Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.137exploits catalogados
35.961CVEs com exploração pública
24.695testados em laboratório
22.657 exploits
ReferênciaVexDay Proof
phpAuction - 'profile.php' SQL Injection (1)
CVE-2008-6663webappsphp
SQL injection vulnerability in profile.php in PHPAuctions.info PHPAuctions (aka PHPAuctionSystem) allows remote attacker
23RISCO
abrir
Referência
CVE-2016-5195
CVE-2016-5195HIGHsob ataque
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
ReferênciaVexDay Proof
nweb2fax 0.2.7 - Multiple Vulnerabilities
CVE-2008-6669webappsphp
viewrq.php in nweb2fax 0.2.7 and earlier allows remote attackers to execute arbitrary code via shell metacharacters in t
23RISCO
abrir
Referência
CVE-2016-5195
CVE-2016-5195HIGHsob ataque
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
Referência
CVE-2016-5195
CVE-2016-5195HIGHsob ataque
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
Referência
CVE-2016-5195
CVE-2016-5195HIGHsob ataque
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
Referência
CVE-2016-5195
CVE-2016-5195HIGHsob ataque
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
Referência
CVE-2016-5195
CVE-2016-5195HIGHsob ataque
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
Referência
CVE-2016-5195
CVE-2016-5195HIGHsob ataque
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
Referência
CVE-2026-75976
TRENDnet TEW-823DRU NVRAM wan.cgi strcpy stack-based overflow
48RISCO
abrir
Referência
CVE-2014-0329
The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account
23RISCO
abrir
Referência
CVE-2014-0476
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute a
38RISCO
abrir
Referência
CVE-2026-7121
Totolink A8000RU CGI cstecgi.cgi setWizardCfg os command injection
48RISCO
abrir
Referência
CVE-2026-16632
boazsegev facil.io WebSocket Frame websocket_parser.h websocket_on_protocol_error input validation
33RISCO
abrir
Referência
CVE-2026-16631
publint package-manager pack.js child_process.exec os command injection
33RISCO
abrir
Referência
CVE-2026-65013
Onlook tRPC Insecure Direct Object Reference via multiple procedures
41RISCO
abrir
ReferênciaVexDay Proof
Absolute Banner Manager - Insecure Cookie Handling
CVE-2008-6858webappsphp
Absolute Banner Manager .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by sett
23RISCO
abrir
Referência
CVE-2026-30368
A client-side authorization flaw in Lightspeed Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersona
33RISCO
abrir
Referência
CVE-2026-26210
KTransformers Unsafe Deserialization RCE via balance_serve
48RISCO
abrir
Referência
CVE-2026-6942
radare2-mcp <=1.6.0 OS Command Injection via Shell Metacharacter Bypass
28RISCO
abrir
Referência
CVE-2026-6941
radare2 < 6.1.4 Project Notes Path Traversal via Symlink
13RISCO
abrir
Referência
CVE-2026-6940
radare2 < 6.1.4 Project Deletion Path Traversal Directory Deletion
13RISCO
abrir
Referência
CVE-2026-25874
LeRobot Unsafe Deserialization Remote Code Execution via gRPC
53RISCO
abrir
Referência
CVE-2026-23751
Kofax Capture 6.0.0.0 Unauthenticated File Read/Write & SMB Coercion via .NET Remoting
48RISCO
abrir
Referência
CVE-2026-41460
SocialEngine <= 7.8.0 SQL Injection via activity/index/get-memberall
48RISCO
abrir
Referência
CVE-2026-4512
WP reCaptcha by WebDesignBy < 2.0 – Admin+ Stored XSS
28RISCO
abrir
Referência
CVE-2026-4106
HT Mega < 3.0.7 – Unauthenticated PII Disclosure
48RISCO
abrir
Referência
CVE-2026-6878
ByteDance verl grader.py math_equal sandbox
33RISCO
abrir
Referência
CVE-2026-6874
ericc-ch copilot-api Header token dns rebinding
33RISCO
abrir
Referência
CVE-2026-40517
radare2 < 6.1.4 Command Injection via PDB Parser Symbol Names
41RISCO
abrir
anteriorpágina 696 / 756próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.