Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
79.980 exploits
GitHub PoC
endusdksla/xwiki-cve-2025-24893
CVE-2025-24893CRITICALsob ataque09 jul 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC1
CVE-2026-50181 / GHSA-fg23-3346-88f5: Langroid path traversal advisory landing page
CVE-2026-50181HIGH09 jul 2026
Langroid: Path traversal in the file tools allows read/write outside configured current directory
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware09 jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Librebooking Admin RCE PoC CVE-2026-61343
CVE-2026-61343HIGH09 jul 2026
LibreBooking path traversal
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALsob ataque09 jul 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISCO
abrir
GitHub PoC
Laboratory validation of CVE-2026-48908 in Joomla SP Page Builder, covering unauthorized icon upload, PHP file write, code execution as www-data, auditd and PCAP evidence, event timeline reconstruction, and SOC detection recommendations. Includes Polish and English reports.
CVE-2026-48908CRITICAL09 jul 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
68RISCO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHsob ataqueransomware09 jul 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
GitHub PoC1
Tracking GhostLock (CVE-2026-43499), the rtmutex/futex stack use-after-free
CVE-2026-43499HIGH09 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC
Control Web Panel (CWP) vulnerability scenario related to CVE-2026-57517
CVE-2026-57517CRITICAL09 jul 2026
Control Web Panel < 0.9.8.1225 Blind SQL Injection via userRes Parameter
48RISCO
abrir
GitHub PoC
CVE-2026-50746... - Draft
CVE-2026-50746CRITICAL09 jul 2026
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Conne
48RISCO
abrir
GitHub PoC
johnwickakash12/CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware09 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC9
tc3650/CVE-2026-43499-armv7
CVE-2026-43499HIGH09 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISCO
abrir
GitHub PoC1
Offical PoC for this cve
CVE-2026-56876HIGH09 jul 2026
extract-zip unvalidated symlink path traversal
41RISCO
abrir
GitHub PoC1
0x00phantom-hat/CVE-2026-12400-Exploit
CVE-2026-12400MEDIUM09 jul 2026
FlowForms <= 1.1.1 - Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary Form Modification via REST API '/flowforms/v1/forms/{id}' Endpoints
33RISCO
abrir
GitHub PoC1
CVE-2026-50131 / GHSA-xw9q-2mv6-9fr8: Fedify incomplete SSRF mitigation advisory landing page
CVE-2026-50131HIGH09 jul 2026
Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-1571509 jul 2026
In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a ma
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-8037CRITICALsob ataque09 jul 2026
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-48908CRITICAL09 jul 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
68RISCO
abrir
GitHub PoC2
CVE-2026-53359漏洞补丁
CVE-2026-53359HIGH09 jul 2026
KVM: x86: Fix shadow paging use-after-free due to unexpected role
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHsob ataqueransomware09 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC1
CVE-2026-4257 - Contact Form by Supsystic <= 1.7.36 # SSTI to RCE
CVE-2026-4257CRITICAL09 jul 2026
Contact Form by Supsystic <= 1.7.36 - Unauthenticated Server-Side Template Injection via Prefill Functionality
75RISCO
abrir
GitHub PoC
Automated exploit for Krayin CRM ≤ 2.2.x.
CVE-2026-38526CRITICAL08 jul 2026
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RISCO
abrir
GitHub PoC1
Blocking the DirtyFrag Linux LPE chain (CVE-2026-43284 / CVE-2026-43500) at runtime with a Cilium Tetragon TracingPolicy
CVE-2026-43284HIGH08 jul 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISCO
abrir
GitHub PoC
junghyeonkum/CVE-2022-24706
CVE-2022-24706CRITICALsob ataque08 jul 2026
Remote Code Execution Vulnerability in Packaging
100RISCO
abrir
GitHub PoC
eunho87/CVE-2021-42013
CVE-2021-42013CRITICALsob ataqueransomware08 jul 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC
Tracking Januscape (CVE-2026-53359), the KVM/x86 guest-to-host escape
CVE-2026-53359HIGH08 jul 2026
KVM: x86: Fix shadow paging use-after-free due to unexpected role
41RISCO
abrir
Exploit-DB
Joomla Page Builder CK 3.5.10 - Arbitrary File Upload
CVE-2026-56290CRITICALwebappsmultiple08 jul 2026
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
75RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-44825HIGH08 jul 2026
Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users
56RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-40048: Apache Camel camel-pqc FileBasedKeyLifecycleManager unsafe deserialization (RCE)
CVE-2026-40048HIGH08 jul 2026
Apache Camel PQC: Unsafe Deserialization from FileBasedKeyLifecycleManager
41RISCO
abrir
GitHub PoC
zero-trace7/CVE-2026-50229
CVE-2026-50229MEDIUM08 jul 2026
Apache Tomcat: XSS in number guess example
48RISCO
abrir
anteriorpágina 70 / 2.666próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.