Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.324exploits catalogados
36.054CVEs com exploração pública
24.695testados em laboratório
22.697 exploits
Referência
CVE-2017-17623
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
23RISCO
abrir
Referência
CVE-2017-17623
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
23RISCO
abrir
Referência
CVE-2016-3223
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold an
28RISCO
abrir
Referência
CVE-2010-3428
SQL injection vulnerability in modules/notes/json.php in Intermesh Group-Office 3.5.9 allows remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
ZeusCart 2.0 - 'category_list.php' SQL Injection
CVE-2008-5216webappsphp
SQL injection vulnerability in category_list.php in AJ Square ZeusCart 2.0 and earlier allows remote attackers to execut
23RISCO
abrir
Referência
CVE-2016-3235
CVE-2016-3235HIGHsob ataque
Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 misha
98RISCO
abrir
Referência
CVE-2017-17624
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat o
23RISCO
abrir
Referência
CVE-2026-19650
Cross-Site Request Forgery (CSRF) in GitLab
41RISCO
abrir
Referência
CVE-2026-74842
Kira-Pgr PromptShopMCP Image-Toolkit-MCP-Server server.py download_image server-side request forgery
33RISCO
abrir
Referência
CVE-2026-20000
itsourcecode Hospital Management System viewprescriptionrecord.php sql injection
33RISCO
abrir
Referência
CVE-2026-16055
Contest Gallery < 30.0.7 - Unauthenticated Login-Protection and 2FA Bypass via post_cg_login
41RISCO
abrir
Referência
CVE-2026-14553
Zportals < 6.3.4 - Subscriber+ Arbitrary File Upload
41RISCO
abrir
Referência
CVE-2025-15677
GeoDirectory < 2.8.110 - Editor+ Stored XSS via Place Categories
28RISCO
abrir
Referência
CVE-2021-26084
CVE-2021-26084CRITICALsob ataqueransomware
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
Referência
CVE-2010-3467
SQL injection vulnerability in modules/sections/index.php in E-Xoopport Samsara 3.1 and earlier, when the Tutorial modul
23RISCO
abrir
Referência
CVE-2010-3467
SQL injection vulnerability in modules/sections/index.php in E-Xoopport Samsara 3.1 and earlier, when the Tutorial modul
23RISCO
abrir
Referência
CVE-2010-3481
Multiple SQL injection vulnerabilities in login.php in ApPHP PHP MicroCMS 1.0.1, when magic_quotes_gpc is disabled, allo
23RISCO
abrir
ReferênciaVexDay Proof
Merlix Teamworx Server - File Disclosure/Bypass
CVE-2008-5600webappsphp
Merlix Teamworx Server stores sensitive information under the web root with insufficient access control, which allows re
23RISCO
abrir
Referência
CVE-2016-3670
Cross-site scripting (XSS) vulnerability in users.jsp in the Profile Search functionality in Liferay before 7.0.0 CE RC1
23RISCO
abrir
ReferênciaVexDay Proof
User Engine Lite ASP - 'users.mdb' Database Disclosure
CVE-2008-5601webappsphp
User Engine Lite ASP stores sensitive information under the web root with insufficient access control, which allows remo
23RISCO
abrir
Referência
CVE-2026-18787
GL.iNet AX1800 RPC Endpoint oui-rpc.lua remove_rule command injection
41RISCO
abrir
Referência
CVE-2026-18785
o6 open62541 client_types_custom.c UA_Client_getRemoteDataTypes use after free
33RISCO
abrir
Referência
CVE-2026-18784
o6 open62541 ua_client_highlevel.c UA_Client_readNodeClassAttribute heap-based overflow
33RISCO
abrir
ReferênciaVexDay Proof
Natterchat 1.12 - Database Disclosure
CVE-2008-5602webappsasp
Natterchat 1.12 stores sensitive information under the web root with insufficient access control, which allows remote at
23RISCO
abrir
ReferênciaVexDay Proof
ASPTicker 1.0 - Remote Database Disclosure
CVE-2008-5603webappsasp
ASPTicker 1.0 stores sensitive information under the web root with insufficient access control, which allows remote atta
23RISCO
abrir
Referência
CVE-2026-14229
ECS < 4.3.8 - Unauthenticated Private Content Disclosure via ecsload
33RISCO
abrir
Referência
CVE-2026-19845
TOTOLINK A800R lan.so cstecgi.cgi setStaticDhcpConfig stack-based overflow
41RISCO
abrir
Referência
CVE-2026-19844
TOTOLINK A800R ipv6.so cstecgi.cgi setRadvdCfg stack-based overflow
41RISCO
abrir
Referência
CVE-2026-32847
DeepCode 1.2.0 Path Traversal via SPA Catch-All Route in main.py
21RISCO
abrir
Referência
CVE-2013-5316
Cross-site request forgery (CSRF) vulnerability in RiteCMS 1.0.0 allows remote attackers to hijack the authentication of
23RISCO
abrir
anteriorpágina 681 / 757próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.