signed-assertion privilege escalation. Self-contained PoC, verified e2e.
CVE-2026-46490HIGH30 jun 2026
samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Assertions
41RISCO
abrir
GitHub PoC
rootdirective-sec/CVE-2026-55255-Lab
CVE-2026-55255HIGH30 jun 2026
Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
41RISCO
abrir
GitHub PoC1
CVE-2025-40271 Modifed By MadEploits
CVE-2025-40271HIGH30 jun 2026
fs/proc: fix uaf in proc_readdir_de()
41RISCO
abrir
GitHub PoC13
watchtowrlabs/watchTowr-vs-Netscaler-CVE-2026-8451
CVE-2026-8451HIGH30 jun 2026
Insufficient input validation leading to memory overread
46RISCO
abrir
GitHub PoC
CVE-2026-46817 - Draft
CVE-2026-46817CRITICALsob ataque30 jun 2026
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versi
83RISCO
abrir
GitHub PoC
CVE-2026-56121 — Feast <0.63.0 unauthenticated RCE via gRPC registry dill.loads of OnDemandFeatureView UDF (pre-auth). Lab + PoC, verified e2e.
CVE-2026-56121CRITICAL30 jun 2026
Feast < 0.63.0 Unauthenticated RCE via ApplyFeatureView gRPC Deserialization
48RISCO
abrir
GitHub PoC2
Kestra Auth-Bypass Vulnerability Checker
CVE-2026-49869CRITICALsob ataque30 jun 2026
Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`
78RISCO
abrir
GitHub PoC
Defensive validation of CVE-2026-46331 / pedit COW with auditd, AppArmor, mitigation comparison and detection logic.
CVE-2026-46331HIGH30 jun 2026
net/sched: fix pedit partial COW leading to page cache corruption
41RISCO
abrir
GitHub PoC
Safari 跨域读取视频
CVE-2026-43700MEDIUM30 jun 2026
A cross-origin issue was addressed with improved tracking of security origins. This issue is fixed in Safari 26.5.2, iOS
33RISCO
abrir
GitHub PoC
Chequeo y Fix de la vulnerabilidad "pedit COW"
CVE-2026-46331HIGH30 jun 2026
net/sched: fix pedit partial COW leading to page cache corruption
41RISCO
abrir
GitHub PoC
CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).
CVE-2026-58138CRITICAL30 jun 2026
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
63RISCO
abrir
GitHub PoC
CVE-2012-1823 - PHP CGI Argument Injection Remote Code Execution (RCE)
CVE-2012-1823CRITICALsob ataque30 jun 2026
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RISCO
abrir
GitHub PoC
CVE-2026-8037 - Draft
CVE-2026-8037CRITICALsob ataque30 jun 2026
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
100RISCO
abrir
GitHub PoC14
DirtySlide XNU Exploit (CVE-2026-43724) For MacOS
CVE-2026-43724HIGH30 jun 2026
The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.
41RISCO
abrir
GitHub PoC
Independent reverse engineering and reproduction of CVE-2015-1187, an unauthenticated command injection in the D-Link DIR-820L (Rev A, v1.05B03). MIPS firmware extraction with binwalk, static analysis in Ghidra, and tracing the `ping_addr` parameter to its command-execution sink.
CVE-2015-1187CRITICALsob ataque30 jun 2026
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr
100RISCO
abrir
GitHub PoC3
CVE-2026-43284 - CVE-2026-43500 - CVE-2026-46300 Variant of dirtyfrag exploit
CVE-2026-46300HIGH30 jun 2026
net: skbuff: preserve shared-frag marker during coalescing
56RISCO
abrir
GitHub PoC
CVE-2026-44789 — n8n <1.123.43 HTTP Request pagination prototype pollution to RCE (NODE_OPTIONS runner-spawn gadget). Lab + automated PoC, verified e2e.
CVE-2026-44789CRITICAL30 jun 2026
n8n: HTTP Request Node Pagination Prototype Pollution to RCE
48RISCO
abrir
GitHub PoC2
Citrix NetScaler CVE Preconditions Checker as per CTX696604 | Supported CVE : CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817, and CVE-2026-13474
CVE-2026-8451HIGH30 jun 2026
Insufficient input validation leading to memory overread
46RISCO
abrir
GitHub PoC
Goal is to triage well known attacks and learn how security teams quickly respond.
CVE-2017-0144HIGHsob ataqueransomware29 jun 2026
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
GitHub PoC4
CVE-2026-48907 – Joomla JCE Unauthenticated Remote Code Execution (RCE)
CVE-2026-48907CRITICALsob ataque29 jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISCO
abrir
GitHub PoC3
Pure C exploit for CVE-2023-4911 (Looney Tunables) — x86_64 & aarch64 implementations. Multi-processing brute-forcing, dynamic calibration, integrated ELF parser.
CVE-2023-4911HIGHsob ataque29 jun 2026
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISCO
abrir
GitHub PoC
xitexploiter96-dot/CVE-2026-48907-
CVE-2026-48907CRITICALsob ataque29 jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISCO
abrir
GitHub PoC1
CVE-2026-56782 — Gorse <0.5.10 unauthenticated DB dump/restore (admin_api_key fail-open). Lab + PoC, verified e2e.
CVE-2026-56782CRITICAL29 jun 2026
Gorse - Unauthenticated Database Dump and Restore via /api/dump and /api/restore Endpoints
63RISCO
abrir
GitHub PoC
cve-2026-48907 scanner
CVE-2026-48907CRITICALsob ataque29 jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISCO
abrir
GitHub PoC
HutTwoThreeFour/CVE-2026-5562-Exploit
CVE-2026-5562MEDIUM29 jun 2026
provectus kafka-ui Endpoint testexecutions validateAccess code injection
33RISCO
abrir
GitHub PoC1
React2Shell (CVE-2025-55182) PoC
CVE-2025-55182CRITICALsob ataqueransomware29 jun 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
CVE-2026-53753 — Crawl4AI <0.8.7 unauthenticated RCE (AST sandbox escape via gi_frame.f_back). Lab + PoC, verified e2e.
CVE-2026-53753CRITICAL29 jun 2026
Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API
63RISCO
abrir
anteriorpágina 55 / 506próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.