Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.137exploits catalogados
35.961CVEs com exploração pública
24.695testados em laboratório
22.657 exploits
Referência
CVE-2026-7694
Acrel Electrical ECEMS Enterprise Microgrid Energy Efficiency Management System elecMaxMinAvgValue sql injection
33RISCO
abrir
Referência
CVE-2026-7692
Wavlink WL-WN570HA1 adm.cgi ping_ddns command injection
33RISCO
abrir
Referência
CVE-2026-7691
Wavlink WL-WN570HA1 adm.cgi set_sys_cmd command injection
33RISCO
abrir
Referência
CVE-2026-7690
Wavlink WL-WN570HA1 adm.cgi set_sys_adm command injection
33RISCO
abrir
Referência
CVE-2026-7689
Dolibarr ERP CRM Online Signature security.lib.php dol_verifyHash signature verification
33RISCO
abrir
Referência
CVE-2026-7687
langflow-ai langflow Full Builtins code_parser.py CodeParser.parse_callable_details command injection
33RISCO
abrir
Referência
CVE-2016-7255
CVE-2016-7255HIGHsob ataque
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RISCO
abrir
Referência
CVE-2016-7287
The scripting engines in Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary c
35RISCO
abrir
Referência
CVE-2014-4113
CVE-2014-4113HIGHsob ataque
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RISCO
abrir
Referência
CVE-2026-9386
Totolink A8000RU Web Management cstecgi.cgi setLanguageCfg os command injection
48RISCO
abrir
Referência
CVE-2026-9385
Totolink A8000RU Web Management cstecgi.cgi setTracerouteCfg os command injection
48RISCO
abrir
Referência
CVE-2026-9376
JPress UCenter Article Submission Endpoint doWriteSave improper authorization
33RISCO
abrir
Referência
CVE-2026-9372
ItzCrazyKns Vane Model Provider API route.ts server-side request forgery
33RISCO
abrir
Referência
CVE-2026-9371
ItzCrazyKns Vane API route.ts missing authentication
33RISCO
abrir
Referência
CVE-2026-9370
ulisesbocchio jasypt-spring-boot Password Hash SimpleGCMConfig.java getSecretKeySaltGenerator hash predictable salt
33RISCO
abrir
Referência
CVE-2026-10872
Shibby Tomato Web UI rc start_vpnserver os command injection
41RISCO
abrir
Referência
CVE-2026-10871
Shibby Tomato Web UI rc start_6rd_tunnel os command injection
41RISCO
abrir
Referência
CVE-2026-50266
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another p
28RISCO
abrir
Referência
CVE-2019-25745
WordPress Plugin Google Review Slider 6.1 SQL Injection via tid
41RISCO
abrir
Referência
CVE-2019-25735
AllPlayer 7.4 Local Buffer Overflow via SEH Unicode
41RISCO
abrir
Referência
CVE-2026-8764
H3C Magic B3 aspForm UpdateWanParams buffer overflow
41RISCO
abrir
Referência
CVE-2020-37244
WordPress Plugin Supsystic Membership 1.4.7 SQL Injection via sidx
41RISCO
abrir
Referência
CVE-2020-37243
WordPress Plugin Supsystic Pricing Table 1.8.7 SQL Injection XSS
41RISCO
abrir
Referência
CVE-2026-10809
itsourcecode Fees Management System manage_user.php sql injection
33RISCO
abrir
Referência
CVE-2026-7678
YunaiV yudao-cloud GoViewDataServiceImpl.java getDataBySQL sql injection
33RISCO
abrir
Referência
CVE-2026-7443
BurtTheCoder mcp-dnstwist MCP index.ts fuzz_domain os command injection
33RISCO
abrir
Referência
CVE-2012-1465
Stack-based buffer overflow in the HTTP Server in NetMechanica NetDecision before 4.6.1 allows remote attackers to cause
43RISCO
abrir
Referência
CVE-2026-7420
UTT HiPER 1250GW ConfigAdvideo strcpy buffer overflow
41RISCO
abrir
Referência
CVE-2026-7419
UTT HiPER 1250GW formTaskEdit_ap strcpy buffer overflow
41RISCO
abrir
Referência
CVE-2026-7418
UTT HiPER 1250GW NTP strcpy buffer overflow
41RISCO
abrir
anteriorpágina 692 / 756próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.