Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
79.980 exploits
GitHub PoC1
Remote Code Execution (RCE) in Yamcs Mission Control System via Java Statement Injection in Yarch SQL Double-Quoted IdentifiersRemote Code Execution (RCE) in Yamcs Mission Control System via Java Statement Injection in Yarch SQL Double-Quoted Identifiers
CVE-2026-55511CRITICAL15 jul 2026
Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql`
48RISCO
abrir
GitHub PoC2
CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie deserialization to write webshell via Joomla FormattedtextLogger gadget chain. Includes interactive shell, path discovery, and cleanup. For authorized security testing only.
CVE-2026-48909CRITICAL15 jul 2026
Joomla Extension - joomshaper.com - PHP Object injection in SP LMS extension for Joomla < 4.1.4
63RISCO
abrir
GitHub PoC1
罗技云掌机 · GhostLock CVE-2026-43499 root 尝试
CVE-2026-43499HIGH15 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
A containerized enterprise-style lab for researching and defending against CVE-2026-27483.
CVE-2026-27483HIGH15 jul 2026
MindsDB has Path Traversal in /api/files Leading to Remote Code Execution
61RISCO
abrir
GitHub PoC
WhatsWrongAndWhy/CVE-2015-1328
CVE-2015-132815 jul 2026
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISCO
abrir
GitHub PoC
Cxyofficial/x200-cve-2026-43499
CVE-2026-43499HIGH15 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC3
CvE-2026-43499偏移量计算
CVE-2026-43499HIGH15 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC1
Samsung libimagecodec.quram.so OOB Write PoC
CVE-2026-21045HIGH15 jul 2026
Out-of-bounds write in parsing TIFF format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote
41RISCO
abrir
GitHub PoC47
Xiaomi K70e (duchamp) one-click root via CVE-2026-43499 (IonStack) + KernelSU integration
CVE-2026-43499HIGH15 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
lamaper/CVE-2026-52199
CVE-2026-52199CRITICAL15 jul 2026
An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/
48RISCO
abrir
GitHub PoC
exploit for CVE-2022-42889
CVE-2022-4288915 jul 2026
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
GitHub PoC
WhatsWrongAndWhy/CVE-2016-9793
CVE-2016-979315 jul 2026
The sock_setsockopt function in net/core/sock.c in the Linux kernel before 4.8.14 mishandles negative values of sk_sndbu
23RISCO
abrir
GitHub PoC
Panduan mitigasi Januscape (CVE-2026-53359) AlmaLinux 9.5 production-safe + scripts
CVE-2026-53359HIGH15 jul 2026
KVM: x86: Fix shadow paging use-after-free due to unexpected role
41RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-46585: Apache Camel camel-lucene QUERY header injection enabling authorization bypass / index data exfiltration (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-46585HIGH15 jul 2026
Apache Camel Lucene: The query control headers used non-Camel-prefixed names (QUERY, RETURN_LUCENE_DOCS) that bypass the HTTP header filter, allowing an HTTP client to inject the full-text search query
41RISCO
abrir
GitHub PoC
FzRsLLaSheR/CVE-2026-14960-CVE-2026-14961
CVE-2026-14960CRITICAL15 jul 2026
CVE-2026-14960
48RISCO
abrir
GitHub PoC
CVE-2026-15409 - Dectect
CVE-2026-15409CRITICALsob ataqueransomware15 jul 2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RISCO
abrir
GitHub PoC
CVE-2026-43499 Implementation for 6.12.23-android16-5-g75e9b1c7ae7c-abogki463945075-4k
CVE-2026-43499HIGH15 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
Technical analysis and safety-conscious research harness for CVE-2019-6447 in ES File Explorer for Android
CVE-2019-644715 jul 2026
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHsob ataqueransomware15 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2024-5082HIGH15 jul 2026
Nexus Repository 2 - Remote Code Execution
56RISCO
abrir
GitHub PoC1
A modified method to root Android device with locked bootloader via new exploit. (Only for Samsung now or smthing like that devices cuz i ported it to N970U1), Fork of https://github.com/localhosts-A/CyberMeowfia
CVE-2026-43499HIGH15 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC12
CVE-2026-56164 EOP Exploit
CVE-2026-56164MEDIUMsob ataque15 jul 2026
Microsoft SharePoint Server Elevation of Privilege Vulnerability
68RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-4288915 jul 2026
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-15409CRITICALsob ataqueransomware15 jul 2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RISCO
abrir
GitHub PoC1
ctn-Qvo/CVE-2026-43499-so-build
CVE-2026-43499HIGH15 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC2
CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).
CVE-2026-58138CRITICAL15 jul 2026
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
63RISCO
abrir
GitHub PoC
My portfolio showcasing vulnerability research (CVE-2026-11989, CVE-2026-11395) and automated threat orchestration engineering (Lucius Engine, TalonVigil).
CVE-2026-11989MEDIUM15 jul 2026
Bit integrations <= 2.8.7 - Unauthenticated Server-Side Request Forgery via Form Field Upload Mapping
33RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-46587: Apache Camel camel-couchbase CCB_* header injection enabling document disclosure, tampering, and TTL-forced data destruction (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-46587HIGH15 jul 2026
Apache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
41RISCO
abrir
VulnCheck XDB
local
CVE-2023-36802HIGHsob ataque15 jul 2026
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC3
CVE-2026-15409
CVE-2026-15409CRITICALsob ataqueransomware15 jul 2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RISCO
abrir
anteriorpágina 63 / 2.666próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.