Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
15.228 exploits
GitHub PoC
POC for CVE-2025-24054
CVE-2025-24054MEDIUMsob ataque21 jun 2026
NTLM Hash Disclosure Spoofing Vulnerability
75RISCO
abrir
GitHub PoC
Version: Download Manager 3.3.5.2 Title: Missing Authorization - Unauthenticated IDOR Exploit
CVE-2026-39676MEDIUM21 jun 2026
WordPress Download Manager plugin <= 3.3.52 - Broken Access Control vulnerability
33RISCO
abrir
GitHub PoC
Luisbuilds-data/cve-2024-1086-writeup
CVE-2024-1086HIGHsob ataqueransomware21 jun 2026
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISCO
abrir
GitHub PoC
Traveller is an Easy Linux machine featuring a Joomla 4.2.7 travel booking website vulnerable to CVE-2023-23752, an unauthenticated REST API information disclosure that leaks database credentials, leading to admin panel access, remote code execution, and root via sudo misconfiguration.
CVE-2023-23752MEDIUMsob ataque21 jun 2026
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir
GitHub PoC
adriannurrr/CVE-2026-45321-Tanstack
CVE-2026-45321CRITICALsob ataqueransomware21 jun 2026
Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
78RISCO
abrir
GitHub PoC
Technical analysis of CVE-2025-68613, a critical Expression Injection vulnerability in n8n that allows authenticated attackers to achieve Remote Code Execution (RCE)
CVE-2025-68613CRITICALsob ataque21 jun 2026
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISCO
abrir
GitHub PoC1
Nuclei template for CVE-2026-11561 — Apinizer SSTI / RCE version detection
CVE-2026-11561CRITICAL21 jun 2026
SSTI in Soagen Informatics' Apinizer
48RISCO
abrir
GitHub PoC
POC for CVE-2025-29927
CVE-2025-29927CRITICAL21 jun 2026
Authorization Bypass in Next.js Middleware
85RISCO
abrir
GitHub PoC
alexlanum/CVE-2026-32202
CVE-2026-32202MEDIUMsob ataque21 jun 2026
Windows Shell Spoofing Vulnerability
75RISCO
abrir
GitHub PoC
asdrf5gh67j8ki/CVE-2026-32202
CVE-2026-32202MEDIUMsob ataque21 jun 2026
Windows Shell Spoofing Vulnerability
75RISCO
abrir
GitHub PoC
POC for CVE-2025-24893
CVE-2025-24893CRITICALsob ataque21 jun 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC
POC for CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware21 jun 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Technical analysis of Apache Tomcat CVE-2024-50379, covering root cause, exploitation conditions, detection strategies, and mitigation techniques.
CVE-2024-50379CRITICAL20 jun 2026
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RISCO
abrir
GitHub PoC1
GadaLuBau1337/CVE-2026-44578
CVE-2026-44578HIGH20 jun 2026
Next.js: Server-side request forgery in applications using WebSocket upgrades
68RISCO
abrir
GitHub PoC3
CVE-2026-41091 RedSun | Microsoft Defender LPE exploit. Low-privileged users gain NT AUTHORITY\SYSTEM 🔥 via Cloud Files API + NTFS junction trickery. Forces Defender to write malicious payloads to System32 with SYSTEM rights. ⚠️ Actively exploited in wild. CVSS 7.8. Patch: Defender Engine 1.1.26040.8. 🛡️ Educational PoC only.
CVE-2026-41091HIGHsob ataque20 jun 2026
Microsoft Defender Elevation of Privilege Vulnerability
71RISCO
abrir
GitHub PoC
aelshimony-cloud/OpenWire-CVE-2023-46604-Investigation
CVE-2023-46604CRITICALsob ataqueransomware20 jun 2026
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISCO
abrir
GitHub PoC2
CVE-2026-37149 - SQL Injection vulnerability in the scost parameter of search_products.php in GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0.
CVE-2026-37149HIGH20 jun 2026
GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0 was discovered to contain a SQL injection vulnerabil
41RISCO
abrir
GitHub PoC
Time-Based Blind SQL Injection tool for MySQL - CVE-2019-9053
CVE-2019-905320 jun 2026
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
GitHub PoC2
Missing Authorization to Unauthenticated File Modification
CVE-2026-11912HIGH20 jun 2026
Simple File List <= 6.3.7 - Missing Authorization to Unauthenticated File Modification via simplefilelist_edit_job AJAX Action
41RISCO
abrir
GitHub PoC
HTTP/2 Bomb (CVE-2026-49975) non-destructive vulnerability detector for Nginx / Apache httpd. Zero-dependency Python.
CVE-2026-49975HIGH20 jun 2026
Apache HTTP Server: mod_http2 denial of service
53RISCO
abrir
GitHub PoC
ClearLotus-git/CVE-2026-4480-PoC
CVE-2026-4480CRITICAL20 jun 2026
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RISCO
abrir
GitHub PoC1
Unauthenticated Privilege Escalation via Account Takeover
CVE-2026-11551CRITICAL19 jun 2026
Branda – White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated Privilege Escalation via Account Takeover
48RISCO
abrir
GitHub PoC
Повышение привилегий через race condition в polkit
CVE-2021-3560HIGHsob ataque19 jun 2026
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISCO
abrir
GitHub PoC
Saku0512/CVE-2026-54761-poc
CVE-2026-54761MEDIUM19 jun 2026
Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services
33RISCO
abrir
GitHub PoC
xxconi/CVE-2026-4782
CVE-2026-4782MEDIUM19 jun 2026
Avada Builder <= 3.15.2 - Authenticated (Subscriber+) Arbitrary File Read via 'custom_svg' Shortcode Parameter
33RISCO
abrir
GitHub PoC
CVE-2026-11551: Branda Plugin - Unauthenticated Privilege Escalation via Account Takeover
CVE-2026-11551CRITICAL19 jun 2026
Branda – White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated Privilege Escalation via Account Takeover
48RISCO
abrir
GitHub PoC4
Scanner PoC for CVE-2026-42530 -- nginx 1.31.0-1.31.1 HTTP/3 QPACK encoder stream Use-After-Free (CVSS 9.2)
CVE-2026-42530CRITICAL19 jun 2026
NGINX Open-Source ngx_http_v3_module vulnerability
48RISCO
abrir
GitHub PoC
Exploitability PoC for CVE-2026-43515 (Apache Tomcat constraint bypass).
CVE-2026-43515CRITICAL19 jun 2026
Apache Tomcat: Security constraints not correctly applied
48RISCO
abrir
GitHub PoC6
PoC exploit for CVE-2023-6019 - Remote Code Execution via unauthenticated Ray Dashboard Jobs API.
CVE-2023-6019CRITICAL19 jun 2026
Ray Command Injection in cpu_profile Parameter
85RISCO
abrir
GitHub PoC
CVE-2026-7515: BetterDocs Pro <= 3.8.0 - Unauthenticated Local File Inclusion TO RCE EXPLOİT
CVE-2026-7515CRITICAL19 jun 2026
BetterDocs Pro <= 3.8.0 - Unauthenticated Local File Inclusion via doc_style
48RISCO
abrir
anteriorpágina 63 / 508próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.