Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
79.980 exploits
VulnCheck XDB
initial-access
CVE-2021-41773HIGHsob ataqueransomware12 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
VulnCheck XDB
local
CVE-2023-4911HIGHsob ataque12 jul 2026
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISCO
abrir
GitHub PoC226
CVE-2026-43499 Implementation for 6.12.23-android16-5-g75e9b1c7ae7c-abogki463945075-4k
CVE-2026-43499HIGH12 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC1
Hunt-Benito/samsung-bixby-command-execution-cve-2026-21055-improper-component-export
CVE-2026-21055HIGH12 jul 2026
Improper export of android application components in Bixby prior to version 4.0.70.8 allows local attackers to execute a
41RISCO
abrir
GitHub PoC269
GhostLock (CVE-2026-43499) kernel exploit for OnePlus devices with locked bootloader
CVE-2026-43499HIGH12 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC94
基于 CVE-2026-43499 的 8E5 机型自动化解锁辅助工具,仅限授权安全研究与自有设备使用。
CVE-2026-43499HIGH12 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
CVE research-to-detection-signature engineering project: fingerprinting the vsftpd 2.3.4 backdoor (CVE-2011-2523) externally, at scale, with validated false-positive/negative handling - built in Python
CVE-2011-252312 jul 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
GitHub PoC1
CVE-2026-23744 MCPJam Inspector unauthenticated RCE PoC
CVE-2026-23744CRITICAL11 jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
GitHub PoC
[AI-assisted] Root method for Lenovo IdeaTab A1000G (MT8317, kernel 3.4.0, Android 4.1) via CVE-2016-5195 (Dirty COW)
CVE-2016-5195HIGHsob ataque11 jul 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
GitHub PoC1
CVE-2026-46242
CVE-2026-46242HIGH11 jul 2026
eventpoll: fix ep_remove struct eventpoll / struct file UAF
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALsob ataqueransomware11 jul 2026
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-14894CRITICAL11 jul 2026
Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-0740CRITICAL11 jul 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RISCO
abrir
VulnCheck XDB
info-leak
CVE-2021-43798HIGHsob ataque11 jul 2026
Grafana path traversal
100RISCO
abrir
GitHub PoC
MW-HF/Drupal-CVE-2026-9082
CVE-2026-9082CRITICALsob ataque11 jul 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHsob ataqueransomware11 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2022-2907811 jul 2026
The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[
50RISCO
abrir
GitHub PoC
An unauthenticated SQL injection vulnerability exists in the Vendure Shop API. A user-controlled query string parameter is interpolated directly into a raw SQL expression without parameterization or validation, allowing an attacker to execute arbitrary SQL against the database.
CVE-2026-40887CRITICAL11 jul 2026
@vendure/core has a SQL Injection vulnerability
43RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-42527 — Apache Camel permissive default ObjectInputFilter admits java.net.URL, enabling a DNS-based out-of-band side channel
CVE-2026-42527HIGH11 jul 2026
Apache Camel: Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based information disclosure
41RISCO
abrir
GitHub PoC6
Termux Privilege Escalation Tool & Root Manager - CVE-2026-43501
CVE-2026-43501CRITICAL11 jul 2026
ipv6: rpl: reserve mac_len headroom when recompressed SRH grows
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL11 jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
VulnCheck XDB
local
CVE-2026-46331HIGH11 jul 2026
net/sched: fix pedit partial COW leading to page cache corruption
41RISCO
abrir
GitHub PoC1
Dahua CVE-2026-29115
CVE-2026-29115MEDIUM11 jul 2026
A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially c
33RISCO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHsob ataque11 jul 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-56291CRITICALsob ataque11 jul 2026
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
98RISCO
abrir
GitHub PoC4
CVE-2026-46331 act_pedit page-cache corruption exploit, with Alpine PIE fix
CVE-2026-46331HIGH11 jul 2026
net/sched: fix pedit partial COW leading to page cache corruption
41RISCO
abrir
GitHub PoC1
Dahua CVE-2026-29116
CVE-2026-29116HIGH11 jul 2026
A vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker to send a specially
41RISCO
abrir
GitHub PoC1
RustDesk < 1.4.9 - Missing Session-Scope Enforcement Allows Out-of-Scope Control Message Injection
CVE-2026-57850HIGH11 jul 2026
RustDesk Missing Session Scope Enforcement Allows Out-of-Scope Control Message Injection
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2019-1003030CRITICALsob ataque11 jul 2026
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-2564611 jul 2026
Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.
60RISCO
abrir
anteriorpágina 67 / 2.666próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.