Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
22.721 exploits
Referência
CVE-2017-15967
Mailing List Manager Pro 3.0 allows SQL Injection via the edit parameter to admin/users in a sort=login action, or the e
23RISCO
abrir
Referência
CVE-2015-6305
Untrusted search path vulnerability in the CMainThread::launchDownloader function in vpndownloader.exe in Cisco AnyConne
23RISCO
abrir
Referência
CVE-2017-15968
MyBuilder Clone 1.0 allows SQL Injection via the phpsqlsearch_genxml.php subcategory parameter.
23RISCO
abrir
Referência
CVE-2017-15969
PG All Share Video 1.0 allows SQL Injection via the PATH_INFO to search/tag, friends/index, users/profile, or video_cata
23RISCO
abrir
Referência
CVE-2017-15969
PG All Share Video 1.0 allows SQL Injection via the PATH_INFO to search/tag, friends/index, users/profile, or video_cata
23RISCO
abrir
Referência
CVE-2021-34369
portlets/contact/ref/refContactDetail.do in Accela Civic Platform through 20.1 allows remote attackers to obtain sensiti
23RISCO
abrir
Referência
CVE-2026-75089
PHPGurukul Complaint Management System check_availability.php sql injection
33RISCO
abrir
Referência
CVE-2026-75014
SourceCodester Pet Grooming Management Software get_barcode_data.php sql injection
33RISCO
abrir
Referência
CVE-2026-75013
TOTOLINK EX1200L cstecgi.cgi setWizardCfg null pointer dereference
41RISCO
abrir
Referência
CVE-2026-19995
Webkul Bagisto RMA Message send-message cross site scripting
33RISCO
abrir
Referência
CVE-2015-7297
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RISCO
abrir
Referência
CVE-2015-7601
Directory traversal vulnerability in PCMan's FTP Server 2.0.7 allows remote attackers to read arbitrary files via a ..//
50RISCO
abrir
Referência
CVE-2017-15973
Sokial Social Network Script 1.0 allows SQL Injection via the id parameter to admin/members_view.php.
23RISCO
abrir
Referência
CVE-2015-7603
Directory traversal vulnerability in Konica Minolta FTP Utility 1.0 allows remote attackers to read arbitrary files via
50RISCO
abrir
Referência
CVE-2015-7714
Multiple SQL injection vulnerabilities in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allow remote adm
23RISCO
abrir
Referência
CVE-2015-7858
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RISCO
abrir
Referência
CVE-2015-7890
Multiple buffer overflows in the esa_write function in /dev/seirenin the Exynos Seiren Audio driver, as used in Samsung
23RISCO
abrir
Referência
CVE-2015-8410
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RISCO
abrir
Referência
CVE-2015-8428
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RISCO
abrir
Referência
CVE-2016-0040
CVE-2016-0040HIGHsob ataque
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to g
91RISCO
abrir
Referência
CVE-2016-0491
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RISCO
abrir
Referência
CVE-2026-19770
feedmob fm-mcp-servers Download Endpoint index.ts downloadReport server-side request forgery
33RISCO
abrir
Referência
CVE-2026-19049
ProSolution WP Client < 2.0.9 - Unauthenticated SQLi and Plugin Data Deletion via 'removesite' Cookie
41RISCO
abrir
Referência
CVE-2016-10033
CVE-2016-10033CRITICALsob ataque
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir
Referência
CVE-2026-16595
WP Directory Kit < 1.5.5 - Subscriber+ User and Unpublished Listing Disclosure
33RISCO
abrir
Referência
CVE-2026-16590
WP Directory Kit < 1.5.5 - Subscriber+ Contact Message and User Data Disclosure
33RISCO
abrir
Referência
CVE-2026-19244
HKUDS nanobot MCP enabledTools Scope mcp.py connect_mcp_servers access control
33RISCO
abrir
Referência
CVE-2016-1106
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RISCO
abrir
Referência
CVE-2026-15215
Subscriptions for WooCommerce < 2.0.1 - Shop Manager+ Arbitrary Plugin Installation
41RISCO
abrir
Referência
CVE-2026-15214
Subscriptions for WooCommerce < 2.0.1 - Subscriber+ Subscription Detail Disclosure via IDOR
33RISCO
abrir
anteriorpágina 715 / 758próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.