Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.858exploits catalogados
36.825CVEs com exploração pública
24.695testados em laboratório
15.209 exploits
GitHub PoC
CVE-2026-54807 WooCommerce Privilege Escalation ║ ║ Unauthenticated Admin Role Assignment via Reg. Form
CVE-2026-54807CRITICAL26 jun 2026
WordPress Registration Form for WooCommerce plugin <= 1.0.9 - Privilege Escalation vulnerability
48RISCO
abrir
GitHub PoC5
CVE-2026-8461
CVE-2026-8461HIGH26 jun 2026
Heap out-of-bounds write via odd slice_height in FFmpeg MagicYUV decoder
41RISCO
abrir
GitHub PoC
scanner for CVE-2020-0796
CVE-2020-0796CRITICALsob ataqueransomware26 jun 2026
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC17
mooder1/dirtyclone-CVE-2026-43503
CVE-2026-43503HIGH26 jun 2026
net: skbuff: propagate shared-frag marker through frag-transfer helpers
41RISCO
abrir
GitHub PoC
sec0x/CVE-2026-43503
CVE-2026-43503HIGH26 jun 2026
net: skbuff: propagate shared-frag marker through frag-transfer helpers
41RISCO
abrir
GitHub PoC
The SSRF filter checked hostname text, but the actual destination was decided later by DNS. That gap let attacker-controlled Webhook URLs reach loopback, metadata, and private network targets.
CVE-2026-34207HIGH26 jun 2026
TypeBot: SSRF Protection Bypass via DNS-Resolved Hostnames in Webhook / HTTP Request Validation
41RISCO
abrir
GitHub PoC4
aexdyhaxor/CVE-2026-43503-DirtyClone
CVE-2026-43503HIGH26 jun 2026
net: skbuff: propagate shared-frag marker through frag-transfer helpers
41RISCO
abrir
GitHub PoC
A low-privileged Docmost user could supply a victim attachmentId to the generic upload endpoint and overwrite another page's stored attachment inside the same workspace.
CVE-2026-34213MEDIUM26 jun 2026
Docmost has cross-page attachment overwrite via flawed attachmentId overwrite validation
33RISCO
abrir
GitHub PoC
Docmost accepted a javascript: URL inside an attachment node, preserved it through storage and rendering, and turned it back into a clickable anchor in the Docmost origin.
CVE-2026-34212MEDIUM26 jun 2026
Docmost page content has stored XSS via unsanitized attachment URLs
33RISCO
abrir
GitHub PoC
A public share looked clean in the page tree, but the search endpoint told a different story. In Docmost, restricted child pages hidden from public share viewers could still leak through public share search results.
CVE-2026-33146MEDIUM26 jun 2026
Docmost's Public Share Search Exposes Metadata of Restricted Children
33RISCO
abrir
GitHub PoC
Flowiseai Flowise Auth Bypass Vulnerability Proof of Concept
CVE-2025-58434CRITICAL26 jun 2026
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
75RISCO
abrir
GitHub PoC
12hrformat/CVE-2026-35273-POC
CVE-2026-35273CRITICALsob ataqueransomware26 jun 2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Mana
100RISCO
abrir
GitHub PoC1
CVE-2026-8932
CVE-2026-8932HIGH26 jun 2026
incomplete mTLS config matching in conn reuse
41RISCO
abrir
GitHub PoC1
Ghost CMS Content API Blind SQL Injection
CVE-2026-26980CRITICAL26 jun 2026
Ghost has a SQL Injection in its Content API
85RISCO
abrir
GitHub PoC11
CVE-2026-26980 - Ghost CMS Content API SQL Injection
CVE-2026-26980CRITICAL26 jun 2026
Ghost has a SQL Injection in its Content API
85RISCO
abrir
GitHub PoC1
CVE-2026-24207 — NVIDIA Triton SageMaker auth bypass to unauth RCE. Detection script, bypass demo, RCE-chain PoC, and IDS rules.
CVE-2026-24207CRITICAL26 jun 2026
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A succes
63RISCO
abrir
GitHub PoC3
CVE-2026-20251 — Splunk Secure Gateway jsonpickle deserialization RCE (CVSS 8.8) | ReactiveZero Security Research
CVE-2026-20251HIGH26 jun 2026
Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway
53RISCO
abrir
GitHub PoC
Cacti <= 1.2.30
CVE-2026-39938CRITICAL26 jun 2026
Cacti: Unauthenticated RCE on Graph Image
48RISCO
abrir
GitHub PoC
Unauthenticated time-based blind SQL injection exploit for CMS Made Simple ≤ 2.2.9 (CVE-2019-9053), ported to Python 3.
CVE-2019-905325 jun 2026
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
GitHub PoC
CVE-2026-55584 — phpSysInfo IP Allowlist Bypass
CVE-2026-55584HIGH25 jun 2026
phpSysInfo: IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP headers
41RISCO
abrir
GitHub PoC1
CVE-2026-7574
CVE-2026-7574HIGH25 jun 2026
Anthropic Claude Desktop Cowork VM Image Contents Not Validated Before Use
41RISCO
abrir
GitHub PoC
POC of CVE-2026-53075
CVE-2026-53075HIGH25 jun 2026
ppp: require CAP_NET_ADMIN in target netns for unattached ioctls
41RISCO
abrir
GitHub PoC
Lab — Privilege Escalation via Dirty Cow CVE-2016-5195 | 4Geeks Academy
CVE-2016-5195HIGHsob ataque25 jun 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC1
SCAN END POC THE CVE-2024-4367
CVE-2024-4367MEDIUM25 jun 2026
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir
GitHub PoC
7whyex/CVE-2026-45321-Tanstack
CVE-2026-45321CRITICALsob ataqueransomware25 jun 2026
Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
78RISCO
abrir
GitHub PoC
Squamity/CVE-2026-8181-PoC
CVE-2026-8181CRITICAL25 jun 2026
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RISCO
abrir
GitHub PoC1
W5M1n9/Cisco-Unified-Communications-Manager-Server-Side-Forgery-Request-Vulnerability-CVE-2026-20230
CVE-2026-20230HIGH25 jun 2026
Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability
63RISCO
abrir
GitHub PoC1
VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password hash, and escalating to root via SUID find.
CVE-2018-7600CRITICALsob ataqueransomware25 jun 2026
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC34
CVE-2026-43503
CVE-2026-43503HIGH25 jun 2026
net: skbuff: propagate shared-frag marker through frag-transfer helpers
41RISCO
abrir
GitHub PoC
Unauthenticated RCE PoC for CVE-2026-48908 SP Page Builder (Joomla) arbitrary file upload and remote code execution exploit with mass scaning support.
CVE-2026-48908CRITICAL24 jun 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
68RISCO
abrir
anteriorpágina 59 / 507próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.