Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.533exploits catalogados
35.607CVEs com exploração pública
24.695testados em laboratório
22.407 exploits
ReferênciaVexDay Proof
CoolPlayer 2.19 - '.Skin' Local Buffer Overflow
CVE-2008-5735localwindows
Stack-based buffer overflow in skin.c in CoolPlayer 2.17 through 2.19 allows remote attackers to execute arbitrary code
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Windows Media Player - '.wav' Remote Crash (PoC)
CVE-2008-5745doswindows
Integer overflow in quartz.dll in the DirectShow framework in Microsoft Windows Media Player (WMP) 9, 10, and 11, includ
28RISCO
abrir
ReferênciaVexDay Proof
Google Chrome - 'ChromeHTML://' Remote Parameter Injection
CVE-2008-5750remotewindows
Argument injection vulnerability in Microsoft Internet Explorer 8 beta 2 on Windows XP SP3 allows remote attackers to ex
28RISCO
abrir
ReferênciaVexDay Proof
Alstrasoft Web Email Script Enterprise - 'id' SQL Injection
CVE-2008-5751webappsphp
SQL injection vulnerability in index.php in AlstraSoft Web Email Script Enterprise (ESE) allows remote attackers to exec
23RISCO
abrir
Referência
CVE-2026-38764
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kerne
41RISCO
abrir
Referência
CVE-2026-16628
oclif JIT Plugin Entry child_process.exec os command injection
33RISCO
abrir
Referência
CVE-2026-12968
Product Addons – WowAddons < 1.6.15 - Unauthenticated Stored XSS via Arbitrary SVG Upload
41RISCO
abrir
Referência
CVE-2026-8989
Open Recovery Mode
41RISCO
abrir
Referência
CVE-2026-8988
Access to Bootloader
41RISCO
abrir
Referência
CVE-2026-8982
Hard-coded / Backdoor Accounts
48RISCO
abrir
Referência
CVE-2016-20096
Linknat VOS3000/VOS2009 2.1.2.0 SQL Injection via login.jsp
48RISCO
abrir
Referência
CVE-2026-16451
zsadmin2025 ZS-Admin com.zs.file.controller.SysFileController upload unrestricted upload
33RISCO
abrir
Referência
CVE-2026-64824
Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore
48RISCO
abrir
Referência
CVE-2026-16450
zsadmin2025 ZS-Admin MyBatis-Plus Tenant Plugin page getTenantId authorization
33RISCO
abrir
Referência
CVE-2026-16449
zsadmin2025 ZS-Admin com.zs.sys.dept.controller.SysDeptController page OrderItem.desc sql injection
33RISCO
abrir
Referência
CVE-2026-16448
D-Link DNS-1550-04 remote_backup.cgi cgi_check_rsync_rw command injection
33RISCO
abrir
Referência
CVE-2026-16331
D-Link DNS-320 save_ajax.php unrestricted upload
33RISCO
abrir
Referência
CVE-2026-16330
D-Link DNS-320 uploadify.php unrestricted upload
33RISCO
abrir
Referência
CVE-2026-63770
Glance 0.8.5 IP Spoofing Authentication Brute-Force Protection Bypass
41RISCO
abrir
Referência
CVE-2026-63771
Adminer < 5.4.3 Cookie Injection via X-Forwarded-Prefix Header
33RISCO
abrir
Referência
CVE-2026-13402
Royal Elementor Addons < 1.7.1063 - Unauthenticated Private Mega Menu Template Disclosure
33RISCO
abrir
Referência
CVE-2026-16015
poco-ai poco-claw executor_manager API tasks.py create_task missing authentication
33RISCO
abrir
Referência
CVE-2026-12869
Header Footer Builder for Elementor < 1.2.1 - Contributor+ Stored XSS via Template Import
33RISCO
abrir
Referência
CVE-2026-15907
H3C SecPath F1000-C8300 g=log_fw_nbc_mail_jsondata sql injection
33RISCO
abrir
Referência
CVE-2026-11579
Kali Forms < 2.4.17 - Unauthenticated Media Upload
33RISCO
abrir
ReferênciaVexDay Proof
XOOPS Module Amevents - SQL Injection
CVE-2008-5768webappsphp
SQL injection vulnerability in print.php in the AM Events (aka Amevents) module 0.22 for XOOPS allows remote attackers t
23RISCO
abrir
ReferênciaVexDay Proof
PHP weather 2.2.2 - Local File Inclusion / Cross-Site Scripting
CVE-2008-5770webappsphp
Cross-site scripting (XSS) vulnerability in config/make_config.php in PHP Weather 2.2.2 allows remote attackers to injec
23RISCO
abrir
Referência
CVE-2018-7297
Remote Code Execution in the TCL script interpreter in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers
35RISCO
abrir
Referência
CVE-2018-7312
SQL Injection exists in the Alexandria Book Library 3.1.2 component for Joomla! via the letter parameter.
23RISCO
abrir
Referência
CVE-2018-7313
SQL Injection exists in the CW Tags 2.0.6 component for Joomla! via the searchtext array parameter.
28RISCO
abrir
anteriorpágina 479 / 747próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.