Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.324exploits catalogados
36.054CVEs com exploração pública
24.695testados em laboratório
22.697 exploits
Referência
CVE-2026-5543
PHPGurukul User Registration & Login and User Management System yesterday-reg-users.php sql injection
33RISCO
abrir
Referência
CVE-2026-5542
code-projects Simple Laundry System Parameter modstaffinfo.php cross site scripting
33RISCO
abrir
Referência
CVE-2026-5541
code-projects Simple Laundry System Parameter modmemberinfo.php cross site scripting
33RISCO
abrir
Referência
CVE-2026-5540
code-projects Simple Laundry System Parameter modifymember.php sql injection
33RISCO
abrir
Referência
CVE-2026-5539
code-projects Simple Laundry System Parameter modifymember.php cross site scripting
33RISCO
abrir
Referência
CVE-2026-5537
halex CourseSEL HTTP GET Parameter IndexController.class.php check_sel sql injection
33RISCO
abrir
Referência
CVE-2026-5535
FedML-AI FedML MQTT Message FileUtils.java path traversal
33RISCO
abrir
Referência
CVE-2026-5532
ScrapeGraphAI scrapegraph-ai GenerateCodeNode generate_code_node.py create_sandbox_and_execute os command injection
33RISCO
abrir
Referência
CVE-2026-5531
SourceCodester Student Result Management System HTTP GET Request login_credentials.txt cleartext storage in file
33RISCO
abrir
Referência
CVE-2026-5529
Dromara lamp-cloud DefUserController pageUser improper authorization
33RISCO
abrir
Referência
CVE-2026-5528
MoussaabBadla code-screenshot-mcp HTTP os command injection
33RISCO
abrir
Referência
CVE-2018-25246
Wikipedia 12.0 Denial of Service via Search
41RISCO
abrir
Referência
CVE-2016-20054
Nodcms Cross Site Request Forgery via admin endpoints
33RISCO
abrir
Referência
CVE-2018-25255
10-Strike LANState 8.8 Local Buffer Overflow SEH
41RISCO
abrir
Referência
CVE-2018-25254
NICO-FTP 3.0.1.19 Buffer Overflow SEH
48RISCO
abrir
Referência
CVE-2018-25253
Termite 3.4 Denial of Service via Settings Buffer Overflow
33RISCO
abrir
Referência
CVE-2018-25252
FTP Voyager 16.2.0 Denial of Service via Malformed Site Profile
33RISCO
abrir
Referência
CVE-2010-4272
SQL injection vulnerability in the Pulse Infotech Sponsor Wall (com_sponsorwall) component 1.1 for Joomla! allows remote
23RISCO
abrir
Referência
CVE-2016-4669
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS b
38RISCO
abrir
Referência
CVE-2010-4401
languages.inc.php in DynPG CMS 4.2.0 allows remote attackers to obtain sensitive information via a direct request, which
23RISCO
abrir
Referência
CVE-2017-8740
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current u
45RISCO
abrir
Referência
CVE-2010-4435
Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows remote attackers to affect confidentiality, integrity, a
28RISCO
abrir
Referência
CVE-2010-5017
SQL injection vulnerability in stats.php in Elite Gaming Ladders 3.0 allows remote attackers to execute arbitrary SQL co
23RISCO
abrir
Referência
CVE-2026-9393
H3C Magic B0 aspForm Edit_BasicSSID_5G buffer overflow
41RISCO
abrir
Referência
CVE-2026-17022
Salon Booking System – Free Version < 10.30.34 - Unauthenticated Booking Information Disclosure via Booking Wizard
41RISCO
abrir
Referência
CVE-2026-16948
Solace Extra < 1.6.1 - Subscriber+ Multiple Missing Authorization via Site-Wide Nonce Exposure
41RISCO
abrir
Referência
CVE-2026-16608
Download Monitor < 5.2.6 - Unauthenticated Download Log Injection
33RISCO
abrir
Referência
CVE-2026-14943
Password Protected < 2.8.4 - Unauthenticated Sensitive Information Exposure via REST API
41RISCO
abrir
Referência
CVE-2026-19195 Proof of Concept
V-Secure Jingyun Antivirus Kernel Driver ZyArk.sys access control
41RISCO
abrir
Referência
CVE-2026-16954
AI Engine < 3.6.4 - Editor+ Sensitive Information Disclosure of API Key and Bearer Tokens
33RISCO
abrir
anteriorpágina 685 / 757próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.