Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.137exploits catalogados
35.961CVEs com exploração pública
24.695testados em laboratório
22.657 exploits
Referência
CVE-2026-15373
Eleveo Call Recording Software userAddAction.do improper authorization
33RISCO
abrir
Referência
CVE-2019-3398
CVE-2019-3398HIGHsob ataque
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote at
100RISCO
abrir
Referência
CVE-2019-3398
CVE-2019-3398HIGHsob ataque
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote at
100RISCO
abrir
Referência
CVE-2014-6332
CVE-2014-6332HIGHsob ataque
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RISCO
abrir
Referência
CVE-2026-15190
SourceCodester Simple and Nice Shopping Cart Script login.php sql injection
33RISCO
abrir
Referência
CVE-2026-11406
GL.iNet MT3000 OpenVPN Client Import Workflow ovpnclient.sh command injection
33RISCO
abrir
Referência
CVE-2019-25727
WordPress Plugin ad manager wd 1.0.11 Arbitrary File Download
48RISCO
abrir
Referência
CVE-2019-25726
All in One Video Downloader 1.2 SQL Injection via admin page-edit
41RISCO
abrir
Referência
CVE-2026-10160
TRENDnet TEW-432BRP formSetEnableWizard stack-based overflow
41RISCO
abrir
Referência
CVE-2026-10159
TRENDnet TEW-432BRP formSysLog stack-based overflow
41RISCO
abrir
Referência
CVE-2026-10158
TRENDnet TEW-432BRP formPortFw stack-based overflow
41RISCO
abrir
Referência
CVE-2026-15471
Eleveo Call Recording Software pci_dss_status.jsp improper authorization
33RISCO
abrir
Referência
CVE-2026-15470
Eleveo Call Recording Software group.jsp improper authorization
33RISCO
abrir
Referência
CVE-2026-15311
NousResearch hermes-agent Matrix Adapter matrix.py MatrixAdapter._markdown_to_html cross site scripting
33RISCO
abrir
Referência
CVE-2026-10810
itsourcecode Fees Management System navbar.php cross site scripting
33RISCO
abrir
Referência
CVE-2026-7716
code-projects Gym Management System In PHP/Windows NT index.php sql injection
33RISCO
abrir
Referência
CVE-2026-7071
CodeAstro Online Job Portal user-cvs file information disclosure
33RISCO
abrir
Referência
CVE-2026-7070
code-projects Inventory Management System Login sql injection
33RISCO
abrir
Referência
CVE-2026-7069
D-Link DIR-825 miniupnpd upnpsoap.c AddPortMapping buffer overflow
41RISCO
abrir
Referência
CVE-2026-15547
Shibby Tomato CIFS Mount sub_2D048 os command injection
33RISCO
abrir
Referência
CVE-2026-47123
FreeScout: Agent Impersonation via Missing HMAC Verification on Notification Reply Message-ID Path
41RISCO
abrir
Referência
CVE-2026-29009
U-Boot < 2026.07-rc2 Buffer Overflow in nfs_readlink_reply() via NFS READLINK
41RISCO
abrir
Referência
CVE-2026-15703
SourceCodester Simple and Nice Shopping Cart Script userproductdeletequery.php sql injection
33RISCO
abrir
Referência
CVE-2018-25388
HaPe PKH 1.1 Arbitrary File Upload via aksi_foto.php
41RISCO
abrir
ReferênciaVexDay Proof
Rianxosencabos CMS 0.9 - Blind SQL Injection
CVE-2008-6014webappsphp
SQL injection vulnerability in scripts/links.php in Rianxosencabos CMS 0.9 allows remote attackers to execute arbitrary
23RISCO
abrir
Referência
CVE-2018-25387
HaPe PKH 1.1 Cross-Site Request Forgery via aksi_user.php
33RISCO
abrir
Referência
CVE-2018-25386
HaPe PKH 1.1 SQL Injection via id Parameter in admin/media.php
41RISCO
abrir
Referência
CVE-2018-25385
E-Registrasi Pencak Silat 18.10 SQL Injection via id_partai
41RISCO
abrir
Referência
CVE-2018-25384
Wikidforum 2.20 Cross-Site Scripting via reply_text Parameter
33RISCO
abrir
Referência
CVE-2014-7169
CVE-2014-7169CRITICALsob ataque
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RISCO
abrir
anteriorpágina 684 / 756próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.