Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
15.228 exploits
GitHub PoC
rootdirective-sec/CVE-2026-8206-Lab
CVE-2026-8206CRITICAL05 jun 2026
Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'
48RISCO
abrir
GitHub PoC4
CVE-2026-49975 HTTP/2 Stream Amplification — Docker PoC with Web Console
CVE-2026-49975HIGH05 jun 2026
Apache HTTP Server: mod_http2 denial of service
53RISCO
abrir
GitHub PoC
ARMember Premium <= 7.3.1 Full Admin Account Takeover
CVE-2026-5076CRITICAL05 jun 2026
ARMember Premium <= 7.3.1 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation
48RISCO
abrir
GitHub PoC1
CVE-2026-48866 — Gravity Forms <= 2.10.0.1 Arbitrary File Deletion via Path Traversal (CVSS 9.6)
CVE-2026-48866CRITICAL05 jun 2026
WordPress Gravity Forms plugin <= 2.10.0.1 - Arbitrary File Deletion vulnerability
48RISCO
abrir
GitHub PoC
PoC for CVE-2026-26179 / ZDI-26-276, my very own Secure Kernel bug
CVE-2026-26179HIGH05 jun 2026
Windows Kernel Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC66
Safely detect whether a UniFi OS Server is vulnerable to CVE-2026-34908
CVE-2026-34908CRITICALsob ataque05 jun 2026
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS de
100RISCO
abrir
GitHub PoC29
HTTP/2 Bomb PoC — CVE-2026-49975 (HPACK indexed reference bomb + flow-control stall)
CVE-2026-49975HIGH04 jun 2026
Apache HTTP Server: mod_http2 denial of service
53RISCO
abrir
GitHub PoC
CVE-2026-50142 — Heap allocation vulnerability in libheif HEIF sequence parser
CVE-2026-50142HIGH04 jun 2026
libheif: unbounded heap allocation in HEIF sequence parser (stsz fixed-size mode missing bound check)
41RISCO
abrir
GitHub PoC
CVE-2026-5076 — ARMember Premium <= 7.3.1 Insecure Password Reset Mechanism → Full Admin Account Takeover | Proof of Concept
CVE-2026-5076CRITICAL04 jun 2026
ARMember Premium <= 7.3.1 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation
48RISCO
abrir
GitHub PoC10
strivepan/ActiveMQ-cve-2026-42588-scanner-gui
CVE-2026-42588HIGH04 jun 2026
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnector
41RISCO
abrir
GitHub PoC1
Detect-only scanner for CVE-2026-42945 (NGINX Rift), a heap overflow in ngx_http_rewrite_module. Version detection + nginx.conf pattern analysis. Python 3 stdlib-only, no network calls.
CVE-2026-42945CRITICAL04 jun 2026
NGINX ngx_http_rewrite_module vulnerability
60RISCO
abrir
GitHub PoC
0-Click RCE Android Adb TLS Wireless Debugging
CVE-2026-0073HIGH04 jun 2026
In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic err
41RISCO
abrir
GitHub PoC
PoC CVE-2026-8732 (WP Maps Pro <= 6.1.0)
CVE-2026-8732CRITICAL04 jun 2026
WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action
68RISCO
abrir
GitHub PoC
rootdirective-sec/CVE-2026-34234-Lab
CVE-2026-34234CRITICAL04 jun 2026
CtrlPanel: Unauthenticated RCE using installer script
48RISCO
abrir
GitHub PoC1
horrister/log4shell-cve-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware04 jun 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
GitHub PoC
YellowKey | BitLocker Bypass Vulnerability (CVE-2026-45585)
CVE-2026-45585MEDIUM04 jun 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RISCO
abrir
GitHub PoC1
horrister/solarwinds-sunburst-cve-2020-10148
CVE-2020-10148CRITICALsob ataque04 jun 2026
SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
100RISCO
abrir
GitHub PoC
Dhananjayasj/CVE-2024-1698-NotificationX-WordPress-Plugin-SQL-Injection-to-Admin-Credential-Extraction
CVE-2024-1698CRITICAL04 jun 2026
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RISCO
abrir
GitHub PoC
CVE-2026-45247 - Draft
CVE-2026-45247CRITICALsob ataque04 jun 2026
Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection
83RISCO
abrir
GitHub PoC
CVE-2026-23744
CVE-2026-23744CRITICAL04 jun 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISCO
abrir
GitHub PoC
Safe read-only version checker + Sigma rule for Redis CVE-2026-23479 (authenticated use-after-free → RCE). Find exposed instances, patch left-of-boom. By DugganUSA.
CVE-2026-23479HIGH04 jun 2026
redis-server use-after-free in unblock client flow may allow remote code execution
41RISCO
abrir
GitHub PoC2
Proof of Concept (PoC) exploit for CVE-2026-6815: Authenticated Path Traversal & Arbitrary File Write in Casdoor (< 3.54.1) leading to RCE/DoS.
CVE-2026-6815MEDIUM04 jun 2026
CVE-2026-6815
33RISCO
abrir
GitHub PoC
HTB Facts is a Easy Linux box featuring Camaleon CMS and MinIO. Gain admin access via open registration and a mass assignment vulnerability, then extract MinIO credentials from admin settings. Use CVE-2024-46987 path traversal to steal an SSH private key, crack its passphrase, and escalate to root by abusing sudo permissions on facter via GTFOBins.
CVE-2024-46987HIGH04 jun 2026
Arbitrary path traversal in Camaleon CMS
61RISCO
abrir
GitHub PoC13
Attack surface in the real-world environment of CVE-2026-41096
CVE-2026-41096CRITICAL04 jun 2026
Windows DNS Client Remote Code Execution Vulnerability
48RISCO
abrir
GitHub PoC
CVE-2026-35904 / CVE-2026-35905 / CVE-2026-35906 — Unauth RCE, Hardcoded Root Creds & Telnet Enable in T3 Technology CPE
CVE-2026-35904CRITICAL04 jun 2026
Incorrect access control in the web management interface of T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, an
48RISCO
abrir
GitHub PoC
Improved Metasploit module for CVE-2013-6117 (Dahua DVR authentication bypass)
CVE-2013-611704 jun 2026
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive informatio
50RISCO
abrir
GitHub PoC
CVE-2026-23631-Draft
CVE-2026-23631MEDIUM04 jun 2026
redis-server Lua use-after-free may allow remote code execution
33RISCO
abrir
GitHub PoC
Piotnet Forms Pro <= 2.1.40 - Unauthenticated Arbitrary File Upload → RCE
CVE-2026-4883CRITICAL04 jun 2026
Piotnet Forms <= 2.1.40 - Unauthenticated Arbitrary File Upload via Form File Upload
48RISCO
abrir
GitHub PoC6
PoC de CVE-2026-49975 (HTTP/2 Bomb): DoS remoto contra servidores web con HTTP/2 por defecto.
CVE-2026-49975HIGH03 jun 2026
Apache HTTP Server: mod_http2 denial of service
53RISCO
abrir
GitHub PoC1
PoC of CVE-2026-49943
CVE-2026-49943MEDIUM03 jun 2026
CZ.NIC BIRD Internet Routing Daemon through 2.19.0 contains a stack-based buffer overflow in the BGP AS_PATH mask matchi
33RISCO
abrir
anteriorpágina 75 / 508próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.