Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
22.721 exploits
ReferênciaVexDay Proof
ForumApp 3.3 - Remote Database Disclosure
CVE-2008-6147webappsasp
ForumApp 3.3 stores sensitive information under the web root with insufficient access control, which allows remote attac
23RISCO
abrir
Referência
CVE-2020-25223
CVE-2020-25223CRITICALsob ataque
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511
100RISCO
abrir
ReferênciaVexDay Proof
KsIRC 1.3.12 - 'PRIVMSG' Remote Buffer Overflow (PoC)
CVE-2006-6811doslinux
KsIRC 1.3.12 allows remote attackers to cause a denial of service (crash) via a long PRIVMSG string when connecting to a
28RISCO
abrir
ReferênciaVexDay Proof
Butterfly ORGanizer 2.0.0 - Arbitrary Delete (Category/Account)
CVE-2008-7181webappsphp
Butterfly Organizer 2.0.0 allows remote attackers to (1) delete arbitrary categories via a modified tablehere parameter
23RISCO
abrir
ReferênciaVexDay Proof
EgyPlus 7ml 1.0.1 - Authentication Bypass
CVE-2009-2167webappsphp
Multiple SQL injection vulnerabilities in cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier, when magic_quo
23RISCO
abrir
Referência
CVE-2026-10236
SourceCodester Water Billing Management System User Management Endpoint Users.php save improper authorization
33RISCO
abrir
Referência
CVE-2019-15107
CVE-2019-15107CRITICALsob ataqueransomware
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
Referência
CVE-2019-15107
CVE-2019-15107CRITICALsob ataqueransomware
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
ReferênciaVexDay Proof
Comdev News Publisher 4.1.2 - SQL Injection
CVE-2008-1872webappsphp
SQL injection vulnerability in home.news.php in Comdev News Publisher 4.1.2 allows remote attackers to execute arbitrary
23RISCO
abrir
Referência
CVE-2026-23760
CVE-2026-23760CRITICALsob ataqueransomware
SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API
100RISCO
abrir
Referência
CVE-2026-9377
SourceCodester SUP Online Shopping productedit.php cross site scripting
33RISCO
abrir
ReferênciaVexDay Proof
XPOZE Pro 3.05 - 'reed' SQL Injection
CVE-2008-1874webappsphp
SQL injection vulnerability in account/user/mail.html in Xpoze Pro 3.05 and earlier allows remote authenticated users to
23RISCO
abrir
ReferênciaVexDay Proof
Xine-Lib 1.1.12 - NSF demuxer Stack Overflow (PoC)
CVE-2008-1878doslinux
Stack-based buffer overflow in the demux_nsf_send_chunk function in src/demuxers/demux_nsf.c in xine-lib 1.1.12 and earl
28RISCO
abrir
ReferênciaVexDay Proof
VideoLAN VLC Media Player 0.8.6e - Subtitle Parsing Local Buffer Overflow
CVE-2008-1881localwindows
Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle.c) in VLC 0.8.6e allows remote attackers to
28RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component xsstream-dm 0.01b - SQL Injection
CVE-2008-2454webappsphp
SQL injection vulnerability in the xsstream-dm (com_xsstream-dm) component 0.01 Beta for Joomla! allows remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
KwsPHP 1.3.456 Module Galerie - 'id_gal' SQL Injection
CVE-2008-6197webappsphp
SQL injection vulnerability in index.php in the galerie module for KwsPHP 1.3.456 allows remote attackers to execute arb
23RISCO
abrir
Referência
CVE-2019-10068
CVE-2019-10068CRITICALsob ataque
An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions
100RISCO
abrir
Referência
CVE-2026-7228
SourceCodester Pizzafy Ecommerce System ajax.php get_cart_count sql injection
33RISCO
abrir
Referência
CVE-2019-15637
Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to informat
46RISCO
abrir
Referência
CVE-2012-1125
Unrestricted file upload vulnerability in uploadify/scripts/uploadify.php in the Kish Guest Posting plugin before 1.2 fo
28RISCO
abrir
ReferênciaVexDay Proof
LaserNet CMS 1.5 - SQL Injection
CVE-2008-1913webappsphp
SQL injection vulnerability in index.php in Lasernet CMS 1.5 and 1.11, when magic_quotes_gpc is disabled, allows remote
23RISCO
abrir
Referência
CVE-2020-17530
CVE-2020-17530CRITICALsob ataque
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISCO
abrir
Referência
CVE-2020-5847
CVE-2020-5847CRITICALsob ataque
Unraid through 6.8.0 allows Remote Code Execution.
100RISCO
abrir
ReferênciaVexDay Proof
Web Calendar 4.1 - Blind SQL Injection
CVE-2008-1954webappsphp
SQL injection vulnerability in one_day.php in Web Calendar Pro 4.1 and earlier allows remote attackers to execute arbitr
23RISCO
abrir
Referência
CVE-2019-7609
CVE-2019-7609CRITICALsob ataque
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISCO
abrir
Referência
CVE-2019-15889
The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by t
53RISCO
abrir
ReferênciaVexDay Proof
TR News 2.1 - 'nb' SQL Injection
CVE-2008-1957webappsphp
SQL injection vulnerability in news.php in Tr Script News 2.1 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
ReferênciaVexDay Proof
SFS EZ Webstore - 'where' SQL Injection
CVE-2008-6242webappsphp
SQL injection vulnerability in SearchResults.php in Scripts For Sites (SFS) EZ e-store allows remote attackers to execut
23RISCO
abrir
Referência
CVE-2026-17434
nanocoai NanoClaw add_mcp_server request.ts handleAddMcpServer improper authorization
33RISCO
abrir
Referência
CVE-2026-65711
sysPass 3.2.11 Authenticated OS Command Injection via Backup Path
41RISCO
abrir

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.