Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.324exploits catalogados
36.054CVEs com exploração pública
24.695testados em laboratório
22.697 exploits
Referência
CVE-2026-6990
projeto-siga novo cross site scripting
33RISCO
abrir
Referência
CVE-2026-6989
Tenda F453 Telnet Service telnet TendaTelnet command injection
33RISCO
abrir
Referência
CVE-2026-6988
Tenda HG10 Boa Service formRouting formRoute buffer overflow
41RISCO
abrir
Referência
CVE-2026-6986
Cesanta Mongoose GCM Authentication Tag tls_aes128.c mg_aes_gcm_decrypt signature verification
33RISCO
abrir
Referência
CVE-2026-6985
Cesanta Mongoose TCP Option net_builtin.c handle_opt infinite loop
33RISCO
abrir
Referência
CVE-2026-6984
AstrBotDevs AstrBot Dashboard API t2i.py create_template special elements used in a template engine
33RISCO
abrir
Referência
CVE-2026-7408
SourceCodester Pizzafy Ecommerce System ajax.php save_menu sql injection
33RISCO
abrir
Referência
CVE-2026-6623
BichitroGan ISP Billing Software Profile users-view cross site scripting
33RISCO
abrir
Referência
CVE-2026-6622
BichitroGan ISP Billing Software Customer edit cross site scripting
33RISCO
abrir
Referência
CVE-2026-6620
SonicCloudOrg sonic-server File Upload Endpoint FileTool.java upload path traversal
33RISCO
abrir
Referência
CVE-2026-6619
langgenius dify ImagePreview image-preview.tsx openInNewTab cross site scripting
33RISCO
abrir
Referência
CVE-2026-6618
langgenius dify ApiBasedToolSchemaParser parser.py parse_openai_plugin_json_to_tool_bundle server-side request forgery
33RISCO
abrir
Referência
CVE-2026-6616
TransformerOptimus SuperAGI WebScraperTool webpage_extractor.py extract_with_lxml server-side request forgery
33RISCO
abrir
Referência
CVE-2016-8021
Improper verification of cryptographic signature vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3
23RISCO
abrir
Referência
CVE-2026-78434
Faveo Helpdesk post-ticket-reply Endpoint FormController.php post_ticket_reply missing authentication
33RISCO
abrir
Referência
CVE-2026-7612
itsourcecode Courier Management System edit_user.php sql injection
33RISCO
abrir
Referência
CVE-2026-7609
TRENDnet TEW-821DAP Firmware Udpate diagnostic tools_diagnostic os command injection
33RISCO
abrir
Referência
CVE-2026-7608
TRENDnet TEW-821DAP tools_diagnostic os command injection
33RISCO
abrir
Referência
CVE-2026-7545
SourceCodester Advanced School Management System checkEmail Endpoint commonController.php sql injection
33RISCO
abrir
Referência
CVE-2026-7538
Totolink A8000RU CGI cstecgi.cgi vulnerability os command injection
48RISCO
abrir
Referência
CVE-2026-7536
Open5GS BSF pcfBindings bsf_sess_add_by_ip_address denial of service
33RISCO
abrir
Referência
CVE-2026-7535
Open5GS transfer-update denial of service
33RISCO
abrir
Referência
CVE-2018-17128
A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode.
45RISCO
abrir
Referência
CVE-2014-4311
Epicor Enterprise 7.4 before FS74SP6_HotfixTL054181 allows attackers to obtain the (1) Database Connection and (2) E-mai
23RISCO
abrir
Referência
CVE-2016-8806
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RISCO
abrir
Referência
CVE-2026-71503
Dolibarr < 24.0.0 Reflected XSS via Extra Fields Administration Template
33RISCO
abrir
Referência
CVE-2014-4312
Multiple cross-site scripting (XSS) vulnerabilities in Epicor Enterprise 7.4 before FS74SP6_HotfixTL054181 allow remote
23RISCO
abrir
Referência
CVE-2026-6014
D-Link DIR-513 POST Request formAdvanceSetup buffer overflow
41RISCO
abrir
Referência
CVE-2026-6013
D-Link DIR-513 POST Request formSetRoute buffer overflow
41RISCO
abrir
Referência
CVE-2026-6012
D-Link DIR-513 POST Request formSetPassword buffer overflow
41RISCO
abrir
anteriorpágina 691 / 757próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.