Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.813exploits catalogados
35.788CVEs com exploração pública
24.695testados em laboratório
22.549 exploits
Referência
CVE-2015-6104
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
35RISCO
abrir
Referência
CVE-2015-6152
Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
35RISCO
abrir
Referência
CVE-2015-6541
Multiple cross-site request forgery (CSRF) vulnerabilities in the Mail interface in Zimbra Collaboration Server (ZCS) be
23RISCO
abrir
Referência
CVE-2026-15245
BNE Testimonials < 2.0.8.2 - Contributor+ Stored XSS via Slider Shortcode
33RISCO
abrir
Referência
CVE-2026-15215
Subscriptions for WooCommerce < 2.0.1 - Shop Manager+ Arbitrary Plugin Installation
41RISCO
abrir
Referência
CVE-2014-6271
CVE-2014-6271CRITICALsob ataque
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
Referência
CVE-2014-6271
CVE-2014-6271CRITICALsob ataque
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
Referência
CVE-2014-6271
CVE-2014-6271CRITICALsob ataque
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
Referência
CVE-2014-6271
CVE-2014-6271CRITICALsob ataque
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
Referência
CVE-2014-6271
CVE-2014-6271CRITICALsob ataque
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
Referência
CVE-2026-70636
Flowise 3.1.4 Authentication Bypass via OAuth2 Credential Refresh Endpoint
41RISCO
abrir
Referência
CVE-2026-67622
Flowise 3.1.4 IDOR in OpenAI Assistants Integration
41RISCO
abrir
Referência
CVE-2026-67621
Flowise 3.1.4 Missing Authorization on Document Store Mutation Endpoints
41RISCO
abrir
Referência
CVE-2026-19110
DataGear Chart Name HtmlTplDashboardWidgetHtmlRenderer.java HtmlTplDashboardWidgetHtmlRenderer cross site scripting
33RISCO
abrir
Referência
CVE-2026-19071
itsourcecode Hospital Management System viewappointment.php sql injection
33RISCO
abrir
Referência
CVE-2026-19070
itsourcecode Hospital Management System viewadmin.php sql injection
33RISCO
abrir
Referência
CVE-2015-7857
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.p
60RISCO
abrir
Referência
CVE-2010-0467
Directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attac
50RISCO
abrir
Referência
CVE-2015-7858
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RISCO
abrir
Referência
CVE-2015-7890
Multiple buffer overflows in the esa_write function in /dev/seirenin the Exynos Seiren Audio driver, as used in Samsung
23RISCO
abrir
Referência
CVE-2021-33045
CVE-2021-33045CRITICALsob ataque
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISCO
abrir
Referência52
Scanner for CVE-2024-4040
CVE-2024-4040CRITICALsob ataque
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISCO
abrir
Referência
CVE-2026-18582
mz-automation libiec61850 Report Sending Path reporting.c Reporting_RCBWriteAccessHandler free of memory not on the heap
33RISCO
abrir
Referência
CVE-2015-8770
Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before
28RISCO
abrir
Referência
CVE-2010-0607
Cross-site scripting (XSS) vulnerability in Forms/status_statistics_1 in the Sterlite SAM300 AX Router allows remote att
23RISCO
abrir
Referência
CVE-2026-12500
WP Travel Engine < 6.8.2 - Unauthenticated Trip Difficulty Level Option Update
41RISCO
abrir
Referência
CVE-2026-11881
Fluent Forms < 6.2.6 - Contributor+ Stored XSS via Date/Time Field
33RISCO
abrir
Referência
CVE-2026-11870
Hide My WP Ghost < 7.0.05 - IP Address Spoofing via Trusted Proxy Headers Leading to Protection Mechanism Bypass
33RISCO
abrir
Referência
CVE-2016-0099
CVE-2016-0099HIGHsob ataqueransomware
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RISCO
abrir
Referência
CVE-2016-0099
CVE-2016-0099HIGHsob ataqueransomware
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RISCO
abrir
anteriorpágina 605 / 752próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.