Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.302exploits catalogados
35.469CVEs com exploração pública
24.695testados em laboratório
22.301 exploits
Referência
CVE-2018-19862
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST re
28RISCO
abrir
Referência
CVE-2018-20062
CVE-2018-20062CRITICALsob ataque
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RISCO
abrir
Referência
CVE-2017-0144
CVE-2017-0144HIGHsob ataqueransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Referência
Inosoft VisiWin 7 2022-2.1 - Insecure Folders Permissions
CVE-2023-31468HIGHlocalwindows
An issue was discovered in Inosoft VisiWin 7 through 2022-2.1 (Runtime RT7.3 RC3 20221209.5). The "%PROGRAMFILES(X86)%\I
41RISCO
abrir
Referência
CVE-2023-31747
Wondershare Filmora 12 (Build 12.2.1.2088) was discovered to contain an unquoted service path vulnerability via the comp
41RISCO
abrir
Referência
CVE-2017-8601
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute
35RISCO
abrir
ReferênciaVexDay Proof
Student Study Center Management System v1.0 - Stored Cross-Site Scripting (XSS)
CVE-2023-33580webappsphp
Phpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" f
23RISCO
abrir
Referência
Thruk Monitoring Web Interface 3.06 - Path Traversal
CVE-2023-34096MEDIUMwebappsperl
Thruk has Path Traversal Vulnerability in panorama.pm
45RISCO
abrir
ReferênciaVexDay Proof
Service Provider Management System v1.0 - SQL Injection
CVE-2023-34581webappsphp
Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/
23RISCO
abrir
Referência
CVE-2023-33592
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lf
23RISCO
abrir
Referência
CVE-2023-34581
Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/
23RISCO
abrir
Referência
CVE-2023-3460
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISCO
abrir
Referência
CVE-2023-3845
mooSocial mooDating URL ajax_invite cross site scripting
43RISCO
abrir
Referência
CVE-2003-0727
Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to
50RISCO
abrir
ReferênciaVexDay Proof
ashNews 0.83 - 'pathtoashnews' Remote File Inclusion
CVE-2003-1292webappsphp
PHP remote file include vulnerability in Derek Ashauer ashNews 0.83 allows remote attackers to include and execute arbit
23RISCO
abrir
ReferênciaVexDay Proof
Eznet 3.5.0 - Remote Stack Overflow / Denial of Service
CVE-2003-1339remotewindows
Stack-based buffer overflow in eZnet.exe, as used in eZ (a) eZphotoshare, (b) eZmeeting, (c) eZnetwork, and (d) eZshare
35RISCO
abrir
Referência
CVE-2026-19384
SourceCodester Simple Doctors Appointment System ajax.php set_appointment sql injection
33RISCO
abrir
Referência
CVE-2024-57708
An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __
33RISCO
abrir
Referência
CVE-2026-67620 - Flowise SSRF via incomplete cloud-metadata deny-list (Oracle OCI 192.0.0.192 + Alibaba 100.100.100.200 bypass the DEFAULT_DENY_LIST)
Flowise 3.1.4 SSRF via fetch-links Endpoint Incomplete Deny-List
33RISCO
abrir
Referência
CVE-2026-19268
abdullah1854 MCPGateway Claude Usage Range Endpoint claude-usage.ts getUsageByDateRange command injection
33RISCO
abrir
Referência
CVE-2026-16955
AI Engine < 3.6.6 - Subscriber+ Arbitrary File Read via Audio Transcription
33RISCO
abrir
Referência
CVE-2026-16953
AI Engine < 3.6.4 - Unauthenticated Cross-Session Chatbot File Deletion via Forgeable Session Cookie
33RISCO
abrir
Referência
CVE-2026-16948
Solace Extra < 1.6.1 - Subscriber+ Multiple Missing Authorization via Site-Wide Nonce Exposure
41RISCO
abrir
Referência
CVE-2026-16608
Download Monitor < 5.2.6 - Unauthenticated Download Log Injection
33RISCO
abrir
Referência
CVE-2026-16595
WP Directory Kit < 1.5.5 - Subscriber+ User and Unpublished Listing Disclosure
33RISCO
abrir
Referência
CVE-2026-16594
WP Directory Kit < 1.5.5 - Subscriber+ Plugin Settings and API Key Disclosure
41RISCO
abrir
Referência
CVE-2026-16590
WP Directory Kit < 1.5.5 - Subscriber+ Contact Message and User Data Disclosure
33RISCO
abrir
Referência
CVE-2026-16589
WP Directory Kit < 1.5.5 - Subscriber+ SQL Injection via data_fields_list Parameter
41RISCO
abrir
Referência
CVE-2026-16578
Admin Safety Guard < 1.4.0 - Unauthenticated User Data Disclosure via 2fa/app/users REST Route
41RISCO
abrir
Referência
CVE-2026-16574
Dokan < 5.0.11 - Vendor+ Cross-Vendor Downloadable Product Access Grant via Order Downloads REST Endpoint
33RISCO
abrir
anteriorpágina 469 / 744próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.