Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
79.980 exploits
GitHub PoC
FzRsLLaSheR/CVE-2026-14960-CVE-2026-14961
CVE-2026-14960CRITICAL15 jul 2026
CVE-2026-14960
48RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-46591: Apache Camel camel-neo4j Cypher injection via property names in CamelNeo4jMatchProperties, enabling authorization bypass / cross-label data exfiltration (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-46591HIGH15 jul 2026
Apache Camel: Camel-Neo4j: JSON property names from the CamelNeo4jMatchProperties header are interpolated into the Cypher WHERE clause without validation, allowing Cypher injection (incomplete remediation of CVE-2025-66169)
41RISCO
abrir
GitHub PoC
CVE-2026-15410 - More: https://github.com/HORKimhab/poc-cve-collection
CVE-2026-15410HIGHsob ataqueransomware15 jul 2026
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the S
76RISCO
abrir
GitHub PoC
ctnBobong32/CVE-2026-43499-so-build
CVE-2026-43499HIGH15 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC1
罗技云掌机 · GhostLock CVE-2026-43499 root 尝试
CVE-2026-43499HIGH15 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC3
CvE-2026-43499偏移量计算
CVE-2026-43499HIGH15 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC1
A modified method to root Android device with locked bootloader via new exploit. (Only for Samsung now or smthing like that devices cuz i ported it to N970U1), Fork of https://github.com/localhosts-A/CyberMeowfia
CVE-2026-43499HIGH15 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
Cxyofficial/x200-cve-2026-43499
CVE-2026-43499HIGH15 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-46587: Apache Camel camel-couchbase CCB_* header injection enabling document disclosure, tampering, and TTL-forced data destruction (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-46587HIGH15 jul 2026
Apache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
41RISCO
abrir
GitHub PoC
Blog on CVE-2026-59827, Unsafe H2 query ouput deserialization
CVE-2026-59827CRITICAL15 jul 2026
Metabase: Unsafe Deserialization of H2 Query Results
48RISCO
abrir
GitHub PoC47
Xiaomi K70e (duchamp) one-click root via CVE-2026-43499 (IonStack) + KernelSU integration
CVE-2026-43499HIGH15 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-46588: Apache Camel camel-couchdb CouchDb* header injection (operation confusion) subverting a write-only endpoint into read + delete of arbitrary documents (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-46588HIGH15 jul 2026
Apache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
41RISCO
abrir
GitHub PoC12
CVE-2026-56164 EOP Exploit
CVE-2026-56164MEDIUMsob ataque15 jul 2026
Microsoft SharePoint Server Elevation of Privilege Vulnerability
68RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-46585: Apache Camel camel-lucene QUERY header injection enabling authorization bypass / index data exfiltration (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-46585HIGH15 jul 2026
Apache Camel Lucene: The query control headers used non-Camel-prefixed names (QUERY, RETURN_LUCENE_DOCS) that bypass the HTTP header filter, allowing an HTTP client to inject the full-text search query
41RISCO
abrir
GitHub PoC
CVE-2026-15409 - Dectect
CVE-2026-15409CRITICALsob ataqueransomware15 jul 2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RISCO
abrir
GitHub PoC
The GREENDARK hospital infrastructure was configured by Dr. Gusto Rogue prior to his termination. No further details are provided.
CVE-2021-41773HIGHsob ataqueransomware15 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
VulnCheck XDB
local
CVE-2023-36802HIGHsob ataque15 jul 2026
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
76RISCO
abrir
GitHub PoC1
Samsung libimagecodec.quram.so OOB Write PoC
CVE-2026-21045HIGH15 jul 2026
Out-of-bounds write in parsing TIFF format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote
41RISCO
abrir
GitHub PoC
Technical analysis and safety-conscious research harness for CVE-2019-6447 in ES File Explorer for Android
CVE-2019-644715 jul 2026
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISCO
abrir
GitHub PoC2
CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).
CVE-2026-58138CRITICAL15 jul 2026
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
63RISCO
abrir
GitHub PoC
NeseOS-Corp/CVE-2026-50657
CVE-2026-50657MEDIUM15 jul 2026
Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability
33RISCO
abrir
GitHub PoC30
PoC for CVE-2026-58635: Windows Narrator Braille Local Privilege Escalation
CVE-2026-58635HIGH15 jul 2026
Windows Narrator Braille Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC27
This repo contains a proof-of-concept exploit for CVE-2026-15409. It establishes non-root remote code execution on SonicWall SMA 1000 by implementing the Erlang protocol expected by localhost:1050 and tunneling it through the websocket for file r/w and arbitrary code execution via RPC calls.
CVE-2026-15409CRITICALsob ataqueransomware15 jul 2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-3864614 jul 2026
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISCO
abrir
GitHub PoC
asoka666/Cve-2020-11023
CVE-2020-11023MEDIUMsob ataque14 jul 2026
Potential XSS vulnerability in jQuery
85RISCO
abrir
GitHub PoC
JohannesLks/CVE-2026-50338
CVE-2026-50338HIGH14 jul 2026
Azure Spring Apps Elevation of Privilege Vulnerability
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-0740CRITICAL14 jul 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-46457 — Apache Camel camel-nats inbound header injection (Camel control-header injection via a NATS publisher; CamelHttpUri -> SSRF)
CVE-2026-46457HIGH14 jul 2026
Apache Camel: Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilterStrategy, allowing a client that can publish to the subject to inject Camel control headers
41RISCO
abrir
GitHub PoC15
Vulnerability analysis and Proof of Concept (PoC) for CVE-2026-43499 affecting Xiaomi devices. For educational and research purposes only.
CVE-2026-43499HIGH14 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
Pen Tesing Lab exploiting VSFTPD 2.3.4 backdoor via Metasploit Framework
CVE-2011-252314 jul 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
anteriorpágina 64 / 2.666próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.