Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
79.980 exploits
GitHub PoC
Unauthenticated time-based blind SQL injection exploit for CMS Made Simple ≤ 2.2.9 (CVE-2019-9053), ported to Python 3.
CVE-2019-905325 jun 2026
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISCO
abrir
GitHub PoC1
VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password hash, and escalating to root via SUID find.
CVE-2018-7600CRITICALsob ataqueransomware25 jun 2026
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
GitHub PoC1
SCAN END POC THE CVE-2024-4367
CVE-2024-4367MEDIUM25 jun 2026
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISCO
abrir
VulnCheck XDB
local
CVE-2025-61155MEDIUM25 jun 2026
The GameDriverX64.sys kernel-mode anti-cheat driver (v7.23.4.7 and earlier) contains an access control vulnerability in
33RISCO
abrir
VulnCheck XDB
initial-access
CVE-2023-20198CRITICALsob ataque25 jun 2026
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISCO
abrir
GitHub PoC
POC of CVE-2026-53075
CVE-2026-53075HIGH25 jun 2026
ppp: require CAP_NET_ADMIN in target netns for unattached ioctls
41RISCO
abrir
GitHub PoC
CVE-2026-55584 — phpSysInfo IP Allowlist Bypass
CVE-2026-55584HIGH25 jun 2026
phpSysInfo: IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP headers
41RISCO
abrir
GitHub PoC
7whyex/CVE-2026-45321-Tanstack
CVE-2026-45321CRITICALsob ataqueransomware25 jun 2026
Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
78RISCO
abrir
GitHub PoC1
CVE-2026-7574
CVE-2026-7574HIGH25 jun 2026
Anthropic Claude Desktop Cowork VM Image Contents Not Validated Before Use
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-22205CRITICALsob ataqueransomware24 jun 2026
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISCO
abrir
GitHub PoC
CVE-2026-48908 - SP Page Builder Joomla Unauthenticated RCE
CVE-2026-48908CRITICAL24 jun 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
68RISCO
abrir
GitHub PoC1
CVE-2026-49777, CVE-2026-10735
CVE-2026-49777CRITICAL24 jun 2026
WordPress Product Slider Pro for WooCommerce plugin < 3.5.4 - Backdoor vulnerability
63RISCO
abrir
GitHub PoC
Joapath/CVE-2021-42013
CVE-2021-42013CRITICALsob ataqueransomware24 jun 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC
CVE-2025-57819 FreePBX SQLi RCE PoC
CVE-2025-57819CRITICALsob ataque24 jun 2026
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir
GitHub PoC
Khai thác lỗ hổng bảo mật CVE-2025-55182
CVE-2025-55182CRITICALsob ataqueransomware24 jun 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
GitHub PoC1
CVE-2026-8461 - Draft
CVE-2026-8461HIGH24 jun 2026
Heap out-of-bounds write via odd slice_height in FFmpeg MagicYUV decoder
41RISCO
abrir
GitHub PoC63
CVE-2026-45504 Microsoft Exchange File Read
CVE-2026-45504HIGH24 jun 2026
Microsoft Exchange Server Elevation of Privilege Vulnerability
41RISCO
abrir
GitHub PoC
ROOT TOOL
CVE-2022-37706HIGH24 jun 2026
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-57819CRITICALsob ataque24 jun 2026
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISCO
abrir
GitHub PoC16
Y5neKO/CVE-2026-8461-EXP
CVE-2026-8461HIGH24 jun 2026
Heap out-of-bounds write via odd slice_height in FFmpeg MagicYUV decoder
41RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALsob ataqueransomware24 jun 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALsob ataqueransomware24 jun 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2025-58034MEDIUMsob ataque24 jun 2026
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vul
90RISCO
abrir
GitHub PoC3
Unauthenticated Account Takeover via Weak Password Reset Validation via 'reset_user_id' Parameter | Unauthenticated Privilege Escalation via Weak Password Reset Validation via 'reset_activation_code' Leading to Account Takeover
CVE-2026-12416CRITICAL24 jun 2026
Invoice Generator <= 1.0.0 - Unauthenticated Account Takeover via Weak Password Reset Validation via 'reset_user_id' Parameter
48RISCO
abrir
GitHub PoC
Lỗ hổng FORTIWEB_CVE-2025-64446 & CVE-2025-58034
CVE-2025-64446CRITICALsob ataque24 jun 2026
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISCO
abrir
GitHub PoC
Unauthenticated RCE PoC for CVE-2026-48908 SP Page Builder (Joomla) arbitrary file upload and remote code execution exploit with mass scaning support.
CVE-2026-48908CRITICAL24 jun 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
68RISCO
abrir
GitHub PoC1
CVE-2026-39275 - Stored XSS Leading to Account Takeover in Cockpit CMS
CVE-2026-39275MEDIUM24 jun 2026
Cross Site Scripting vulnerability in Cockpit CMS v.2.13.5 and before allows a remote attacker to execute arbitrary code
33RISCO
abrir
GitHub PoC
CVE-2021-22205 - GitLab Unauthenticated Remote Code Execution
CVE-2021-22205CRITICALsob ataqueransomware24 jun 2026
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISCO
abrir
GitHub PoC
CVE-2026-31431 getroot from a Turkish Cryptominer
CVE-2026-31431HIGHsob ataque24 jun 2026
crypto: algif_aead - Revert to operating out-of-place
100RISCO
abrir
GitHub PoC2
CVE-2026-48908
CVE-2026-48908CRITICAL24 jun 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
68RISCO
abrir
anteriorpágina 83 / 2.666próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.