Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.250VulnCheck XDB 8.959Nuclei 4.393Metasploit 3.502✓ só verificadosrecentespopularesrisco
79.980 exploits
VulnCheck XDB
initial-access
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir ↗GitHub PoC
Wazuh + Suricata SOC lab detecting real exploits (CVE-2011-2523) and brute-force attacks, with custom detection rules for gaps in default IDS signatures.
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir ↗GitHub PoC★ 1
Dahua CVE-2026-29115
A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially c
33RISCO
abrir ↗VulnCheck XDB
initial-access
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/
100RISCO
abrir ↗GitHub PoC★ 2
Balbooa Forms (com_baforms) < 2.4.1 — Unauthenticated File Upload to RCE via form.uploadAttachmentFile | CVSS 9.8 | CISA KEV
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
98RISCO
abrir ↗GitHub PoC★ 1
Dahua CVE-2026-29116
A vulnerability has been found in some Dahua products could
allow an unauthenticated remote attacker to send a specially
41RISCO
abrir ↗GitHub PoC★ 4
CVE-2026-46331 act_pedit page-cache corruption exploit, with Alpine PIE fix
net/sched: fix pedit partial COW leading to page cache corruption
41RISCO
abrir ↗VulnCheck XDB
remote-with-credentials
Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.
60RISCO
abrir ↗GitHub PoC★ 1
RustDesk < 1.4.9 - Missing Session-Scope Enforcement Allows Out-of-Scope Control Message Injection
RustDesk Missing Session Scope Enforcement Allows Out-of-Scope Control Message Injection
41RISCO
abrir ↗GitHub PoC
Instant Appointment <= 1.2 — Unauthenticated Arbitrary File Upload to RCE via add_service_front AJAX | CVSS 9.8
Instant Appointment <= 1.2 - Unauthenticated Arbitrary File Upload
48RISCO
abrir ↗VulnCheck XDB
initial-access
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
98RISCO
abrir ↗VulnCheck XDB
local
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir ↗VulnCheck XDB
initial-access
The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[
50RISCO
abrir ↗VulnCheck XDB
initial-access
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir ↗GitHub PoC
[AI-assisted] Root method for Lenovo IdeaTab A1000G (MT8317, kernel 3.4.0, Android 4.1) via CVE-2016-5195 (Dirty COW)
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir ↗GitHub PoC
Cybersecurity Capstone Project completed during the NCSC Nashama CyberCamp 11, delivered in collaboration with IT Security C&T. The project demonstrates vulnerability assessment, exploitation, mitigation, and SIEM detection for Oracle WebLogic (CVE-2017-10271) and Apache Druid (CVE-2021-25646).
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISCO
abrir ↗GitHub PoC
Exploitability PoC for CVE-2026-9558 (SSTI Mautic Theme)
A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twi
48RISCO
abrir ↗GitHub PoC
CVE-2025-60787 motionEye authenticated command injection RCE PoC
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name
61RISCO
abrir ↗GitHub PoC
Exploit for CVE-2022-26134
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir ↗GitHub PoC
caspy123/CVE-2026-43499
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir ↗GitHub PoC★ 2
A Proof of Concept (PoC) exploit for CVE-2026-46331
net/sched: fix pedit partial COW leading to page cache corruption
41RISCO
abrir ↗GitHub PoC
CVE-2026-54390 — JTL Shop Smarty SSTI RCE | Pre-Auth Template Injection via fetch('string:' . ) | 5.2.0-5.7.1
JTL Shop < 5.7.2 Server-Side Template Injection via Smarty Renderer
48RISCO
abrir ↗GitHub PoC
Dr-D25/CVE-2026-49049
Joomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler
56RISCO
abrir ↗GitHub PoC
Reproducer for CVE-2026-40860 — Apache Camel camel-jms/sjms/amqp JMS ObjectMessage unsafe deserialization (RCE)
Apache Camel: Unsafe Deserialization of JMS ObjectMessage in camel-jms, camel-sjms, camel-sjms2 and camel-amqp
48RISCO
abrir ↗GitHub PoC
oPanel Authanticated Remote Code Execution via 'advenced/curl' Component
A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allow
41RISCO
abrir ↗GitHub PoC
Reproducer for CVE-2026-40859 — Apache Camel camel-netty-http / camel-vertx-http producer-side unsafe deserialization of HTTP response bodies (RCE)
Apache Camel: Camel-Vertx-Http: Unsafe Java deserialization of HTTP response bodies via a raw ObjectInputStream when transferException is enabled
41RISCO
abrir ↗GitHub PoC★ 1
Reproducer for CVE-2026-40858 — Apache Camel camel-infinispan remote aggregation repository unsafe deserialization (RCE)
Apache Camel: Camel-Infinispan: Unsafe Deserialization in Remote Aggregation Repository
41RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.