Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.444exploits catalogados
35.552CVEs com exploração pública
24.695testados em laboratório
22.332 exploits
Referência
CVE-2026-37171
A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one
33RISCO
abrir
Referência
CVE-2026-70636
Flowise 3.1.4 Authentication Bypass via OAuth2 Credential Refresh Endpoint
41RISCO
abrir
Referência
CVE-2026-67622
Flowise 3.1.4 IDOR in OpenAI Assistants Integration
41RISCO
abrir
Referência
CVE-2026-67621
Flowise 3.1.4 Missing Authorization on Document Store Mutation Endpoints
41RISCO
abrir
Referência
CVE-2026-19110
DataGear Chart Name HtmlTplDashboardWidgetHtmlRenderer.java HtmlTplDashboardWidgetHtmlRenderer cross site scripting
33RISCO
abrir
Referência
CVE-2026-19108
MZ Automation libiec61850 URCB Revalidation reporting.c deleteDataSetValuesShadowBuffer use after free
33RISCO
abrir
Referência
CVE-2026-19071
itsourcecode Hospital Management System viewappointment.php sql injection
33RISCO
abrir
Referência
CVE-2026-19070
itsourcecode Hospital Management System viewadmin.php sql injection
33RISCO
abrir
Referência
CVE-2026-19069
itsourcecode Hospital Management System treatmentrecord.php sql injection
33RISCO
abrir
Referência
CVE-2026-19068
itsourcecode Hospital Management System treatmentdetail.php sql injection
33RISCO
abrir
Referência
CVE-2026-19067
itsourcecode Hospital Management System treatment.php sql injection
33RISCO
abrir
Referência
CVE-2025-15674
Content Protector (Passster) < 4.3.7 - Contributor+ Protected Content Disclosure via Core REST API
28RISCO
abrir
Referência
CVE-2026-16620
WPC Name Your Price for WooCommerce < 2.2.5 - Unauthenticated Price Manipulation via Select Mode
41RISCO
abrir
Referência
CVE-2026-16619
miniOrange 2FA < 6.2.8 - 2FA Bypass via Unlimited Second-Factor Attempts
41RISCO
abrir
Referência
CVE-2026-19062
chiuwingyan house selectall.action sql injection
33RISCO
abrir
Referência
CVE-2026-16067
Event Booking Manager for WooCommerce (Pro) < 5.0.3 - Unauthenticated Payment Bypass via Client-Controlled Ticket Price
33RISCO
abrir
Referência
CVE-2026-15256
Ninja Forms < 3.14.10 - Unauthenticated Arbitrary Shortcode Execution via Query-String Populated Field Default
33RISCO
abrir
Referência
CVE-2026-17032
Supsystic Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server
48RISCO
abrir
Referência
CVE-2026-13342
Security Optimizer – The All-In-One Protection Plugin < 1.6.5 - Login Access IP Allowlist Bypass via post_password
33RISCO
abrir
Referência
CVE-2026-15149
WP Hotel Booking < 2.3.3 - Unauthenticated Payment Bypass via Price Manipulation
33RISCO
abrir
Referência
CVE-2026-15208
RegistrationMagic < 6.0.9.5 - Unauthenticated Payment Bypass via Amount-Blind PayPal Verification
33RISCO
abrir
ReferênciaVexDay Proof
Pro Chat Rooms 3.0.3 - SQL Injection
CVE-2008-5070webappsphp
SQL injection vulnerability in Pro Chat Rooms 3.0.3, when magic_quotes_gpc is disabled, allows remote attackers to execu
23RISCO
abrir
Referência
CVE-2018-6888
An issue was discovered in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cro
23RISCO
abrir
ReferênciaVexDay Proof
Yoxel 1.23beta - 'itpm_estimate.php' Remote Code Execution
CVE-2008-5071webappsphp
Multiple eval injection vulnerabilities in itpm_estimate.php in Yoxel 1.23beta and earlier allow remote authenticated us
23RISCO
abrir
ReferênciaVexDay Proof
Deterministic Network Enhancer - 'dne2000.sys' Kernel Ring0 SYSTEM
CVE-2008-5121localwindows
dne2000.sys in Citrix Deterministic Network Enhancer (DNE) 2.21.7.233 through 3.21.7.17464, as used in (1) Cisco VPN Cli
23RISCO
abrir
Referência
CVE-2018-6892
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RISCO
abrir
ReferênciaVexDay Proof
Orca 2.0/2.0.2 - 'params.php?gConf[dir][layouts]' Remote File Inclusion
CVE-2008-5167webappsphp
PHP remote file inclusion vulnerability in layout/default/params.php in Boonex Orca 2.0 and 2.0.2, when register_globals
23RISCO
abrir
ReferênciaVexDay Proof
Tips Complete Website 1.2.0 - 'tipid' SQL Injection
CVE-2008-5168webappsphp
SQL injection vulnerability in tip.php in Tips Complete Website 1.2.0 allows remote attackers to execute arbitrary SQL c
23RISCO
abrir
ReferênciaVexDay Proof
Cheats Complete Website 1.1.1 - 'itemID' SQL Injection
CVE-2008-5170webappsphp
SQL injection vulnerability in item.php in Cheats Complete Website 1.1.1 allows remote attackers to execute arbitrary SQ
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Office - Communicator 'SIP' Remote Denial of Service
CVE-2008-5180MEDIUMdoswindows
Microsoft Communicator, and Communicator in Microsoft Office 2010 beta, allows remote attackers to cause a denial of ser
45RISCO
abrir
anteriorpágina 490 / 745próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.