Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.231exploits catalogados
35.420CVEs com exploração pública
24.695testados em laboratório
22.266 exploits
Referência
CVE-2018-25287
Drive Power Manager 1.10 Denial of Service via Name Field
33RISCO
abrir
Referência
CVE-2018-25286
Easy PhotoResQ 1.0 Buffer Overflow Denial of Service
33RISCO
abrir
Referência
CVE-2018-25285
Fathom 2.4 Denial of Service via Authorization Code Buffer Overflow
33RISCO
abrir
Referência
CVE-2018-25284
HD Tune Pro 5.70 Denial of Service via Options Dialog
33RISCO
abrir
Referência
CVE-2018-25283
iSmartViewPro 1.5 Buffer Overflow via SavePath Parameter
41RISCO
abrir
Referência
CVE-2018-25282
Nmap 7.70 Denial of Service via XML Entity Expansion
33RISCO
abrir
Referência
CVE-2018-25281
iCash 7.6.5 Denial of Service via Connect to Server
33RISCO
abrir
Referência
CVE-2018-25280
Infiltrator Network Security Scanner 4.6 Denial of Service
33RISCO
abrir
Referência
CVE-2018-25279
jiNa OCR Image to Text 1.0 Denial of Service via PNG
33RISCO
abrir
Referência
CVE-2018-25278
PicaJet FX 2.6.5 Denial of Service via Registration Fields
33RISCO
abrir
Referência
CVE-2018-0752
The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709
23RISCO
abrir
Referência
CVE-2018-0823
The Named Pipe File System in Windows 10 version 1709 and Windows Server, version 1709 allows an elevation of privilege
23RISCO
abrir
Referência
CVE-2026-5806
code-projects Easy Blog Site update.php cross site scripting
33RISCO
abrir
Referência
CVE-2026-5805
code-projects Easy Blog Site contact_us.php sql injection
33RISCO
abrir
Referência
CVE-2026-5803
bigsk1 openai-realtime-ui API Proxy Endpoint server.js server-side request forgery
33RISCO
abrir
Referência
CVE-2026-5802
idachev mcp-javadc HTTP os command injection
33RISCO
abrir
Referência
CVE-2026-4338
ActivityPub Routing < 8.0.2 - Unauthenticated Drafts/Scheduled/Pending Posts Disclosure
41RISCO
abrir
Referência
CVE-2026-5741
suvarchal docker-mcp-server HTTP index.ts pull_image os command injection
33RISCO
abrir
Referência
CVE-2018-0838
Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remot
35RISCO
abrir
Referência
CVE-2018-0860
Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remot
35RISCO
abrir
Referência
CVE-2018-25240
Watchr 1.1.0.0 Denial of Service via Search
33RISCO
abrir
Referência
CVE-2018-25239
Smart VPN 1.1.3.0 Denial of Service via Search
33RISCO
abrir
Referência
CVE-2018-25238
VSCO 1.1.1.0 Denial of Service via Search
33RISCO
abrir
Referência
CVE-2016-20061
sheed AntiVirus 2.3 Unquoted Service Path Privilege Escalation
41RISCO
abrir
Referência
CVE-2016-20060
Hotspot Shield 6.0.3 Unquoted Service Path Privilege Escalation
41RISCO
abrir
Referência
CVE-2016-20059
IObit Malware Fighter 4.3.1 Unquoted Service Path Privilege Escalation
41RISCO
abrir
Referência
CVE-2016-20058
Netgate AMITI Antivirus build 23.0.305 Unquoted Service Path Privilege Escalation
41RISCO
abrir
Referência
CVE-2016-20057
NETGATE Registry Cleaner build 16.0.205 Unquoted Service Path Privilege Escalation
41RISCO
abrir
Referência
CVE-2016-20052
Snews CMS 1.7 Unrestricted File Upload via snews_files
48RISCO
abrir
Referência
CVE-2016-20051
Snews CMS 1.7 Cross-Site Request Forgery via changeup
33RISCO
abrir
anteriorpágina 438 / 743próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.