Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.137exploits catalogados
35.961CVEs com exploração pública
24.695testados em laboratório
22.657 exploits
ReferênciaVexDay Proof
Yourownbux 4.0 - 'cookie' SQL Injection
CVE-2008-4492webappsphp
SQL injection vulnerability in referrals.php in YourOwnBux 4.0 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
ReferênciaVexDay Proof
Mambo Component MGM 0.95r2 - Remote File Inclusion
CVE-2006-3980webappsphp
PHP remote file inclusion vulnerability in administrator/components/com_mgm/help.mgm.php in Mambo Gallery Manager (MGM)
23RISCO
abrir
Referência
CVE-2026-9442
Edimax BR-6478AC POST Request formiNICSiteSurvey buffer overflow
41RISCO
abrir
Referência
CVE-2017-16781
The installer in MyBB before 1.8.13 has XSS.
23RISCO
abrir
ReferênciaVexDay Proof
YACS CMS 6.6.1 - context[path_to_root] Remote File Inclusion
CVE-2006-4532webappsphp
PHP remote file inclusion vulnerability in articles/article.php in Yet Another Community System (YACS) CMS 6.6.1 and ear
23RISCO
abrir
ReferênciaVexDay Proof
CMS Frogss 0.4 - 'podpis' SQL Injection
CVE-2006-4536webappsphp
SQL injection vulnerability in module/rejestracja.php in CMS Frogss 0.4 and earlier allows remote attackers to execute a
23RISCO
abrir
Referência
CVE-2010-3210
Multiple PHP remote file inclusion vulnerabilities in Multi-lingual E-Commerce System 0.2 allow remote attackers to exec
23RISCO
abrir
ReferênciaVexDay Proof
PhpReactor 1.2.7pl1 - 'pathtohomedir' Remote File Inclusion
CVE-2006-3983webappsphp
PHP remote file inclusion vulnerability in editprofile.php in php(Reactor) 1.27pl1 allows remote attackers to execute ar
23RISCO
abrir
Referência
CVE-2021-22986
CVE-2021-22986CRITICALsob ataqueransomware
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir
Referência
CVE-2010-3211
Multiple SQL injection vulnerabilities in the JE FAQ Pro (com_jefaqpro) component 1.5.0 for Joomla! allow remote attacke
23RISCO
abrir
Referência
CVE-2010-3212
SQL injection vulnerability in index.php in Seagull 0.6.7 and earlier allows remote attackers to execute arbitrary SQL c
23RISCO
abrir
Referência
CVE-2026-16327
D-Link DNS-320 upload.php unrestricted upload
33RISCO
abrir
Referência
CVE-2026-76582
TRENDnet TEW-821DAP ssi ping.cgi system command injection
33RISCO
abrir
Referência
CVE-2026-76576
yangzongzhuan RuoYi-Vue Common Download Endpoint CommonController.java resourceDownload path traversal
33RISCO
abrir
Referência
CVE-2026-11868
WP Travel < 11.7.1 - Unauthenticated Arbitrary Booking Cancellation
33RISCO
abrir
Referência
CVE-2026-76574
code-projects Hospital Information System User Login UsersController.php login sql injection
33RISCO
abrir
Referência
CVE-2026-61518
ISPConfig Authenticated SQL Injection via Remote API primary_id Parameter
41RISCO
abrir
Referência
CVE-2026-75148
cgltf 1.15 Integer Overflow via cgltf_validate() Accessor Bounds Check
13RISCO
abrir
Referência
CVE-2026-19842
SAML Single Sign On 4.8.85 - 5.4.6 - Unauthenticated Administrator Account Takeover via SAML Trust Anchor Overwrite
41RISCO
abrir
Referência
CVE-2026-19782
WPS Bidouille < 1.33.5 - Subscriber+ User Email Disclosure via wps_get_users
33RISCO
abrir
Referência
CVE-2026-19709
Membership For WooCommerce < 3.1.2 - Unauthenticated Member Data Disclosure via REST Consumer Secret Bypass
33RISCO
abrir
Referência
CVE-2026-19417
KiviCare < 4.5.4 - Patient+ Arbitrary Media Attachment Read via IDOR
33RISCO
abrir
ReferênciaVexDay Proof
GuildFTPd 0.999.8.11/0.999.14 - Heap Corruption (PoC) / Denial of Service
CVE-2008-4572doswindows
GuildFTPd 0.999.14, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possib
50RISCO
abrir
ReferênciaVexDay Proof
phpAuction 2.1 - 'phpAds_path' Remote File Inclusion
CVE-2006-3984webappsphp
PHP remote file inclusion vulnerability in phpAdsNew/view.inc.php in Albasoftware Phpauction 2.1 and possibly later vers
23RISCO
abrir
ReferênciaVexDay Proof
MunzurSoft Wep Portal W3 - 'kat' SQL Injection
CVE-2008-4573webappsasp
SQL injection vulnerability in kategori.asp in MunzurSoft Wep Portal W3 allows remote attackers to execute arbitrary SQL
23RISCO
abrir
Referência
CVE-2016-2494
Off-by-one error in sdcard/sdcard.c in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before
23RISCO
abrir
Referência
CVE-2026-12197
Ruijie EG105G-P JSON-RPC Diagnose Endpoint diagnose nslookup command injection
41RISCO
abrir
Referência
CVE-2016-2494
Off-by-one error in sdcard/sdcard.c in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before
23RISCO
abrir
Referência
CVE-2026-25558
QloApps 1.7.0 Stored XSS via SVG File Upload in Admin File Manager
13RISCO
abrir
ReferênciaVexDay Proof
Hummingbird Deployment Wizard 2008 - ActiveX Command Execution
CVE-2008-4728remotewindows
Multiple insecure method vulnerabilities in the DeployRun.DeploymentSetup.1 (DeployRun.dll) ActiveX control 10.0.0.44 in
35RISCO
abrir
anteriorpágina 675 / 756próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.