Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.137exploits catalogados
35.961CVEs com exploração pública
24.695testados em laboratório
22.657 exploits
Referência
CVE-2026-75876
xianrendzw EasyReport Move Operations ModuleController.java sql injection
33RISCO
abrir
Referência
CVE-2026-70667
Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for CVE-2026-55162)
33RISCO
abrir
Referência20
PoC repository for the blog post CopyEscape: Taking Over Docker Hosts with docker cp
Tar extraction in moby/go-archive can write outside the destination directory via link following
41RISCO
abrir
Referência
CVE-2026-3430
Creative Mail 1.6.5 - 1.6.9 - Unauthenticated SQLi
41RISCO
abrir
Referência
CVE-2026-19035
Shibby Tomato qoslimit new_qoslimit_start os command injection
41RISCO
abrir
Referência
CVE-2026-19009
TinyAGI Message API Endpoint response.ts collectFiles file inclusion
33RISCO
abrir
Referência
CVE-2026-19008
mf-yang openclaw-cn apply_patch Tool sandbox-paths.ts assertNoSymlinkEscape link following
33RISCO
abrir
Referência
CVE-2026-19007
mf-yang openclaw-cn reply-elevated.ts isApprovedElevatedSender privileges management
33RISCO
abrir
Referência
CVE-2026-14204
Google Authenticator < 0.56 - 2FA Secret Overwrite via CSRF
33RISCO
abrir
Referência
CVE-2026-16537
Slick Slider < 0.5.3 - Contributor+ Stored XSS via Gallery Shortcode
33RISCO
abrir
ReferênciaVexDay Proof
Mole Group Pizza - 'manufacturers_id' SQL Injection
CVE-2008-5046webappsphp
SQL injection vulnerability in index.php in Mole Group Pizza Script allows remote attackers to execute arbitrary SQL com
23RISCO
abrir
Referência
CVE-2016-3081
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, a
60RISCO
abrir
ReferênciaVexDay Proof
Mole Group Rental Script - Authentication Bypass
CVE-2008-5047webappsphp
SQL injection vulnerability in admin/index.php in Mole Group Rental Script allows remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
Anti-Keylogger Elite 3.3.0 - 'AKEProtect.sys' Local Privilege Escalation
CVE-2008-5049localwindows
Buffer overflow in AKEProtect.sys 3.3.3.0 in ISecSoft Anti-Keylogger Elite 3.3.0 and earlier, and possibly other version
23RISCO
abrir
Referência
CVE-2021-24563
Frontend Uploader <= 1.3.2 - Unauthenticated Stored Cross-Site Scripting
28RISCO
abrir
Referência
CVE-2021-24931
Secure Copy Content Protection and Content Locking < 2.8.2 - Unauthenticated SQL Injection
60RISCO
abrir
Referência
CVE-2026-49136
Banana Slides 0.4.0 Path Traversal via generate_image() in ai_service.py
21RISCO
abrir
Referência
CVE-2026-43624
F5-TTS 1.1.20 Path Traversal via finetune_gradio.py create_data_project()
21RISCO
abrir
Referência
CVE-2026-43623
microtar 0.1.0 Stack-Based Buffer Overflow via raw_to_header()
21RISCO
abrir
Referência
CVE-2017-17623
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
23RISCO
abrir
Referência
CVE-2017-17623
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
23RISCO
abrir
Referência
CVE-2016-3223
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold an
28RISCO
abrir
Referência
CVE-2010-3428
SQL injection vulnerability in modules/notes/json.php in Intermesh Group-Office 3.5.9 allows remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
ZeusCart 2.0 - 'category_list.php' SQL Injection
CVE-2008-5216webappsphp
SQL injection vulnerability in category_list.php in AJ Square ZeusCart 2.0 and earlier allows remote attackers to execut
23RISCO
abrir
Referência
CVE-2016-3235
CVE-2016-3235HIGHsob ataque
Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 misha
98RISCO
abrir
Referência
CVE-2017-17624
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat o
23RISCO
abrir
Referência
CVE-2026-19650
Cross-Site Request Forgery (CSRF) in GitLab
41RISCO
abrir
Referência
CVE-2026-74842
Kira-Pgr PromptShopMCP Image-Toolkit-MCP-Server server.py download_image server-side request forgery
33RISCO
abrir
Referência
CVE-2026-20000
itsourcecode Hospital Management System viewprescriptionrecord.php sql injection
33RISCO
abrir
Referência
CVE-2026-16055
Contest Gallery < 30.0.7 - Unauthenticated Login-Protection and 2FA Bypass via post_cg_login
41RISCO
abrir
anteriorpágina 695 / 756próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.