Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.324exploits catalogados
36.054CVEs com exploração pública
24.695testados em laboratório
22.697 exploits
Referência
CVE-2026-6552
3RISCO
abrir
Referência
CVE-2026-7713
crocodilestick Calibre-Web-Automated Kobo auth-token Route kobo_auth.py generate_auth_token improper authorization
33RISCO
abrir
ReferênciaVexDay Proof
NewsLetter 3.5 - 'NL_PATH' Remote File Inclusion
CVE-2006-3986webappsphp
PHP remote file inclusion vulnerability in index.php in Knusperleicht Newsletter 3.5 and earlier allows remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component ds-syndicate - 'feed_id' SQL Injection
CVE-2008-4623webappsphp
SQL injection vulnerability in the DS-Syndicate (com_ds-syndicate) component 1.1.1 for Joomla allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
newsReporter 1.1 - 'index.php' Remote File Inclusion
CVE-2006-3988webappsphp
PHP remote file inclusion vulnerability in index.php in Knusperleicht newsReporter 1.1 and earlier allows remote attacke
23RISCO
abrir
ReferênciaVexDay Proof
XOOPS Module makale 0.26 - SQL Injection
CVE-2008-4653webappsphp
SQL injection vulnerability in makale.php in Makale 0.26 and possibly other versions, a module for XOOPS, allows remote
23RISCO
abrir
Referência
CVE-2016-2494
Off-by-one error in sdcard/sdcard.c in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before
23RISCO
abrir
Referência
CVE-2026-12197
Ruijie EG105G-P JSON-RPC Diagnose Endpoint diagnose nslookup command injection
41RISCO
abrir
Referência
CVE-2016-2494
Off-by-one error in sdcard/sdcard.c in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before
23RISCO
abrir
Referência
CVE-2026-25558
QloApps 1.7.0 Stored XSS via SVG File Upload in Admin File Manager
13RISCO
abrir
ReferênciaVexDay Proof
Hummingbird Deployment Wizard 2008 - ActiveX Command Execution
CVE-2008-4728remotewindows
Multiple insecure method vulnerabilities in the DeployRun.DeploymentSetup.1 (DeployRun.dll) ActiveX control 10.0.0.44 in
35RISCO
abrir
ReferênciaVexDay Proof
Hummingbird Deployment Wizard 2008 - ActiveX File Execution(2)
CVE-2008-4728remotewindows
Multiple insecure method vulnerabilities in the DeployRun.DeploymentSetup.1 (DeployRun.dll) ActiveX control 10.0.0.44 in
35RISCO
abrir
ReferênciaVexDay Proof
Hummingbird Deployment Wizard 2008 - Registry Values Creation/Change
CVE-2008-4728remotewindows
Multiple insecure method vulnerabilities in the DeployRun.DeploymentSetup.1 (DeployRun.dll) ActiveX control 10.0.0.44 in
35RISCO
abrir
Referência
CVE-2026-24065
Local Privilege Escalation via Insecure XPC Client Validation in Waves Central for macOS
41RISCO
abrir
Referência
CVE-2016-2776
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly
60RISCO
abrir
ReferênciaVexDay Proof
Hummingbird 13.0 - ActiveX Remote Buffer Overflow (PoC)
CVE-2008-4729doswindows
Stack-based buffer overflow in Hummingbird.XWebHostCtrl.1 ActiveX control (hclxweb.dll) in Hummingbird Xweb ActiveX Cont
23RISCO
abrir
Referência
CVE-2021-24145
Modern Events Calendar Lite < 5.16.5 - Authenticated Arbitrary File Upload leading to RCE
60RISCO
abrir
Referência
CVE-2021-24272
Fitness Calculators < 1.9.6 - Cross-Site Request Forgery to Cross-Site Scripting (XSS)
23RISCO
abrir
Referência
CVE-2021-24276
Contact Form by Supsystic < 1.7.15 - Reflected Cross-Site scripting (XSS)
43RISCO
abrir
Referência
CVE-2021-24286
Redirect 404 to Parent < 1.3.1 - Reflected Cross-Site Scripting (XSS)
43RISCO
abrir
Referência
CVE-2017-17597
Nearbuy Clone Script 3.2 has SQL Injection via the category_list.php search parameter.
23RISCO
abrir
ReferênciaVexDay Proof
k_shoutbox 4.4 - Remote File Inclusion
CVE-2006-3989webappsphp
PHP remote file inclusion vulnerability in index.php in Knusperleicht Shoutbox 4.4 and earlier allows remote attackers t
23RISCO
abrir
Referência
CVE-2026-13169
Eventin < 4.1.21 - Contributor+ Arbitrary Event Modification, Deletion and Ownership Takeover via IDOR
41RISCO
abrir
Referência
CVE-2016-2784
CMS Made Simple 2.x before 2.1.3 and 1.x before 1.12.2, when Smarty Cache is activated, allow remote attackers to conduc
23RISCO
abrir
ReferênciaVexDay Proof
QuestCMS - Cross-Site Scripting / Directory Traversal / SQL Injection
CVE-2008-4772webappsphp
SQL injection vulnerability in main/main.php in QuestCMS allows remote attackers to execute arbitrary SQL commands via t
23RISCO
abrir
Referência
CVE-2026-75876
xianrendzw EasyReport Move Operations ModuleController.java sql injection
33RISCO
abrir
Referência
CVE-2026-70667
Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for CVE-2026-55162)
33RISCO
abrir
Referência21
PoC repository for the blog post CopyEscape: Taking Over Docker Hosts with docker cp
Tar extraction in moby/go-archive can write outside the destination directory via link following
41RISCO
abrir
Referência
CVE-2026-3430
Creative Mail 1.6.5 - 1.6.9 - Unauthenticated SQLi
41RISCO
abrir
Referência
CVE-2026-19035
Shibby Tomato qoslimit new_qoslimit_start os command injection
41RISCO
abrir
anteriorpágina 679 / 757próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.