Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.449exploits catalogados
35.552CVEs com exploração pública
24.695testados em laboratório
22.332 exploits
Referência
Craft CMS 3.1.12 Pro - Cross-Site Scripting
CVE-2019-9554webappsphp
In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at
23RISCO
abrir
Referência
CVE-2019-9581
phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitra
28RISCO
abrir
Referência
CVE-2026-9426
Edimax EW-7438RPn formHwSet stack-based overflow
41RISCO
abrir
Referência
CVE-2026-9416
code-projects Employee Management System myprofile.php cross site scripting
33RISCO
abrir
Referência
CVE-2026-9415
code-projects Employee Management System eloginwel.php cross site scripting
33RISCO
abrir
Referência
CVE-2026-9413
SourceCodester Indian Invoicing System category.php cross site scripting
33RISCO
abrir
Referência
CVE-2026-9412
SourceCodester Indian Invoicing System Backend Endpoint access control
33RISCO
abrir
ReferênciaVexDay Proof
ApowerManager 3.1.7 - Phone Manager Remote Denial of Service (PoC)
CVE-2019-9601dosandroid
The ApowerManager application through 3.1.7 for Android allows remote attackers to cause a denial of service via many si
23RISCO
abrir
Referência
CVE-2026-9411
SourceCodester Indian Invoicing System Invoice Generation IGST_Invoice.php sql injection
33RISCO
abrir
Referência
CVE-2026-9410
Sushmi-pal Invoice-System Profile Workflow profile improper authorization
33RISCO
abrir
Referência
CVE-2026-9409
Sushmi-pal Invoice-System User Management user improper authorization
33RISCO
abrir
Referência
CVE-2026-9407
Totolink A8000RU Web Management cstecgi.cgi setFirewallType os command injection
48RISCO
abrir
Referência
CVE-2026-9406
Totolink A8000RU Web Management cstecgi.cgi setRemoteCfg os command injection
48RISCO
abrir
Referência
eBrigade ERP 4.5 - Arbitrary File Download
CVE-2019-9622webappsphp
eBrigade through 4.5 allows Arbitrary File Download via ../ directory traversal in the showfile.php file parameter, as d
23RISCO
abrir
Referência
CVE-2019-9670
CVE-2019-9670CRITICALsob ataque
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RISCO
abrir
Referência
CVE-2019-9670
CVE-2019-9670CRITICALsob ataque
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RISCO
abrir
Referência
CVE-2026-14300
miniOrange Social Login and Register < 7.8.0 - Unauthenticated Account Takeover
41RISCO
abrir
Referência
CVE-2026-14234
WOLF - WordPress Posts Bulk Editor and Manager < 1.1.0 - Stored XSS via CSRF
41RISCO
abrir
Referência
CVE-2026-14224
Easy Appointments < 3.12.28 - Subscriber+ Cross-User Appointment Data Modification via IDOR
33RISCO
abrir
Referência
CVE-2026-13692
PayU CommercePro < 3.9.0 - Unauthenticated Order Tampering
33RISCO
abrir
Referência
CVE-2019-9881
The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on
43RISCO
abrir
Referência
CVE-2019-9978
CVE-2019-9978MEDIUMsob ataque
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir
Referência
CVE-2020-0009
In calc_vm_may_flags of ashmem.c, there is a possible arbitrary write to shared memory due to a permissions bypass. This
23RISCO
abrir
Referência
CVE-2018-25342
Smartshop 1 SQL Injection via search.php
41RISCO
abrir
Referência
CVE-2018-25341
Smartshop 1 SQL Injection via product.php id Parameter
41RISCO
abrir
Referência
CVE-2020-0646
CVE-2020-0646CRITICALsob ataque
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.N
100RISCO
abrir
Referência
CVE-2020-0674
CVE-2020-0674HIGHsob ataque
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RISCO
abrir
Referência
CVE-2020-0688
CVE-2020-0688HIGHsob ataqueransomware
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
Referência
CVE-2020-0688
CVE-2020-0688HIGHsob ataqueransomware
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISCO
abrir
Referência
CVE-2020-0796
CVE-2020-0796CRITICALsob ataqueransomware
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
anteriorpágina 492 / 745próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.