Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
22.721 exploits
ReferênciaVexDay Proof
DataTrac Activity Console - Denial of Service
CVE-2005-1667doswindows
DataTrac Activity Console 1.1 allows remote attackers to cause a denial of service via a long HTTP GET request.
23RISCO
abrir
Referência
CVE-2011-5130
dev/less.php in Family Connections CMS (FCMS) 2.5.0 - 2.7.1, when register_globals is enabled, allows remote attackers t
50RISCO
abrir
Referência
CVE-2020-11108
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RISCO
abrir
Referência
CVE-2020-11108
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RISCO
abrir
Referência
CVE-2026-16228
SourceCodester Class and Exam Timetabling System edit_schoolyr.php sql injection
33RISCO
abrir
Referência
CVE-2014-8739
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery
60RISCO
abrir
Referência
CVE-2017-1274
IBM Domino 8.5.3, and 9.0 is vulnerable to a stack based overflow in the IMAP service that could allow an authenticated
23RISCO
abrir
Referência
CVE-2020-37168
Ecommerce Systempay 1.0 Production Key Brute Force
48RISCO
abrir
Referência
CVE-2026-9810
AI Chatbot & Workflow Automation by AIWU < 1.5.4 - Unauthenticated Privilege Escalation via MCP OAuth
48RISCO
abrir
Referência
CVE-2017-12786
Network interfaces of the cliengine and noviengine services, included in the NoviWare software distribution through NW40
28RISCO
abrir
ReferênciaVexDay Proof
ActiveBuyandSell 6.2 - 'buyersend.asp?catid' SQL Injection
CVE-2005-2062webappsasp
Multiple SQL injection vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Referência
CVE-2014-9004
Cross-site scripting (XSS) vulnerability in vldPersonals before 2.7.1 allows remote attackers to inject arbitrary web sc
23RISCO
abrir
Referência
CVE-2026-59258
immich < 3.0.3 Shared Album Editor Ownership Takeover via updateUser
41RISCO
abrir
Referência
CVE-2021-47929
WordPress Plugin Filterable Portfolio Gallery 1.0 Stored XSS
33RISCO
abrir
Referência
CVE-2021-47928
Opencart TMD Vendor System 3.x Blind SQL Injection via product route
41RISCO
abrir
Referência
CVE-2021-47923
OpenCart 3.0.3.8 Session Fixation via OCSESSID Cookie
48RISCO
abrir
Referência
CVE-2011-5204
Akiva WebBoard 8.x stores passwords in plaintext, which allows local users to obtain sensitive information by reading fr
23RISCO
abrir
Referência
CVE-2005-2428
Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hid
60RISCO
abrir
Referência
CVE-2014-9095
Multiple SQL injection vulnerabilities in Raritan Power IQ 4.1.0 and 4.2.1 allow remote attackers to execute arbitrary S
23RISCO
abrir
Referência
CVE-2026-14642
SourceCodester Class and Exam Timetabling System edit_class2.php sql injection
33RISCO
abrir
Referência
CVE-2026-14641
SourceCodester Class and Exam Timetabling System edit_course.php sql injection
33RISCO
abrir
Referência
CVE-2026-14640
CodeAstro Apartment Visitor Management System Login index.php sql injection
33RISCO
abrir
Referência
CVE-2026-14639
CodeAstro Ecommerce Website my_account.php sql injection
33RISCO
abrir
Referência
CVE-2026-14633
kirilkirkov Ecommerce-CodeIgniter-Bootstrap Hidden REST API Endpoint set cross site scripting
33RISCO
abrir
Referência
CVE-2026-14607
RT-Thread lwp_syscall.c sys_getaddrinfo memory corruption
33RISCO
abrir
Referência
CVE-2014-9097
Multiple SQL injection vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly
23RISCO
abrir
Referência
CVE-2026-8207
Gibbon versions before v30.0.01 are affected by an authenticated SQL Injection vulnerability by abusing the Tracking/gr
41RISCO
abrir
Referência
Anuko Time Tracker 1.19.23.5325 - CSV/Formula Injection
CVE-2020-15255HIGHwebappsphp
CSV injection in Anuko Time Tracker
41RISCO
abrir
Referência
CVE-2017-20265
Joomla! Component Flip Wall 8.0 SQL Injection
41RISCO
abrir
Referência
CVE-2011-5283
Cross-site scripting (XSS) vulnerability in the web management interface in httpd/cgi-bin/ipinfo.cgi in Smoothwall Expre
23RISCO
abrir
anteriorpágina 710 / 758próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.