Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.962exploits catalogados
36.896CVEs com exploração pública
24.695testados em laboratório
79.963 exploits
GitHub PoC
hg0434hongzh0/CVE-2026-14266
CVE-2026-14266HIGH17 jul 2026
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability
41RISCO
abrir
GitHub PoC
tungduongNT/CVE-2014-0160.
CVE-2014-0160HIGHsob ataque17 jul 2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALsob ataque17 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC63
CVE-2026-63030, CVE-2026-60137, wp2shell scanner
CVE-2026-63030CRITICALsob ataque17 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALsob ataque17 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC
Pentest completo sobre Metasploitable: recon con nmap, explotación con Metasploit (CVE-2007-2447), extracción y cracking de credenciales, persistencia SSH
CVE-2007-244717 jul 2026
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-8110HIGHsob ataque17 jul 2026
File overwrite in file update API in Gogs
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALsob ataque17 jul 2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISCO
abrir
GitHub PoC773
wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
CVE-2026-63030CRITICALsob ataque17 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC6
sorrow404Null/CVE-2026-43499-RMX5200
CVE-2026-43499HIGH17 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC865
KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499
CVE-2026-43499HIGH17 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC5
CVE-2026-15409/15410 SonicWall SMA1000 multi-exploit Framework 🔥 SSRF→Erlang RPC→RCE→root privesc. Features: --detect safe check, --exec, --read-file, --privesc, --rpc, interactive shell, batch threading, file write, ws-url override, pipe support.🛡️ KEV listed CVSS 10.0 actively exploited. Authorized testing only. Use Ethically, Stay Legal. 🔒
CVE-2026-15409CRITICALsob ataqueransomware17 jul 2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RISCO
abrir
GitHub PoC
TM4WEB Vulnerability - CVE-2022-35497
CVE-2022-3549717 jul 2026
In Trimble TM4WEB 21.4.0.4 due to security misconfiguration with session identifiers, it is possible to recover valid se
23RISCO
abrir
GitHub PoC1
WordPress KeepInMind CVE-2026-9271 Exploit - Tool detecting stored XSS in KeepInMind plugin v0.8.4.2 and below. Built by Sudeepa Wanigarathna, it simulates CSS injection to hijack admin accounts. Features safe testing, attack simulation, credential capture, bulk scanning, reporting. Essential for security researchers.
CVE-2026-9271MEDIUM17 jul 2026
KeepInMind - Dashboard Notes < 0.8.4.2 - Contributor+ Stored XSS
33RISCO
abrir
GitHub PoC
TM4Web Vulnerability - CVE-2022-35499
CVE-2022-35499HIGH17 jul 2026
In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via inject
41RISCO
abrir
GitHub PoC
fancyzll/CVE-2026-43499_OPPO-MT6835
CVE-2026-43499HIGH17 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-47323: Apache Camel CXF/Knative HeaderFilterStrategy missing inbound filtering, enabling Camel control-header injection (RCE via camel-exec) through CXF-RS/CXF-SOAP/Knative endpoints (fixed in 4.14.6/4.18.2/4.19.0)
CVE-2026-47323CRITICAL17 jul 2026
Apache Camel: Camel-CXF Message Header Injection via Missing Inbound Filtering
48RISCO
abrir
VulnCheck XDB
info-leak
CVE-2023-23752MEDIUMsob ataque17 jul 2026
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
GitHub PoC46
CVE-2026-50416: Windows 11 KASLR bypass
CVE-2026-50416LOW17 jul 2026
Win32k Information Disclosure Vulnerability
28RISCO
abrir
GitHub PoC7
CVE-2026-63030
CVE-2026-63030CRITICALsob ataque17 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-48204: Apache Camel camel-mongodb-gridfs gridfs.* header injection overriding the GridFS operation (enumerate/read/delete files) from an unauthenticated HTTP request (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-48204CRITICAL17 jul 2026
Apache Camel: Camel-MongoDB-GridFS: The gridfs.* control headers used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to switch the GridFS operation - including destructive file deletion - in the default configuration
48RISCO
abrir
GitHub PoC1
Reproducer for CVE-2026-48205: Apache Camel camel-dns dns.* header injection redirecting DNS queries to an attacker-controlled resolver (SSRF via DNS) and enabling internal-hostname reconnaissance (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-48205CRITICAL17 jul 2026
Apache Camel DNS: The dns.* and term Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to influence internal behaviour
48RISCO
abrir
GitHub PoC
jaf0rk/CVE-2026-14431
CVE-2026-14431HIGH17 jul 2026
Type Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside
41RISCO
abrir
GitHub PoC
Academic proof-of-concept demonstrating CVE-2026-15583 for authorized security research.
CVE-2026-15583HIGH17 jul 2026
SSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL header
41RISCO
abrir
GitHub PoC1
MiaPatsune/cve-2026-43499
CVE-2026-43499HIGH17 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC6
HIKRAVEN - Advanced Hikvision Security Assessment Platform for professional penetration testing. Detects 12+ CVEs including CVE-2021-36260 (CRITICAL), tests default credentials, performs network discovery, and generates professional security reports. For authorized security testing only! 🛡️🔒
CVE-2021-36260CRITICALsob ataque17 jul 2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISCO
abrir
GitHub PoC1
bekwiner/cve-2026-47777
CVE-2026-47777HIGH17 jul 2026
Mastodon has a consent-check bypass in its remote Collections
41RISCO
abrir
GitHub PoC
Academic proof-of-concept demonstrating CVE-2026-46442 for authorized security research.
CVE-2026-46442CRITICAL17 jul 2026
Flowise: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape
75RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-48203: Apache Camel camel-solr SolrParam./SolrField. header injection enabling Solr document-field injection and SSRF via the shards parameter (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-48203CRITICAL17 jul 2026
Apache Camel: Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fields
48RISCO
abrir
GitHub PoC1
CVE-2026-55579 – Unauthenticated RCE in Pheditor via hardcoded default password "admin". Full Python exploit with file upload & terminal execution. No dependencies.
CVE-2026-55579CRITICAL17 jul 2026
Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise
48RISCO
abrir
anteriorpágina 60 / 2.666próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.