Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
22.832 exploits
ReferênciaVexDay Proof
BulletProof FTP Client 2.63 - Local Heap Overflow (PoC)
CVE-2008-5753doswindows
Stack-based buffer overflow in BulletProof FTP Client 2.63 and 2010 allows user-assisted attackers to execute arbitrary
23RISCO
abrir
Referência
CVE-2018-13108
All ADB broadband gateways / routers based on the Epicentro platform are affected by a local root jailbreak vulnerabilit
23RISCO
abrir
ReferênciaVexDay Proof
TUTOS 1.3 - 'cmd.php' Remote Command Execution
CVE-2008-0149webappsphp
TUTOS 1.3 allows remote attackers to read system information via a direct request to php/admin/phpinfo.php, which calls
23RISCO
abrir
ReferênciaVexDay Proof
FlexBB 0.6.3 - Cookies SQL Injection
CVE-2008-0157webappsphp
SQL injection vulnerability in FlexBB 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via th
23RISCO
abrir
Referência
CVE-2026-16009
itsourcecode Hospital Management System prescriptionorderdetail.php sql injection
33RISCO
abrir
Referência
CVE-2026-12684
Customer Reviews for WooCommerce < 5.113.0 - Unauthenticated Arbitrary Media Upload via cr_upload_media
33RISCO
abrir
Referência
CVE-2026-12585
Abandoned Cart Lite for WooCommerce < 6.8.2 - Unauthenticated Account Takeover via Malleable Recovery-Link Token
41RISCO
abrir
Referência
CVE-2026-15520
GNU LibreDWG R2004 Section Decompression decode.c decompress_R2004_section heap-based overflow
33RISCO
abrir
Referência
CVE-2026-15518
AREA 17 Twill CMS Media Library Insert FileLibraryController.php storeFile unrestricted upload
33RISCO
abrir
Referência
CVE-2026-12525
Redux Framework < 4.5.13 - Subscriber+ Privilege Escalation to Administrator
41RISCO
abrir
Referência
CVE-2026-15523
CodeAstro Simple Online Leave Management System dashboard.php sql injection
33RISCO
abrir
Referência
CVE-2026-15522
tugcantopaloglu godot-mcp run_project index.js validatePath path traversal
33RISCO
abrir
Referência
CVE-2026-15521
makafeli n8n-workflow-builder update_node_from_file server.cjs path traversal
33RISCO
abrir
Referência
CVE-2026-15517
Jinher OA PlanGiveOut.aspx sql injection
33RISCO
abrir
Referência
CVE-2026-15516
MacCMS Pro Installation Index.php step5 authorization
33RISCO
abrir
Referência
CVE-2026-15515
Tencent PC Manager QMUDisk Driver qmudisk64.sys uncontrolled search path
41RISCO
abrir
Referência
CVE-2026-15473
Eleveo Call Recording Software Recorded Calls restoreCallAction.do improper authorization
33RISCO
abrir
Referência
CVE-2018-13405
The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an
23RISCO
abrir
Referência
CVE-2026-15472
Eleveo Call Recording Software composeEmailAction.do improper authorization
33RISCO
abrir
Referência
CVE-2026-12378
BookingPress <= 1.1.28 - Unauthenticated PHP Object Injection
41RISCO
abrir
Referência
CVE-2025-15668
GPAC MP4Box box_code_base.c sgpd_del_entry heap-based overflow
33RISCO
abrir
Referência
CVE-2025-15667
GPAC MP4Box avc_ext.c gf_isom_nalu_sample_rewrite double free
33RISCO
abrir
Referência
CVE-2026-14713
SourceCodester Pizzafy E-Commerce System ajax.php confirm_order sql injection
33RISCO
abrir
Referência
CVE-2026-14706
code-projects Online Examination Quiz Creation Feature update.php sql injection
33RISCO
abrir
ReferênciaVexDay Proof
Binn SBuilder - 'nid' Blind SQL Injection
CVE-2008-0253webappsphp
SQL injection vulnerability in full_text.php in Binn SBuilder allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
ReferênciaVexDay Proof
TutorialCMS 1.02 - 'Username' SQL Injection
CVE-2008-0254webappsphp
SQL injection vulnerability in activate.php in TutorialCMS (aka Photoshop Tutorials) 1.02, when magic_quotes_gpc is disa
23RISCO
abrir
Referência
CVE-2026-6352
Incorrect Authorization in GitLab
28RISCO
abrir
Referência
CVE-2018-14058
Pimcore before 5.3.0 allows SQL Injection via the REST web service API.
43RISCO
abrir
Referência
CVE-2026-6896
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
41RISCO
abrir
Referência
CVE-2026-58583
FluxInk Color Management Driver local privilege escalation
41RISCO
abrir
anteriorpágina 738 / 762próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.