Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.231exploits catalogados
35.420CVEs com exploração pública
24.695testados em laboratório
22.266 exploits
Referência
CVE-2026-11568
Product Configurator for WooCommerce < 1.7.3 - Unauthenticated Private/Draft Product Data Disclosure via pc_get_data
41RISCO
abrir
Referência
CVE-2026-11581
Kali Forms < 2.4.13 - Contributor+ Stored XSS via Form Field Caption
33RISCO
abrir
Referência
CVE-2010-5041
SQL injection vulnerability in index.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute ar
23RISCO
abrir
Referência
CVE-2018-12094
Cross-site scripting (XSS) vulnerability in news.php in Dimofinf CMS Version 3.0.0 allows remote attackers to inject arb
23RISCO
abrir
Referência
CVE-2018-12114
Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts.
23RISCO
abrir
Referência
CVE-2018-12234
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4.0 HRMS Software. The user supplied
23RISCO
abrir
Referência
CVE-2026-11482
SourceCodester Class and Exam Timetabling System archive5.php sql injection
33RISCO
abrir
Referência
CVE-2026-11481
yoanbernabeu grepai Postgres Embedding Cache chunker.go PostgresStore.LookupByContentHash weak hash
28RISCO
abrir
Referência
CVE-2021-47968
Podcast Generator 3.1 Persistent Cross-Site Scripting via long_description
33RISCO
abrir
Referência
CVE-2021-47967
PHP Timeclock 1.04 Multiple Cross-Site Scripting via Parameters
33RISCO
abrir
Referência
CVE-2021-47966
PHP Timeclock 1.04 SQL Injection via login.php
41RISCO
abrir
Referência
CVE-2010-5044
SQL injection vulnerability in models/log.php in the Search Log (com_searchlog) component 3.1.0 for Joomla! allows remot
23RISCO
abrir
ReferênciaVexDay Proof
PHP < 4.4.5/5.2.1 - 'shmop' Local Code Execution
CVE-2007-1376locallinux
The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspo
28RISCO
abrir
ReferênciaVexDay Proof
PHP < 4.4.5/5.2.1 - 'shmop' SSL RSA Private-Key Disclosure
CVE-2007-1376locallinux
The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspo
28RISCO
abrir
Referência
CVE-2018-12525
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /images/ pr
23RISCO
abrir
Referência
CVE-2011-4572
Cross-site scripting (XSS) vulnerability in inc/tesmodrewite.php in CF Image Hosting Script 1.3.82, 1.4.1, and probably
23RISCO
abrir
Referência
CVE-2011-4800
Directory traversal vulnerability in Serv-U FTP Server before 11.1.0.5 allows remote authenticated users to read and wri
23RISCO
abrir
Referência
CVE-2011-4812
Cross-site scripting (XSS) vulnerability in nowosci.php in BestShopPro allows remote attackers to inject arbitrary web s
23RISCO
abrir
Referência
CVE-2026-15622
poco-ai poco-claw Workspace API workspace.py get_workspace_file authorization
33RISCO
abrir
ReferênciaVexDay Proof
PHP < 4.4.5/5.2.1 - PHP_binary Session Deserialization Information Leak
CVE-2007-1380localmultiple
The php_binary serialization handler in the session extension in PHP before 4.4.5, and 5.x before 5.2.1, allows context-
23RISCO
abrir
Referência
CVE-2026-12081
Database for Contact Form 7, WPforms, Elementor forms < 1.5.2 - Unauthenticated PHP Object Injection via Entry File Field
33RISCO
abrir
Referência
CVE-2026-11964
User Registration & Membership < 5.2.2 - Unauthenticated PayPal Webhook Signature Verification Bypass Leading to Membership Activation
48RISCO
abrir
Referência
CVE-2018-12584
The ConnectionBase::preparseNewBytes function in resip/stack/ConnectionBase.cxx in reSIProcate through 1.10.2 allows rem
28RISCO
abrir
Referência
CVE-2018-12584
The ConnectionBase::preparseNewBytes function in resip/stack/ConnectionBase.cxx in reSIProcate through 1.10.2 allows rem
28RISCO
abrir
Referência
CVE-2018-12604
GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_d
28RISCO
abrir
Referência
CVE-2018-12613
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISCO
abrir
Referência
CVE-2018-12613
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISCO
abrir
Referência
CVE-2018-12613
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISCO
abrir
Referência
CVE-2011-5200
Multiple SQL injection vulnerabilities in DeDeCMS, possibly 5.6, allow remote attackers to execute arbitrary SQL command
23RISCO
abrir
Referência
CVE-2011-5230
Multiple SQL injection vulnerabilities in the selectUserIdByLoginPass function in seotoaster_core/application/models/Log
23RISCO
abrir
anteriorpágina 446 / 743próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.