Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.302exploits catalogados
35.469CVEs com exploração pública
24.695testados em laboratório
22.301 exploits
ReferênciaVexDay Proof
Alt-N MDaemon IMAP server 9.6.4 - 'FETCH' Remote Buffer Overflow
CVE-2008-1358remotewindows
Stack-based buffer overflow in the IMAP server in Alt-N Technologies MDaemon 9.6.4 allows remote authenticated users to
50RISCO
abrir
ReferênciaVexDay Proof
AuraCMS 2.2.1 - 'X-Forwarded-For' HTTP Header Blind SQL Injection
CVE-2008-1398webappsphp
SQL injection vulnerability in online.php in AuraCMS 2.0 through 2.2.1 allows remote attackers to execute arbitrary SQL
23RISCO
abrir
ReferênciaVexDay Proof
eXV2 Module Viso 2.0.4.3 - 'kid' SQL Injection
CVE-2008-1404webappsphp
SQL injection vulnerability in index.php in the Viso (Industry Book) 2.04 and 2.03 module for eXV2 allows remote attacke
23RISCO
abrir
Referência
CVE-2026-4935
SureTriggers < 1.1.23 – Unauthenticated SQLi
41RISCO
abrir
Referência
CVE-2023-42344
Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/
56RISCO
abrir
Referência
CVE-2013-6793
Multiple cross-site scripting (XSS) vulnerabilities in the Calendar module in Olat 7.8.0.1 (b20130821 N1) allow remote a
23RISCO
abrir
Referência
CVE-2023-46453
Certain GL.iNet devices with 4.x firmware allow authentication bypass (resulting in administrative control of the device
48RISCO
abrir
Referência
CVE-2013-6881
CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to execute arbitrary commands vi
28RISCO
abrir
Referência
CVE-2024-33288
Prison Management System Using PHP v1.0 was discovered to contain a SQL injection vulnerability via the username on the
56RISCO
abrir
Referência
CVE-2013-7025
Multiple cross-site scripting (XSS) vulnerabilities in ematStaticAlertTypes.jsp in the Alert Settings section in Dell So
23RISCO
abrir
ReferênciaVexDay Proof
RunCMS Module Photo 3.02 - 'cid' SQL Injection
CVE-2008-1551webappsphp
SQL injection vulnerability in viewcat.php in the Photo 3.02 module for RunCMS allows remote attackers to execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
TopperMod 2.0 - SQL Injection
CVE-2008-1554webappsphp
SQL injection vulnerability in account/index.php in TopperMod 2.0, when magic_quotes_gpc is disabled, allows remote atta
23RISCO
abrir
ReferênciaVexDay Proof
MPlayer 1.0 rc2 - 'sdpplin_parse()' Array Indexing Buffer Overflow (PoC)
CVE-2008-1558doslinux
Uncontrolled array index in the sdpplin_parse function in stream/realrtsp/sdpplin.c in MPlayer 1.0 rc2 allows remote att
28RISCO
abrir
Referência
CVE-2011-1496
tmux 1.3 and 1.4 does not properly drop group privileges, which allows local users to gain utmp group privileges via a f
23RISCO
abrir
Referência
CVE-2014-0160
CVE-2014-0160HIGHsob ataque
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
ReferênciaVexDay Proof
Microsoft Works 7 - 'WkImgSrv.dll' ActiveX Denial of Service (PoC)
CVE-2008-1898doswindows
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and
50RISCO
abrir
ReferênciaVexDay Proof
Microsoft Works 7 - 'WkImgSrv.dll' ActiveX Remote Buffer Overflow
CVE-2008-1898remotewindows
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and
50RISCO
abrir
Referência
CVE-2019-0731
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RISCO
abrir
Referência
CVE-2019-0796
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RISCO
abrir
Referência
CVE-2011-1565
Directory traversal vulnerability in IGSSdataServer.exe 9.00.00.11063 and earlier in 7-Technologies Interactive Graphica
50RISCO
abrir
Referência
CVE-2026-7200
SourceCodester Pharmacy Sales and Inventory System index.php cross site scripting
33RISCO
abrir
Referência
CVE-2026-7199
SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
33RISCO
abrir
Referência
CVE-2026-7196
CodeAstro Online Classroom guestdetails sql injection
33RISCO
abrir
Referência
CVE-2026-7194
SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
33RISCO
abrir
Referência
CVE-2026-7179
OSPG binwalk WinCE Extraction Plugin winceextract.py read_null_terminated_string path traversal
33RISCO
abrir
Referência
CVE-2026-7178
ChatGPTNextWeb NextChat Artifacts Endpoint route.ts storeUrl server-side request forgery
33RISCO
abrir
Referência
CVE-2026-7177
ChatGPTNextWeb NextChat route.ts proxyHandler server-side request forgery
33RISCO
abrir
Referência
CVE-2026-7160
Tenda HG3 formTracert command injection
41RISCO
abrir
Referência
CVE-2026-7159
douinc mkdocs-mcp-plugin server.py list_documents path traversal
33RISCO
abrir
Referência
CVE-2026-7158
dmitryglhf mcp-url-downloader server.py _validate_url_safe server-side request forgery
33RISCO
abrir
anteriorpágina 459 / 744próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.