Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.620exploits catalogados
35.647CVEs com exploração pública
24.695testados em laboratório
22.429 exploits
Referência
Joomla! Component Saxum Picker 3.2.10 - SQL Injection
CVE-2018-7178webappsphp
SQL Injection exists in the Saxum Picker 3.2.10 component for Joomla! via the publicid parameter.
23RISCO
abrir
Referência
Joomla! Component SquadManagement 1.0.3 - SQL Injection
CVE-2018-7179webappsphp
SQL Injection exists in the SquadManagement 1.0.3 component for Joomla! via the id parameter.
23RISCO
abrir
Referência
CVE-2026-14630
ForceInjection AI-fundermentals Memory Recall smart_customer_service.py get_conversation_history weak hash
28RISCO
abrir
Referência
CVE-2026-12195
myVesta is affected by an authenticated remote code execution vulnerability. Low privileged users can insert arbitrary c
41RISCO
abrir
Referência
CVE-2026-14625
NousResearch hermes-agent server.py shell.exec protection mechanism
33RISCO
abrir
Referência
CVE-2026-14623
omec-project amf NGAP Message RRCInactiveTransitionReport denial of service
33RISCO
abrir
Referência
CVE-2026-14621
FederatedAI FATE OSX Broker QueuePushReqStreamObserver.java QueuePushReqStreamObserver.initEggroll wrong session
28RISCO
abrir
Referência
CVE-2026-12194
PHPIPAM Authenticated LFI
28RISCO
abrir
Referência
Joomla! Component Saxum Astro 4.0.14 - SQL Injection
CVE-2018-7180webappsphp
SQL Injection exists in the Saxum Astro 4.0.14 component for Joomla! via the publicid parameter.
23RISCO
abrir
Referência
CVE-2018-7841
CVE-2018-7841CRITICALsob ataque
A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code
100RISCO
abrir
Referência
CVE-2026-14619
itsourcecode Hospital Management System medicine.php sql injection
33RISCO
abrir
Referência
CVE-2018-7297
Remote Code Execution in the TCL script interpreter in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers
35RISCO
abrir
Referência
CVE-2018-7312
SQL Injection exists in the Alexandria Book Library 3.1.2 component for Joomla! via the letter parameter.
23RISCO
abrir
Referência
CVE-2018-7313
SQL Injection exists in the CW Tags 2.0.6 component for Joomla! via the searchtext array parameter.
28RISCO
abrir
Referência
CVE-2018-7315
SQL Injection exists in the Ek Rishta 2.9 component for Joomla! via the gender, age1, age2, religion, mothertounge, cast
23RISCO
abrir
Referência
CVE-2018-7358
ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper cha
55RISCO
abrir
Referência
CVE-2018-7448
Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote
28RISCO
abrir
Referência
CVE-2018-7448
Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote
28RISCO
abrir
Referência
CVE-2018-7477
SQL Injection exists in PHP Scripts Mall School Management Script 3.0.4 via the Username and Password fields to parents/
23RISCO
abrir
Referência
CVE-2026-58467
Cockpit CMS 2.14.0 - Path Traversal Local File Inclusion via index.php
41RISCO
abrir
Referência
CVE-2026-59102
Forgejo < 15.0.3 - Stored XSS via Actions Run Full Name Rendering
28RISCO
abrir
Referência
CVE-2026-59100
LobeChat 2.2.9 - Broken Object Level Authorization via Chat-Group Agent Operations
28RISCO
abrir
Referência
CVE-2026-59099
Apereo CAS 7.3.0 < 8.0.0-RC6 - AES-GCM Nonce Reuse Information Disclosure
48RISCO
abrir
Referência
CVE-2026-58579
RAGFlow < 0.26.3 - Stored Cross-Site Scripting via Agent Pipeline Node Name
33RISCO
abrir
Referência
CVE-2026-58578
LobeChat < 2.2.10-canary.15 - Regular Expression Denial of Service in GitHub Skill Import
41RISCO
abrir
Referência
CVE-2024-58352
Landray OA Unauthenticated HQL Injection via wechatLoginHelper.do
41RISCO
abrir
Referência
CVE-2024-58352
Landray OA Unauthenticated HQL Injection via wechatLoginHelper.do
41RISCO
abrir
Referência
CVE-2026-14618
Open5GS AMF nnrf-handler.c amf_nnrf_handle_nf_discover denial of service
33RISCO
abrir
Referência
CVE-2026-14617
NousResearch hermes-agent Streaming Reasoning Tag Filter stream_consumer.py GatewayStreamConsumer._filter_and_accumulate case sensitivity
28RISCO
abrir
Referência
CVE-2026-14610
Open Asset Import Library Assimp CSM File CSMLoader.cpp InternReadFile heap-based overflow
33RISCO
abrir
anteriorpágina 502 / 748próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.