Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
79.980 exploits
GitHub PoC
HTB_Nexus Penetration Test Report – Comprehensive security assessment documenting credential leakage from Gitea, CVE-2026-38526 exploitation in Krayin CRM, and privilege escalation via Gitea template sync directory traversal. Mapped to MITRE ATT&CK and NSA D3FEND frameworks with actionable remediation roadmap and full evidence appendix.
CVE-2026-38526CRITICAL06 jul 2026
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RISCO
abrir
GitHub PoC7
jaf0rk/CVE-2026-14382
CVE-2026-14382CRITICAL06 jul 2026
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-0920CRITICAL06 jul 2026
LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter
48RISCO
abrir
GitHub PoC1
Exploitability PoC for CVE-2026-49352 (9router Hardcoded JWT Secret Authentication Bypass)
CVE-2026-49352CRITICAL06 jul 2026
9Router: Hardcoded Default fallback JWT Secret Allows Authentication Bypass
48RISCO
abrir
GitHub PoC
Exploit for Authenticated Remote Code Execution (RCE) in Krayin CRM v2.2.x (CVE-2026-38526)
CVE-2026-38526CRITICAL06 jul 2026
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RISCO
abrir
GitHub PoC
Next.js / RSC - Unauthenticated RCE (React2Shell) (CVE-2025-55182)
CVE-2025-55182CRITICALsob ataqueransomware06 jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-23550CRITICAL05 jul 2026
WordPress Modular DS plugin <= 2.5.1 - Privilege Escalation vulnerability
68RISCO
abrir
GitHub PoC4
Pre-auth path traversal to arbitrary file delete in Avada (Fusion) Builder <= 3.15.3 leading to RCE (CVSS 9.1)
CVE-2026-8713CRITICAL05 jul 2026
Avada (Fusion) Builder <= 3.15.3 - Unauthenticated Arbitrary File Deletion via Form Entry Value
63RISCO
abrir
GitHub PoC1
Offline jQuery CVE-2020-11023 remediation kit for legacy Spring/JSP - Node.js built-ins only (no npm, no internet)
CVE-2020-11023MEDIUMsob ataque05 jul 2026
Potential XSS vulnerability in jQuery
85RISCO
abrir
GitHub PoC
Pre-auth Local File Inclusion in WP User Manager <= 2.9.17 via path traversal in tab parameter (CVSS 7.5)
CVE-2026-9290HIGH05 jul 2026
WP User Manager <= 2.9.17 - Unauthenticated Path Traversal to Local File Inclusion via 'tab' Query Parameter
56RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-48939CRITICALsob ataque05 jul 2026
Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15
98RISCO
abrir
GitHub PoC
MESLIMOHAMEDM22005188/path-traversal-CVE-2026-14628
CVE-2026-14628MEDIUM05 jul 2026
NousResearch hermes-agent Live Webhook Endpoint base.py extract_media path traversal
33RISCO
abrir
GitHub PoC
 CVE-2026-49049 - Unauthenticated File Deletion, Arbitrary Write & XSS Injection for Helix3 Joomla Extension
CVE-2026-49049HIGH05 jul 2026
Joomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler
56RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-20896CRITICAL05 jul 2026
Gitea Docker image trusts spoofable reverse-proxy headers by default
63RISCO
abrir
GitHub PoC6
Public PoC and detector for CVE-2026-20896 ("Gitea Docker: One Header, Any User")
CVE-2026-20896CRITICAL05 jul 2026
Gitea Docker image trusts spoofable reverse-proxy headers by default
63RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-48908CRITICAL05 jul 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
68RISCO
abrir
GitHub PoC1
CVE-2018-10933 - libssh Authentication Bypass
CVE-2018-10933CRITICAL05 jul 2026
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC2
Product Video Gallery for Woocommerce <= 1.5.1.8 - Authenticated Stored Cross-Site Scripting Proof of Concept
CVE-2026-10104MEDIUM05 jul 2026
Product Video Gallery for Woocommerce <= 1.5.1.8 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via custom_thumbnail Parameter
33RISCO
abrir
GitHub PoC
Eliot-code/CVE-2026-22874-PoC
CVE-2026-22874CRITICAL05 jul 2026
Gitea webhook and migration allow-list filtering permits SSRF
48RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2026-8713CRITICAL05 jul 2026
Avada (Fusion) Builder <= 3.15.3 - Unauthenticated Arbitrary File Deletion via Form Entry Value
63RISCO
abrir
GitHub PoC2
Pre-auth arbitrary file upload RCE exploit for iCagenda Joomla extension < 4.0.8 (CVSS 10.0)
CVE-2026-48939CRITICALsob ataque05 jul 2026
Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15
98RISCO
abrir
GitHub PoC
Research and hands-on PoC of Spectre Variant 2 (CVE-2017-5715), a hardware side-channel vulnerability exploiting CPU speculative execution and branch prediction. Includes lab setup, vulnerability identification, exploit walkthrough, cache-timing analysis, demo video, and mitigation strategies.
CVE-2017-5715MEDIUM05 jul 2026
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
55RISCO
abrir
GitHub PoC1
QNAP password reset URL injection writeup + PoC.
CVE-2025-59382LOW05 jul 2026
QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances)
28RISCO
abrir
GitHub PoC6
Epson Printer RAW Protocol Exploit Framework
CVE-2026-39047HIGH05 jul 2026
Buffer Overflow vulnerability in EPSON L14150 FL27PB allows a remote attacker to execute arbitrary code via the RAW Prin
21RISCO
abrir
GitHub PoC
This repository contains a professional bug bounty report demonstrating the successful exploitation of a Blind SSRF vulnerability that reached an internal CGI endpoint vulnerable to Shellshock (CVE-2014-6271). Remote command execution was confirmed using an out-of-band (OAST) DNS callback, showcasing the complete attack chain, technical analysis.
CVE-2014-6271CRITICALsob ataque05 jul 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC
Proof of Concept (PoC) for CVE-2026-49975 – HTTP/2 server memory exhaustion attack leveraging HPACK amplification and connection retention (HTTP/2 Slowloris).
CVE-2026-49975HIGH05 jul 2026
Apache HTTP Server: mod_http2 denial of service
53RISCO
abrir
GitHub PoC
bayu06802/CVE-2026-48908
CVE-2026-48908CRITICAL05 jul 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
68RISCO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALsob ataque05 jul 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
GitHub PoC5
Apache ActiveMQ Classic RCE research: CVE-2026-34197 / CVE-2026-42588 bypass chain + hardened-6.2.6 audit findings + Crowdfense comparison
CVE-2026-34197HIGHsob ataque04 jul 2026
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
100RISCO
abrir
GitHub PoC
Technical troubleshooting repository for fixing infinite rendering vulnerability loops and resource exhaustion threats under CVE-2026-23869 cleanly.
CVE-2026-23869HIGH04 jul 2026
A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-
41RISCO
abrir
anteriorpágina 74 / 2.666próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.