Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
79.980 exploits
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL04 jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
GitHub PoC1
caterscam/CVE-2026-5524-PoC
CVE-2026-5524CRITICAL04 jul 2026
Divi Form Builder <= 5.1.8 - Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via 'acceptFileTypes' Parameter
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-48907CRITICALsob ataque04 jul 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISCO
abrir
GitHub PoC
Exploit for MCPJam Inspector - Remote Code Execution (CVE-2026-23744)
CVE-2026-23744CRITICAL04 jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
GitHub PoC
Casdoor version 2.362.0
CVE-2026-9090CRITICAL04 jul 2026
CVE-2026-9090
48RISCO
abrir
GitHub PoC2
PoC for CVE-2026-54415 — Azuriom CMS (<1.2.11) Broken Access Control → account takeover
CVE-2026-54415HIGH04 jul 2026
Broken Access Control in Azuriom CMS Server Routes Allows Account Takeover
41RISCO
abrir
GitHub PoC
Technical troubleshooting repository for fixing infinite rendering vulnerability loops and resource exhaustion threats under CVE-2026-23869 cleanly.
CVE-2026-23869HIGH04 jul 2026
A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-5524CRITICAL04 jul 2026
Divi Form Builder <= 5.1.8 - Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via 'acceptFileTypes' Parameter
48RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALsob ataque04 jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir
GitHub PoC
CVE-2026-59243 — Apache Airflow FAB Auth Manager JWT signature bypass (embargoed until Apache advisory)
CVE-2026-59243CRITICAL04 jul 2026
Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)
48RISCO
abrir
GitHub PoC5
Apache ActiveMQ Classic RCE research: CVE-2026-34197 / CVE-2026-42588 bypass chain + hardened-6.2.6 audit findings + Crowdfense comparison
CVE-2026-34197HIGHsob ataque04 jul 2026
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2024-21413CRITICALsob ataque04 jul 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2026-56290CRITICAL04 jul 2026
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
75RISCO
abrir
GitHub PoC
Script de python para Webmin 1.996
CVE-2022-3644604 jul 2026
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
60RISCO
abrir
GitHub PoC2
CVE-2026-22874 writeup: incomplete SSRF allow-list in Gitea webhook/migration (IPv6 transition and cloud metadata). Fixed in Gitea 1.26.3.
CVE-2026-22874CRITICAL04 jul 2026
Gitea webhook and migration allow-list filtering permits SSRF
48RISCO
abrir
GitHub PoC3
CVE-2026-54998 RCE Exploit
CVE-2026-54998HIGH04 jul 2026
Microsoft Exchange Online Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC3
📤 Mass exploitation framework for CVE-2026-56290 — Page Builder CK Joomla unauthenticated file upload to RCE
CVE-2026-56290CRITICAL04 jul 2026
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
75RISCO
abrir
GitHub PoC19
CVE-2026-46242
CVE-2026-46242HIGH04 jul 2026
eventpoll: fix ep_remove struct eventpoll / struct file UAF
41RISCO
abrir
GitHub PoC4
PoC for CVE-2026-53360: guest-triggered heap out-of-bounds read/write in KVM SEV-SNP Page State Change (PSC) handling.
CVE-2026-53360HIGH04 jul 2026
KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use
41RISCO
abrir
GitHub PoC30
Static config scanner that flags nginx configs vulnerable to the complex_value two-pass capture-clobbering bug (regex map + regex capture → heap overflow / info leak).
CVE-2026-42533CRITICAL04 jul 2026
NGINX Map directive and Regex matching vulnerability
48RISCO
abrir
GitHub PoC
Python & template nuclei
CVE-2026-48907CRITICALsob ataque04 jul 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISCO
abrir
GitHub PoC1
💉 Blind SQL Injection → RCE exploit for Control Web Panel (CWP) ≤ 0.9.8.1224 — userRes POST → INTO DUMPFILE → cwpsvc shell
CVE-2026-57517CRITICAL04 jul 2026
Control Web Panel < 0.9.8.1225 Blind SQL Injection via userRes Parameter
48RISCO
abrir
GitHub PoC4
Read-only vulnerability scanner for CVE-2026-49049 — Helix3 Joomla plugin unauthenticated AJAX handler
CVE-2026-49049HIGH04 jul 2026
Joomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler
56RISCO
abrir
GitHub PoC1
CVE-2026-34038: Authenticated Remote Command Injection in Coolify
CVE-2026-34038CRITICAL04 jul 2026
Coolify authenticated remote command injection leading to RCE and secret exfiltration
48RISCO
abrir
GitHub PoC
Static config scanner that flags nginx configs vulnerable to the complex_value two-pass capture-clobbering bug (regex map + regex capture → heap overflow / info leak).
CVE-2026-42533CRITICAL04 jul 2026
NGINX Map directive and Regex matching vulnerability
48RISCO
abrir
GitHub PoC
PoC of Langflow CVE-2026-33017
CVE-2026-33017CRITICALsob ataque04 jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISCO
abrir
GitHub PoC
Pardus Software Local Privilege Escalation PoC - affected from <= 1.0.4
CVE-2026-14459HIGH03 jul 2026
Argument Injection in TUBITAK BILGEM's pardus-software
41RISCO
abrir
GitHub PoC
CVE-2017-12615 - Apache Tomcat Remote Code Execution (RCE)
CVE-2017-12615HIGHsob ataqueransomware03 jul 2026
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISCO
abrir
GitHub PoC4
# CVE-2026-28995 Proof of Concept for CVE-2026-28995 — Path Traversal vulnerability in App Intents on iOS 26.4.2 and below.
CVE-2026-28995HIGH03 jul 2026
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 an
41RISCO
abrir
GitHub PoC
Walkthrough and PoC of File path traversal vulnerability(CVE-2026-36851) for UnPoller 2.33.0
CVE-2026-36851HIGH03 jul 2026
Path traversal vulnerability in UnPoller 2.33.0 password field allows arbitrary file read and network exfiltration.
41RISCO
abrir
anteriorpágina 75 / 2.666próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.