Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
22.721 exploits
Referência
CVE-2026-18895
UTT HiPER 1250GW APSecurity_5g strcpy stack-based overflow
41RISCO
abrir
Referência
CVE-2015-7889
The SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR uses weak permissions f
23RISCO
abrir
Referência
CVE-2015-7889
The SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR uses weak permissions f
23RISCO
abrir
Referência
CVE-2015-7890
Multiple buffer overflows in the esa_write function in /dev/seirenin the Exynos Seiren Audio driver, as used in Samsung
23RISCO
abrir
Referência
CVE-2015-7891
Race condition in the ioctl implementation in the Samsung Graphics 2D driver (aka /dev/fimg2d) in Samsung devices with A
23RISCO
abrir
Referência
CVE-2015-7892
Stack-based buffer overflow in the m2m1shot_compat_ioctl32 function in the Samsung m2m1shot driver framework, as used in
23RISCO
abrir
Referência
CVE-2015-7892
Stack-based buffer overflow in the m2m1shot_compat_ioctl32 function in the Samsung m2m1shot driver framework, as used in
23RISCO
abrir
Referência
CVE-2015-7894
The DCMProvider service in Samsung LibQjpeg on a Samsung SM-G925V device running build number LRX22G.G925VVRU1AOE2 allow
23RISCO
abrir
Referência
CVE-2015-7898
Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
23RISCO
abrir
Referência
CVE-2015-7898
Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
23RISCO
abrir
Referência
CVE-2015-8103
The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary co
60RISCO
abrir
Referência
CVE-2015-8256
Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras.
28RISCO
abrir
Referência
CVE-2014-6271
CVE-2014-6271CRITICALsob ataque
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
Referência
CVE-2014-6271
CVE-2014-6271CRITICALsob ataque
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
Referência
CVE-2014-6271
CVE-2014-6271CRITICALsob ataque
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
Referência
CVE-2026-18853
ZomboDroid Meme Generator App com.zombodroid.MemeGenerator t5.l.c path traversal
33RISCO
abrir
Referência
CVE-2026-18852
epsilla-cloud vectordb Filter expr.cpp ShuntingYard unusual condition
33RISCO
abrir
Referência
CVE-2026-70619
Odysseus Missing Admin Authorization via Embedding Endpoint Routes
41RISCO
abrir
Referência
CVE-2015-8644
Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on
28RISCO
abrir
Referência
CVE-2026-63769
Huginn 2022.08.18 SSRF via ScenarioImport fetch_url Method
33RISCO
abrir
Referência
CVE-2026-16276
Classified Listing < 5.4.4 - Contributor+ Store Revenue Total Disclosure via rtcl_revenue_order_search
28RISCO
abrir
Referência
CVE-2026-16274
Classified Listing < 5.4.4 - Contributor+ Unpublished Post Content Disclosure via rtcl_block_css_get_posts
28RISCO
abrir
Referência
CVE-2026-16057
Contest Gallery < 30.0.7 - Author+ Arbitrary Post Deletion via post_cg_youtube_delete_from_library
33RISCO
abrir
Referência
CVE-2016-0492
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RISCO
abrir
Referência
CVE-2016-0492
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RISCO
abrir
Referência
CVE-2015-8660
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op
43RISCO
abrir
Referência
CVE-2026-8155
BuddyPress < 14.5.0 - Subscriber+ Private Messages Disclosure via IDOR
33RISCO
abrir
Referência
CVE-2016-0006
The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8,
23RISCO
abrir
ReferênciaVexDay Proof
Claroline 1.8.0 rc1 - 'import.lib.php' Remote File Inclusion
CVE-2006-5256webappsphp
PHP remote file inclusion vulnerability in claroline/inc/lib/import.lib.php in Claroline 1.8.0 and earlier allows remote
23RISCO
abrir
Referência
CVE-2016-0040
CVE-2016-0040HIGHsob ataque
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to g
91RISCO
abrir
anteriorpágina 717 / 758próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.