Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.302exploits catalogados
35.469CVEs com exploração pública
24.695testados em laboratório
22.301 exploits
Referência
CVE-2018-25230
Free IP Switcher 3.1 Denial of Service via Computer Name
33RISCO
abrir
Referência
CVE-2018-25229
BulletProof FTP Server 2019.0.0.50 Denial of Service via SMTP
33RISCO
abrir
Referência
CVE-2018-25228
NetSetMan 4.7.1 Workgroup Buffer Overflow Denial of Service
33RISCO
abrir
Referência
CVE-2018-25227
Valentina Studio 9.0.4 Denial of Service via Host Parameter
33RISCO
abrir
Referência
CVE-2018-25226
FTPShell Server 6.83 Denial of Service via Account Name
33RISCO
abrir
Referência
CVE-2018-9206
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISCO
abrir
Referência
CVE-2018-9238
proberv.php in Yahei-PHP Proberv 0.4.7 has XSS via the funName parameter.
23RISCO
abrir
Referência
CVE-2018-9515
In sdcardfs_create and sdcardfs_mkdir of inode.c, there is a possible memory corruption due to improper locking. This co
23RISCO
abrir
Referência
CVE-2026-12219
Yealink SIP-T46U Web FastCGI Service start mod_diagnose.CommandShellByType command injection
33RISCO
abrir
Referência
CVE-2026-12218
Yealink SIP-T46U Web FastCGI Service beforewifitest StartReportInformation stack-based overflow
41RISCO
abrir
ReferênciaVexDay Proof
PHP-Nuke Module books SQL - 'cid' SQL Injection
CVE-2008-0827webappsphp
SQL injection vulnerability in the Books module of PHP-Nuke allows remote attackers to execute arbitrary SQL commands vi
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component Rapid Recipe 1.6.5 - SQL Injection
CVE-2008-0831webappsphp
Multiple SQL injection vulnerabilities in the Rapid Recipe (com_rapidrecipe) 1.6.5 and earlier component for Joomla! all
23RISCO
abrir
Referência
CVE-2013-4950
Cross-site scripting (XSS) vulnerability in view.php in Machform 2 allows remote attackers to inject arbitrary web scrip
23RISCO
abrir
Referência
CVE-2026-58055
nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Length
33RISCO
abrir
ReferênciaVexDay Proof
Mambo Component Ricette 1.0 - SQL Injection
CVE-2008-0841webappsphp
SQL injection vulnerability in index.php in the Giorgio Nordo Ricette (com_ricette) 1.0 component for Joomla! and Mambo
23RISCO
abrir
Referência
CVE-2026-12813
activepieces File URL file.ts handleUrlFile server-side request forgery
33RISCO
abrir
ReferênciaVexDay Proof
jspwiki 2.4.104/2.5.139 - Multiple Vulnerabilities
CVE-2008-1229webappsjsp
Cross-site scripting (XSS) vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to inject ar
23RISCO
abrir
ReferênciaVexDay Proof
acronis pxe server 2.0.0.1076 - Directory Traversal / Null Pointer
CVE-2008-1410remotewindows
Directory traversal vulnerability in the PXE Server (pxesrv.exe) in Acronis Snap Deploy 2.0.0.1076 and earlier allows re
23RISCO
abrir
Referência
CVE-2013-5978
Multiple cross-site scripting (XSS) vulnerabilities in products.php in the Cart66 Lite plugin before 1.5.1.15 for WordPr
23RISCO
abrir
Referência
CVE-2026-12773
BerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authentication
33RISCO
abrir
Referência
CVE-2026-12772
BerriAI litellm PROXY_ADMIN database API Key Generator login_utils.py authenticate_user session expiration
33RISCO
abrir
Referência
CVE-2026-8256
Devs Palace ERP Online mr-save cross site scripting
33RISCO
abrir
Referência
CVE-2026-8255
Devs Palace ERP Online add_new_customer cross site scripting
33RISCO
abrir
Referência
CVE-2026-8251
Open5GS SMF npcf-handler.c update_authorized_pcc_rule_and_qos denial of service
33RISCO
abrir
ReferênciaVexDay Proof
phpAuction GPL Enhanced 2.51 - Multiple Remote File Inclusions
CVE-2008-1416webappsphp
Multiple PHP remote file inclusion vulnerabilities in PHPauction GPL 2.51 allow remote attackers to execute arbitrary PH
35RISCO
abrir
Referência
CVE-2011-1099
Multiple directory traversal vulnerabilities in FocalMedia.Net Quick Polls before 1.0.2 allow remote attackers to (1) re
23RISCO
abrir
Referência
CVE-2026-7810
UsamaK98 python-notebook-mcp server.py add_cell path traversal
33RISCO
abrir
Referência
CVE-2026-41471
Easy PayPal Events & Tickets < 1.4 Information Disclosure via QR Code Endpoint
41RISCO
abrir
Referência
CVE-2026-29514
NetBox 4.3.5 - 4.5.4 RCE via RenderTemplateMixin
41RISCO
abrir
Referência
CVE-2013-7091
Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zim
60RISCO
abrir
anteriorpágina 453 / 744próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.