Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
79.980 exploits
GitHub PoC1
CVE-2026-45659 - Microsoft SharePoint Deserialization RCE - PoC & Analysis | CVSS 8.8 | AMN SECURITY
CVE-2026-45659HIGHsob ataqueransomware07 jul 2026
Microsoft SharePoint Remote Code Execution Vulnerability
93RISCO
abrir
GitHub PoC
CVE-2026-11405 - Draft
CVE-2026-11405CRITICAL07 jul 2026
Hidden backdoor authentication mechanism in multiple versions of Tenda firmware allows admin access to web management interface
48RISCO
abrir
GitHub PoC2
CVE-2026-8451 - Citrix NetScaler SAML Memory Overread (CitrixBleed) - PoC & Analysis | CVSS 8.8 | AMN SECURITY
CVE-2026-8451HIGH07 jul 2026
Insufficient input validation leading to memory overread
46RISCO
abrir
GitHub PoC
Laboratory validation of CVE-2026-48282 in Adobe ColdFusion RDS, covering arbitrary CFM file write, code execution as the ColdFusion service user, auditd and PCAP evidence, event timeline reconstruction, and SOC detection recommendations. Includes Polish and English reports.
CVE-2026-48282CRITICAL07 jul 2026
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
75RISCO
abrir
GitHub PoC
Bypass Authentication
CVE-2026-48611CRITICAL07 jul 2026
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or
63RISCO
abrir
GitHub PoC
🐳 docker-compose 를 활용한 취약한 환경 구성 및 검증 (vulhub 한글판)
CVE-2026-40519HIGH07 jul 2026
Nginx Proxy Manager Authenticated RCE via setupCertbotPlugins()
21RISCO
abrir
GitHub PoC1
CVE-2026-39492 — WP Maps (wp-google-map-plugin) <= 4.9.1 Unauthenticated Blind SQL Injection Mass Scanner | sqlmap-style detection | backtick bypass esc_sql() | 100K+ installs
CVE-2026-39492CRITICAL07 jul 2026
WordPress WP Maps plugin <= 4.9.1 - SQL Injection vulnerability
48RISCO
abrir
GitHub PoC101
CVE-2026-42980 PUBLIC EXPLOIT + RESEARCH
CVE-2026-42980HIGH07 jul 2026
NT OS Kernel Elevation of Privilege Vulnerability
41RISCO
abrir
Exploit-DB
WordPress Bricks Builder Theme - RCE
CVE-2024-25600CRITICALwebappsmultiple07 jul 2026
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISCO
abrir
GitHub PoC2
CVE-2026-14762 exploit for Hotel & Tourism Reservation 1.0. Time-based blind SQL injection via /admin/rooms.php?delete. Dumps DB, tables, columns, reads files, writes webshells. Multi-threaded, proxy support, interactive shell. CVSS 7.3. Authorized & Legal testing only.
CVE-2026-14762MEDIUM07 jul 2026
code-projects Hotel and Tourism Reservation Room Management rooms.php sql injection
33RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALsob ataque06 jul 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticated attackers to gain admin access by supplying an empty X-Api-Key header value.
CVE-2026-25555CRITICAL06 jul 2026
OpenBullet2 0.3.2 Authentication Bypass via X-Api-Key Header
63RISCO
abrir
GitHub PoC
AF_ALG/splice 기반 Linux Page Cache 변조 취약점 분석 및 대응 실습
CVE-2026-31431HIGHsob ataque06 jul 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC24
imbas007/CVE-2026-48282
CVE-2026-48282CRITICAL06 jul 2026
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
75RISCO
abrir
GitHub PoC
Rust-based DLL hijacking loader for MobaXterm (CVE-2026-6421) with persistence
CVE-2026-6421HIGH06 jul 2026
Mobatek MobaXterm Home Edition msimg32.dll uncontrolled search path
41RISCO
abrir
GitHub PoC
HTB "Abducted" write-up. Exploit CVE-2026-4480 (Samba RCE) → SMB wide links → systemd → root. Full methodology and flags.
CVE-2026-4480CRITICAL06 jul 2026
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-27172: Apache Camel camel-consul ConsulRegistry Java deserialization (RCE)
CVE-2026-27172HIGH06 jul 2026
Apache Camel: Unsafe Java deserialization in camel-consul ConsulRegistry allows arbitrary code execution via malicious values read from the Consul KV store
41RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-40022: Apache Camel camel-platform-http-main authentication bypass on non-root context paths
CVE-2026-40022HIGH06 jul 2026
Apache Camel Platform HTTP Main: Authentication Bypass on Non-Root Context Paths in camel main runtime
41RISCO
abrir
GitHub PoC
Next.js / RSC - Unauthenticated RCE (React2Shell) (CVE-2025-55182)
CVE-2025-55182CRITICALsob ataqueransomware06 jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
Reproducer for CVE-2026-33453: Apache Camel camel-coap header injection to RCE via camel-exec
CVE-2026-33453CRITICAL06 jul 2026
Apache Camel: CoAP URI Query Parameter to Exchange Header Injection in camel-coap Allows Single-Packet Pre-Auth Remote Code Execution
63RISCO
abrir
GitHub PoC
Exploit for Authenticated Remote Code Execution (RCE) in Krayin CRM v2.2.x (CVE-2026-38526)
CVE-2026-38526CRITICAL06 jul 2026
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RISCO
abrir
GitHub PoC1
Reproducer for CVE-2026-33454: Apache Camel camel-mail header injection to RCE via camel-exec
CVE-2026-33454CRITICAL06 jul 2026
Apache Camel: Inbound Header Filter Missing in MailHeaderFilterStrategy Allows Remote Code Execution via MIME Header Injection (CVE-2025-30177 Variant)
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-54236CRITICALsob ataque06 jul 2026
Adobe Commerce | Improper Input Validation (CWE-20)
100RISCO
abrir
GitHub PoC
HTB_Nexus Penetration Test Report – Comprehensive security assessment documenting credential leakage from Gitea, CVE-2026-38526 exploitation in Krayin CRM, and privilege escalation via Gitea template sync directory traversal. Mapped to MITRE ATT&CK and NSA D3FEND frameworks with actionable remediation roadmap and full evidence appendix.
CVE-2026-38526CRITICAL06 jul 2026
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RISCO
abrir
GitHub PoC1
Exploitability PoC for CVE-2026-49352 (9router Hardcoded JWT Secret Authentication Bypass)
CVE-2026-49352CRITICAL06 jul 2026
9Router: Hardcoded Default fallback JWT Secret Allows Authentication Bypass
48RISCO
abrir
GitHub PoC1
In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution
CVE-2024-39024HIGH06 jul 2026
In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.
41RISCO
abrir
GitHub PoC7
jaf0rk/CVE-2026-14382
CVE-2026-14382CRITICAL06 jul 2026
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware06 jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
Exploit-DB
WordPress Plugin WPZOOM Portfolio 1.4.21 - Reflected Cross-Site Scripting (XSS)
CVE-2026-49069HIGHwebappsmultiple06 jul 2026
WordPress WPZOOM Portfolio plugin <= 1.4.21 - Cross Site Scripting (XSS) vulnerability
56RISCO
abrir
Exploit-DB
Pulpy 0.1.1-Beta - Filesystem Sandbox Bypass
CVE-2026-44225CRITICALwebappsmultiple06 jul 2026
Pulpy: Incomplete filesystem sandbox in pulpy.fs bridge allows packaged web apps to read arbitrary user files
48RISCO
abrir
anteriorpágina 73 / 2.666próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.