Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.258exploits catalogados
36.019CVEs com exploração pública
24.695testados em laboratório
22.697 exploits
Referência
CVE-2026-19967
Open Asset Import Library Assimp File Compression.cpp decompressBlock heap-based overflow
33RISCO
abrir
Referência
CVE-2005-3043
SQL injection vulnerability in AddItem.asp in Mall23 eCommerce allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Referência
CVE-2017-1000366
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causin
23RISCO
abrir
Referência
CVE-2020-15920
There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Executi
60RISCO
abrir
Referência
CVE-2020-15920
There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Executi
60RISCO
abrir
ReferênciaVexDay Proof
Alstrasoft e-Friends 4.98 - 'seid' Multiple SQL Injections
CVE-2007-6106webappsphp
SQL injection vulnerability in index.php in AlstraSoft E-Friends 4.98 and earlier allows remote attackers to execute arb
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component Restaurante 1.0 - 'id' SQL Injection
CVE-2008-1465webappsphp
SQL injection vulnerability in the Detodas Restaurante (com_restaurante) 1.0 component for Mambo and Joomla! allows remo
23RISCO
abrir
Referência
CVE-2018-10507
A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to take a series of steps to bypass or
23RISCO
abrir
Referência
CVE-2023-51951
SQL Injection vulnerability in Stock Management System 1.0 allows a remote attacker to execute arbitrary code via the id
48RISCO
abrir
Referência
CVE-2021-33352
An issue in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitra
48RISCO
abrir
Referência
CVE-2022-38573
10-Strike Network Inventory Explorer v9.3 was discovered to contain a buffer overflow via the Add Computers function.
48RISCO
abrir
Referência
CVE-2022-38573
10-Strike Network Inventory Explorer v9.3 was discovered to contain a buffer overflow via the Add Computers function.
48RISCO
abrir
Referência
CVE-2017-3563
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
23RISCO
abrir
Referência
CVE-2017-7620
MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequen
23RISCO
abrir
Referência
CVE-2026-8267
Open5GS SMF smf_nsmf_handle_created_data_in_vsmf denial of service
33RISCO
abrir
Referência
CVE-2011-4830
Multiple cross-site scripting (XSS) vulnerabilities in the com_listing component in Barter Sites component 1.3 for Jooml
23RISCO
abrir
Referência
CVE-2011-1667
SQL injection vulnerability in index.php in Anzeigenmarkt 2011 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Referência
CVE-2011-1667
SQL injection vulnerability in index.php in Anzeigenmarkt 2011 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Referência
CVE-2010-1496
SQL injection vulnerability in the JoltCard (com_joltcard) component 1.2.1 for Joomla! allows remote attackers to execut
23RISCO
abrir
Referência
CVE-2010-1496
SQL injection vulnerability in the JoltCard (com_joltcard) component 1.2.1 for Joomla! allows remote attackers to execut
23RISCO
abrir
Referência
CVE-2024-10758
code-projects/anirbandutta9 Content Management System/News-Buzz index.php sql injection
33RISCO
abrir
Referência
CVE-2008-3774
SQL injection vulnerability in index.php in Simasy CMS allows remote attackers to execute arbitrary SQL commands via the
23RISCO
abrir
Referência
CVE-2017-1000370
The offset2lib patch as used in the Linux Kernel contains a vulnerability that allows a PIE binary to be execve()'ed wit
23RISCO
abrir
ReferênciaVexDay Proof
VP-ASP 6.00 - 'shopcurrency.asp' SQL Injection
CVE-2006-2263webappsasp
SQL injection vulnerability in shopcurrency.asp in VP-ASP 6.00 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
ReferênciaVexDay Proof
Venalsur on-line Booking Centre - Cross-Site Scripting / SQL Injection
CVE-2008-6216webappsphp
SQL injection vulnerability in cadena_ofertas_ext.php in Venalsur Booking Centre Booking System for Hotels Group allows
23RISCO
abrir
Referência
CVE-2010-4142
Multiple stack-based buffer overflows in DATAC RealWin 2.0 Build 6.1.8.10 and earlier allow remote attackers to cause a
50RISCO
abrir
Referência
CVE-2011-5160
Cross-site scripting (XSS) vulnerability in setup.php in OpenEMR 4 allows remote attackers to inject arbitrary web scrip
23RISCO
abrir
Referência
CVE-2014-3246
SQL injection vulnerability in Collabtive 1.2 allows remote authenticated users to execute arbitrary SQL commands via th
23RISCO
abrir
Referência
CVE-2024-8580
TOTOLINK AC1200 T8 shadow.sample hard-coded password
48RISCO
abrir
Referência
CVE-2016-2288
Cogent DataHub before 7.3.10 allows local users to gain privileges by leveraging the user or guest role to modify a file
23RISCO
abrir
anteriorpágina 658 / 757próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.