Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.858exploits catalogados
36.825CVEs com exploração pública
24.695testados em laboratório
15.209 exploits
GitHub PoC63
CVE-2026-45504 Microsoft Exchange File Read
CVE-2026-45504HIGH24 jun 2026
Microsoft Exchange Server Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC16
Y5neKO/CVE-2026-8461-EXP
CVE-2026-8461HIGH24 jun 2026
Heap out-of-bounds write via odd slice_height in FFmpeg MagicYUV decoder
41RISCO
abrir
GitHub PoC
Khai thác lỗ hổng bảo mật CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware24 jun 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC1
CVE-2026-8461 - Draft
CVE-2026-8461HIGH24 jun 2026
Heap out-of-bounds write via odd slice_height in FFmpeg MagicYUV decoder
41RISCO
abrir
GitHub PoC
Unauthenticated RCE PoC for CVE-2026-48908 SP Page Builder (Joomla) arbitrary file upload and remote code execution exploit with mass scaning support.
CVE-2026-48908CRITICAL24 jun 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
68RISCO
abrir
GitHub PoC
CVE-2026-31431 getroot from a Turkish Cryptominer
CVE-2026-31431HIGHsob ataque24 jun 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC3
Unauthenticated Account Takeover via Weak Password Reset Validation via 'reset_user_id' Parameter | Unauthenticated Privilege Escalation via Weak Password Reset Validation via 'reset_activation_code' Leading to Account Takeover
CVE-2026-12416CRITICAL24 jun 2026
Invoice Generator <= 1.0.0 - Unauthenticated Account Takeover via Weak Password Reset Validation via 'reset_user_id' Parameter
48RISCO
abrir
GitHub PoC
Lỗ hổng FORTIWEB_CVE-2025-64446 & CVE-2025-58034
CVE-2025-64446CRITICALsob ataque24 jun 2026
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISCO
abrir
GitHub PoC1
Proof of concept for CVE-2026-56111, an out-of-bounds write in the M421 G-code handler of Marlin Firmware
CVE-2026-56111HIGH24 jun 2026
Marlin Firmware 2.1.2.7 Out-of-Bounds Write via M421 G-code Handler
41RISCO
abrir
GitHub PoC1
CVE-2026-39275 - Stored XSS Leading to Account Takeover in Cockpit CMS
CVE-2026-39275MEDIUM24 jun 2026
Cross Site Scripting vulnerability in Cockpit CMS v.2.13.5 and before allows a remote attacker to execute arbitrary code
33RISCO
abrir
GitHub PoC
ROOT TOOL
CVE-2022-37706HIGH24 jun 2026
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RISCO
abrir
GitHub PoC
CVE-2026-48908 - SP Page Builder Joomla Unauthenticated RCE
CVE-2026-48908CRITICAL24 jun 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
68RISCO
abrir
GitHub PoC1
CVE-2026-49777, CVE-2026-10735
CVE-2026-49777CRITICAL24 jun 2026
WordPress Product Slider Pro for WooCommerce plugin < 3.5.4 - Backdoor vulnerability
63RISCO
abrir
GitHub PoC
CraftCMS CVE-2025-32432 - Clean PoC
CVE-2025-32432CRITICALsob ataque24 jun 2026
Craft CMS Allows Remote Code Execution
100RISCO
abrir
GitHub PoC
CVE-2025-57819 FreePBX SQLi RCE PoC
CVE-2025-57819CRITICALsob ataque24 jun 2026
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir
GitHub PoC2
CVE-2026-48908
CVE-2026-48908CRITICAL24 jun 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
68RISCO
abrir
GitHub PoC
Joapath/CVE-2021-42013
CVE-2021-42013CRITICALsob ataqueransomware24 jun 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC
CVE-2021-22205 - GitLab Unauthenticated Remote Code Execution
CVE-2021-22205CRITICALsob ataqueransomware24 jun 2026
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISCO
abrir
GitHub PoC2
This repository contains the Proof of Concept (PoC) exploit script for CVE-2026-45156
CVE-2026-45156HIGH23 jun 2026
Nextcloud: Authentication Bypass in ID4me handling via Missing JWT Signature Verification in User OIDC
41RISCO
abrir
GitHub PoC
Public advisory for CVE-2026-39253, addressing an insecure deserialisation in Pivotal CRM 6.6.04.08 allowing remote code execution via unsafe BinaryFormatter usage in Smart Client and PBS components. Includes vulnerability details, affected versions, and remediation guidance.
CVE-2026-39253HIGH23 jun 2026
An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll a
41RISCO
abrir
GitHub PoC
eliHiHo/portfolio-drupal-cve-2026-9082
CVE-2026-9082CRITICALsob ataque23 jun 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISCO
abrir
GitHub PoC
fuchiuebusi-lab/nginx-ui-CVE-2026-42221-CVE-2026-42238-
CVE-2026-42221HIGH23 jun 2026
nginx-ui: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim
56RISCO
abrir
GitHub PoC
s1lentf00thold/CVE-2021-21425-RCE
CVE-2021-21425CRITICAL23 jun 2026
Unauthenticated Arbitrary YAML Write/Update leads to Code Execution
85RISCO
abrir
GitHub PoC28
CVE-2026-42978 — Use-After-Free race condition in Windows Push Notifications (WpnService). Patch diff, root cause analysis, TOCTOU lab, Sysmon/ETW detection rules.
CVE-2026-42978HIGH23 jun 2026
Windows Push Notifications Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC1
CVE-2026-11837: local privilege escalation in the ansible.posix authorized_key module via symlink-following chown. Technical writeup; sibling of CVE-2024-9902.
CVE-2026-11837HIGH23 jun 2026
Ansible-collection-ansible-posix: ansible.posix authorized_key: local privilege escalation via symlink-following chown
41RISCO
abrir
GitHub PoC
mythicaltree/CVE-2019-2215
CVE-2019-2215HIGHsob ataque23 jun 2026
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISCO
abrir
GitHub PoC1
A minimal PoC for CVE-2026-21018, demonstrating how it works
CVE-2026-21018MEDIUM23 jun 2026
Out-of-bounds write in SveService prior to SMR May-2026 Release 1 allows local privileged attackers to execute arbitrary
33RISCO
abrir
GitHub PoC
s1lentf00thold/CVE-2020-11651-Poc
CVE-2020-11651CRITICALsob ataque23 jun 2026
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISCO
abrir
GitHub PoC10
CVE-2026-55200
CVE-2026-55200CRITICAL23 jun 2026
libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
48RISCO
abrir
GitHub PoC
Prueba de concepto de CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware23 jun 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
anteriorpágina 60 / 507próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.