Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.302exploits catalogados
35.469CVEs com exploração pública
24.695testados em laboratório
22.301 exploits
Referência
CVE-2018-16763
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir
Referência
CVE-2024-6039
Feng Office Workspaces sql injection
33RISCO
abrir
Referência
CVE-2018-17310
On the RICOH MP C1803 JPN printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of add
23RISCO
abrir
Referência
CVE-2018-17313
On the RICOH MP C307 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding a
23RISCO
abrir
Referência
CVE-2018-17313
On the RICOH MP C307 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding a
23RISCO
abrir
Referência
CVE-2004-2502
im-switch before 11.4-46.1 in Fedora Core 2 allows local users to overwrite arbitrary files via a symlink attack on the
23RISCO
abrir
Referência
CVE-2024-6244
pz-frontend-manager < 1.0.6 - CSRF change user profile picture
41RISCO
abrir
Referência
CVE-2024-6387
Openssh: regresshion - race condition in ssh allows rce/dos
63RISCO
abrir
Referência
CVE-2018-18803
Curriculum Evaluation System 1.0 allows SQL Injection via the login screen, related to frmCourse.vb and includes/user.vb
23RISCO
abrir
Referência
CVE-2018-19113
The Pronestor PNHM (aka Health Monitoring or HealthMonitor) add-in before 8.1.13.0 for Outlook has "BUILTIN\Users:(I)(F)
23RISCO
abrir
Referência
CVE-2018-19246
PHP-Proxy 5.1.0 allows remote attackers to read local files if the default "pre-installed version" (intended for users w
28RISCO
abrir
Referência
CVE-2018-19276
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated use
85RISCO
abrir
Referência
CVE-2018-19276
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated use
85RISCO
abrir
Referência
CVE-2018-19518
University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh c
60RISCO
abrir
Referência
Windows 10.0.17763.7009 - spoofing vulnerability
CVE-2025-24054MEDIUMsob ataqueremotewindows
NTLM Hash Disclosure Spoofing Vulnerability
75RISCO
abrir
Referência
windows 10/11 - NTLM Hash Disclosure Spoofing
CVE-2025-24054MEDIUMsob ataqueremotewindows
NTLM Hash Disclosure Spoofing Vulnerability
75RISCO
abrir
Referência
CVE-2014-8682
Multiple SQL injection vulnerabilities in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.x before 0.5.6.1105 Beta allow r
50RISCO
abrir
Referência
CVE-2026-67201
V 0.5.2 SSRF Bypass via Parser Differential in net.urllib and net.http
41RISCO
abrir
Referência
CVE-2026-67182
Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Header Injection
33RISCO
abrir
Referência64
FortiWeb CVE-2025-25257 exploit
CVE-2025-25257CRITICALsob ataque
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISCO
abrir
Referência
CVE-2026-14568
WP User Frontend < 4.3.8 - Unauthenticated Author-less Attachment Deletion
33RISCO
abrir
Referência
CVE-2026-14289
WP FacturaONE < 5.37 - Unauthenticated Remote Code Execution
48RISCO
abrir
Referência
CVE-2026-14236
Contact Form 7 – PayPal & Stripe Add-on < 2.5 - Open Redirect
33RISCO
abrir
Referência
CVE-2026-14235
WordPress Download Manager < 3.3.62 - Unauthorized Protected File Download via Reusable Download Key
41RISCO
abrir
Referência
CVE-2026-14203
Smart Manager < 8.92.0 - Contributor+ Stored XSS via Post Title
33RISCO
abrir
Referência
CVE-2026-14190
Sina Extension for Elementor < 3.10.2 - Reflected XSS
33RISCO
abrir
Referência
CVE-2026-15513
Wavlink WL-NU516U1 adm.cgi wlink_uci_set_value os command injection
33RISCO
abrir
Referência
CVE-2026-15512
pig-mesh Pig pig-codegen GeneratorServiceImpl.java code injection
33RISCO
abrir
Referência
CVE-2026-14778
SourceCodester Onlne Examination & Learning Management System Enrollment Management ajax_enroll.php improper authorization
33RISCO
abrir
Referência
CVE-2025-32432
CVE-2025-32432CRITICALsob ataque
Craft CMS Allows Remote Code Execution
100RISCO
abrir
anteriorpágina 473 / 744próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.