Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.302exploits catalogados
35.469CVEs com exploração pública
24.695testados em laboratório
22.301 exploits
Referência
CVE-2017-20264
Joomla! Component Sponsor Wall 8.0 SQL Injection
41RISCO
abrir
Referência
CVE-2026-10181
TRENDnet TEW-432BRP formSysCmd stack-based overflow
41RISCO
abrir
Referência
CVE-2026-10175
Aider-AI Aider Architect Mode auth.py editor_coder.run code injection
33RISCO
abrir
Referência
CVE-2026-10174
Aider-AI Aider Pre-commit Hook args.py protection mechanism
33RISCO
abrir
Referência
CVE-2026-10173
Orthanc Explorer 2 URL StudyList.vue cross site scripting
33RISCO
abrir
Referência
CVE-2026-10172
Bdtask Multi-Store Inventory Management System Component Module.php upload unrestricted upload
33RISCO
abrir
Referência
CVE-2019-0541
CVE-2019-0541HIGHsob ataque
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML E
83RISCO
abrir
Referência
CVE-2026-9562
sambitraj STUDENT-MANAGEMENT-SYSTEM Dashboard access control
33RISCO
abrir
Referência
CVE-2026-11312
bytedance InfiniStore KV Map infinistore.h purge_kv_map algorithmic complexity
33RISCO
abrir
Referência
CVE-2026-10878
D-Link DWR-M920 formSmsManage sub_41C8E8 command injection
33RISCO
abrir
Referência
CVE-2026-9544
Shenzhen Sixun Software Sixun Shanghui Group Business Management System PayConfig sql injection
33RISCO
abrir
Referência
CVE-2026-9543
Totolink N300RH Web Management cstecgi.cgi setPasswordCfg os command injection
48RISCO
abrir
Referência
CVE-2026-10783
gradio-app gradio Audio Cache Key save_audio_to_cache weak hash
28RISCO
abrir
Referência
CVE-2026-10722
cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflow
33RISCO
abrir
Referência
CVE-2026-10704
SourceCodester Pizzafy E-Commerce System Administrative Control Panel admin_class_novo.php login sql injection
33RISCO
abrir
Referência
CVE-2026-10703
EIPStackGroup OpENer SendRRData cipmessagerouter.c CreateMessageRouterRequestStructure use after free
33RISCO
abrir
Referência
CVE-2026-10692
johnhuang316 code-index-mcp search_code_advanced is_safe_regex_pattern redos
33RISCO
abrir
Referência
CVE-2026-10691
wonderwhy-er DesktopCommanderMCP start_search search-manager.ts redos
33RISCO
abrir
Referência
CVE-2026-10688
ahujasid blender-mcp server.py execute_blender_code code injection
33RISCO
abrir
Referência
CVE-2019-0708
CVE-2019-0708CRITICALsob ataqueransomware
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
Referência
CVE-2019-0708
CVE-2019-0708CRITICALsob ataqueransomware
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
Referência
CVE-2019-0708
CVE-2019-0708CRITICALsob ataqueransomware
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
Referência
CVE-2026-10294
PackageKit API pk-transaction.c g_file_test improper authorization
33RISCO
abrir
Referência
CVE-2026-10287
SourceCodester SEO Meta Tag Extractor index.php get_headers server-side request forgery
33RISCO
abrir
Referência
CVE-2026-10258
itsourcecode Content Management System add_sub_topic.php sql injection
33RISCO
abrir
Referência
CVE-2026-10253
itsourcecode Online House Rental System manage_payment.php sql injection
33RISCO
abrir
Referência
CVE-2026-10251
itsourcecode Online House Rental System ajax.php login sql injection
33RISCO
abrir
Referência
CVE-2026-10250
itsourcecode Online Blood Bank Management System campsdetails.php sql injection
33RISCO
abrir
Referência
CVE-2026-10219
nextlevelbuilder GoClaw write_file Tool fsbridge.go FsBridge.WriteFile os command injection
33RISCO
abrir
Referência
CVE-2026-10218
nextlevelbuilder GoClaw evolution_handlers.go auth improper authorization
33RISCO
abrir
anteriorpágina 484 / 744próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.