Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
15.228 exploits
GitHub PoC4
A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass
CVE-2026-24061CRITICALsob ataque08 jun 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISCO
abrir
GitHub PoC
YellowKey | BitLocker Bypass CVE-2026-45585 | Detect & Fix Automatically via Microsoft Intune
CVE-2026-45585MEDIUM08 jun 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RISCO
abrir
GitHub PoC
willygailo/WG-CVE-2026-1555-Linux
CVE-2026-1555CRITICAL08 jun 2026
WebStack <= 1.2024 - Unauthenticated Arbitrary File Upload
48RISCO
abrir
GitHub PoC
carlosalbertotuma/cve-2026-3180-poc
CVE-2026-3180HIGH08 jun 2026
Contest Gallery <= 28.1.4 - Unauthenticated SQL Injection
41RISCO
abrir
GitHub PoC2
Disclosed on June 3, 2026, the "HTTP/2 Bomb" is an unauthenticated remote DoS that combines an HPACK compression bomb with a Slowloris-style hold to exhaust server memory. It affects default HTTP/2 configurations of **nginx, Apache httpd, Microsoft IIS, Envoy, and Cloudflare Pingora**.
CVE-2026-49975HIGH08 jun 2026
Apache HTTP Server: mod_http2 denial of service
53RISCO
abrir
GitHub PoC
Exploitability PoC for CVE-2026-43512 (Apache Tomcat Digest Authentication Bypass)
CVE-2026-43512CRITICAL08 jun 2026
Apache Tomcat: Digest authenticator will authenticate any unknown user
48RISCO
abrir
GitHub PoC2
CVE-2026-11499
CVE-2026-11499CRITICAL08 jun 2026
Tenda HG7HG9/HG10 formDOMAINBLK stack-based overflow
48RISCO
abrir
GitHub PoC1
Mitigation scripts for CVE-2026-50751
CVE-2026-50751CRITICALsob ataqueransomware08 jun 2026
User Authentication Bypass in VPN Remote Access and Mobile Access
100RISCO
abrir
GitHub PoC1
smb spooler to RCE
CVE-2026-4480CRITICAL08 jun 2026
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RISCO
abrir
GitHub PoC
Based on the original version:https://github.com/vulhub/vulhub/blob/master/erlang/CVE-2025-32433/exploit.py Replace Unicode checkmark with ASCII character for Windows compatibility
CVE-2025-32433CRITICALsob ataque08 jun 2026
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISCO
abrir
GitHub PoC
Python tool for analyzing CVE-2018-16763 in FUEL CMS with cleaner response parsing and interactive vulnerability checking.
CVE-2018-1676308 jun 2026
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir
GitHub PoC1
Unauthenticated SQL Injection to Remote Code Execution in FreePBX — CVE-2025-57819
CVE-2025-57819CRITICALsob ataque08 jun 2026
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir
GitHub PoC
CVE-2023-21716 - Microsoft Word RTF fonttbl Heap Corruption RCE exploit with reverse shell payload
CVE-2023-21716CRITICAL08 jun 2026
Microsoft Word Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC
rootdirective-sec/CVE-2026-7465-Lab
CVE-2026-7465HIGH08 jun 2026
Spectra Gutenberg Blocks <= 2.19.25 - Authenticated (Contributor+) Remote Code Execution via Arbitrary PHP Function Call via Block Attributes
41RISCO
abrir
GitHub PoC1
CVE-2026-50751
CVE-2026-50751CRITICALsob ataqueransomware08 jun 2026
User Authentication Bypass in VPN Remote Access and Mobile Access
100RISCO
abrir
GitHub PoC
Unauthenticated SQL injection in FreePBX Endpoint Manager (CVE-2025-57819) that injects a cron-scheduled PHP webshell for remote code execution.
CVE-2025-57819CRITICALsob ataque07 jun 2026
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir
GitHub PoC2
FreePBX Pre-Auth SQLi to RCE (CVE-2025-57819) — All-in-One Exploit
CVE-2025-57819CRITICALsob ataque07 jun 2026
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir
GitHub PoC1
Exploit CVE-2026-4480
CVE-2026-4480CRITICAL07 jun 2026
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RISCO
abrir
GitHub PoC
Drupal Core PostgreSQL SQLi to RCE via /user/login (CVE-2026-9082 / SA-CORE-2026-004)
CVE-2026-9082CRITICALsob ataque07 jun 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISCO
abrir
GitHub PoC
m0nk3ygod/CVE-2026-34040-PoC
CVE-2026-34040HIGH07 jun 2026
Moby: AuthZ plugin bypass with oversized request body
41RISCO
abrir
GitHub PoC1
CVE-2026-4480
CVE-2026-4480CRITICAL07 jun 2026
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RISCO
abrir
GitHub PoC
CVE-2023-46604-RCE exploit with Linux reverse shell payload
CVE-2023-46604CRITICALsob ataqueransomware06 jun 2026
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISCO
abrir
GitHub PoC
CVE-2026-20245 - Cisco SD-WAN - Draft
CVE-2026-20245HIGHsob ataque06 jun 2026
Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability
76RISCO
abrir
GitHub PoC
HTTP/2 attack simulation & defense lab - Slowloris, Rapid Reset (CVE-2023-44487), HPACK Bomb attacks with 5 layered defenses. Built in pure Python with raw sockets and h2 library.
CVE-2023-44487HIGHsob ataque06 jun 2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISCO
abrir
GitHub PoC
Controlled NGINX HTTP/2 frame injection lab for CVE-2026-42926 patch validation and defensive research
CVE-2026-42926MEDIUM06 jun 2026
NGINX ngx_http_proxy_v2_module vulnerability
33RISCO
abrir
GitHub PoC
TechWithOrgito/CVE-2025-55182-Researching-process
CVE-2025-55182CRITICALsob ataqueransomware06 jun 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC
CVE-2026-23744 Reverse shell
CVE-2026-23744CRITICAL06 jun 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
GitHub PoC7
CVE-2025-57819 -> rce
CVE-2025-57819CRITICALsob ataque06 jun 2026
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir
GitHub PoC
Apache ActiveMQ RCE via Jolokia vulnerability analysis and reproduction notes
CVE-2026-34197HIGHsob ataque06 jun 2026
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
100RISCO
abrir
GitHub PoC
t1ckprivate/CVE-2022-0847-Dirty-Pipe
CVE-2022-0847HIGHsob ataque06 jun 2026
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
anteriorpágina 73 / 508próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.