Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.533exploits catalogados
35.607CVEs com exploração pública
24.695testados em laboratório
22.407 exploits
Referência
CVE-2025-13874
Authorization Bypass Through User-Controlled Key in GitLab
33RISCO
abrir
Referência
CVE-2025-14869
Improper Validation of Specified Quantity in Input in GitLab
41RISCO
abrir
Referência
CVE-2025-14870
Allocation of Resources Without Limits or Throttling in GitLab
41RISCO
abrir
Referência
CVE-2026-3607
Access Control Check Implemented After Asset is Accessed in GitLab
33RISCO
abrir
Referência
CVE-2026-9478
Totolink A8000RU Web Management cstecgi.cgi setParentalRules os command injection
48RISCO
abrir
Referência
CVE-2026-19376
Uasoft Badaso File API api.php class permission
33RISCO
abrir
Referência
CVE-2026-19375
dmitriiweb article-scraper-mcp server.py fetch_article server-side request forgery
33RISCO
abrir
Referência
WebERP 4.15 - SQL injection
CVE-2019-13292webappsphp
A SQL Injection issue was discovered in webERP 4.15. Payments.php accepts payment data in base64 format. After this is d
23RISCO
abrir
Referência
CVE-2026-19353
DedeCMS Installation Wizard index.php _4_Setup file inclusion
28RISCO
abrir
Referência
CVE-2019-1346
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Servi
28RISCO
abrir
Referência
CVE-2019-13494
nodeimp.exe in Castle Rock SNMPc before 9.0.12.1 and 10.x before 10.0.9 has a stack-based buffer overflow via a long var
23RISCO
abrir
Referência
CVE-2019-13529
An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform action
41RISCO
abrir
Referência
CVE-2019-13529
An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform action
41RISCO
abrir
Referência
CentOS Control Web Panel 0.9.8.836 - Authentication Bypass
CVE-2019-13605webappslinux
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.838 to 0.9.8.846, remote attackers can bypass authentication in
28RISCO
abrir
Referência
CVE-2019-3396
CVE-2019-3396CRITICALsob ataqueransomware
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISCO
abrir
Referência
CVE-2026-16965
Solace Extra < 1.6.1 - Subscriber+ Post Meta Update via solace_update_sitebuilder_status
33RISCO
abrir
Referência
CVE-2026-16957
Slim SEO < 4.9.11 - Contributor+ Arbitrary Post Meta Disclosure
28RISCO
abrir
Referência
CVE-2026-16562
WP Statistics < 14.16.10 - Subscriber+ Sensitive Data Disclosure via Metabox AJAX Handlers
33RISCO
abrir
Referência
CVE-2026-16559
YMC Filter < 3.12.9 - Author+ Stored XSS via SVG Icon Upload
33RISCO
abrir
Referência
CVE-2026-16558
YMC Filter < 3.12.8 - Contributor+ Stored XSS via Layout Builder Schema
33RISCO
abrir
Referência
CVE-2026-16535
Link Library < 7.9.4 - Reflected XSS via Thumbs-Rating likelabel
33RISCO
abrir
Referência
CVE-2026-16282
Appointment Hour Booking < 1.5.88 - Unauthenticated Booking Price Manipulation via tcost Parameter
33RISCO
abrir
Referência
CVE-2026-19231
SourceCodester Simple Doctors Appointment System ajax.php delete_appointment sql injection
33RISCO
abrir
Referência
CVE-2026-8782
omec-project amf NGAP Message handler.go null pointer dereference
33RISCO
abrir
Referência
CVE-2019-5418
CVE-2019-5418HIGHsob ataque
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir
Referência
CVE-2019-14347
Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an ad
23RISCO
abrir
Referência
WordPress Plugin UserPro 4.9.32 - Cross-Site Scripting
CVE-2019-14470webappsphp
cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has X
60RISCO
abrir
Referência
CVE-2019-14696
Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter.
43RISCO
abrir
Referência
CVE-2021-47962
Savsoft Quiz 5.0 Persistent Cross-Site Scripting via User Settings
33RISCO
abrir
Referência
CVE-2021-47959
WordPress Plugin WPGraphQL 1.3.5 Denial of Service
41RISCO
abrir
anteriorpágina 486 / 747próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.