Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.214exploits catalogados
36.016CVEs com exploração pública
24.695testados em laboratório
22.697 exploits
Referência
CVE-2014-5287
A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input i
23RISCO
abrir
Referência
CVE-2026-19898
VictoriaMetrics VMAuth Authentication Endpoint main.go requestHandler excessive authentication
33RISCO
abrir
Referência
CVE-2014-5345
Cross-site scripting (XSS) vulnerability in upgrade.php in the Disqus Comment System plugin before 2.76 for WordPress al
23RISCO
abrir
Referência
CVE-2017-0148
CVE-2017-0148HIGHsob ataqueransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Referência
CVE-2026-8289
Open5GS SMF nsmf-handler.c smf_nsmf_handle_update_data_in_vsmf denial of service
33RISCO
abrir
Referência
CVE-2026-19838
Webkul Bagisto Backend Reporting Endpoint sales authorization
33RISCO
abrir
Referência
CVE-2011-0611
CVE-2011-0611HIGHsob ataque
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; A
100RISCO
abrir
Referência
CVE-2013-3214
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
60RISCO
abrir
Referência
CVE-2014-5347
Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin before 2.76 for WordPress
23RISCO
abrir
Referência
CVE-2026-19825
SourceCodester Simple Client Management System Master.php save_service sql injection
33RISCO
abrir
Referência
CVE-2026-19787
SourceCodester Air Cargo Management System Master.php save_cargo_type sql injection
33RISCO
abrir
ReferênciaVexDay Proof
FaScript FaPersianHack 1.0 - SQL Injection
CVE-2008-0326webappsphp
SQL injection vulnerability in class/show.php in FaScript FaPersianHack 1.0 allows remote attackers to execute arbitrary
23RISCO
abrir
Referência
CVE-2014-5395
Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3276 and E3236 TCPU before V200R002B470D13S
23RISCO
abrir
Referência
CVE-2026-5633
assafelovic gpt-researcher ws Endpoint server-side request forgery
33RISCO
abrir
Referência
CVE-2014-5520
SQL injection vulnerability in XRMS CRM, possibly 1.99.2, allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
Referência
CVE-2014-6030
Multiple SQL injection vulnerabilities in ClassApps SelectSurvey.NET before 4.125.002 allow (1) remote attackers to exec
23RISCO
abrir
Referência
CVE-2014-6043
ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database
28RISCO
abrir
Referência
CVE-2018-25235
NetworkActiv Web Server 4.0 Username Field Buffer Overflow DoS
33RISCO
abrir
Referência
CVE-2018-25234
SmartFTP Client 9.0.2615.0 Denial of Service via Host Field
33RISCO
abrir
Referência
CVE-2018-25233
WebDrive 18.00.5057 Denial of Service via Secure WebDAV
33RISCO
abrir
Referência
CVE-2018-25232
Softros LAN Messenger 9.2 Denial of Service via Log Files Location
33RISCO
abrir
Referência
CVE-2018-25231
HeidiSQL 9.5.0.5196 Denial of Service via Preferences
33RISCO
abrir
Referência
CVE-2018-25230
Free IP Switcher 3.1 Denial of Service via Computer Name
33RISCO
abrir
Referência
CVE-2018-25229
BulletProof FTP Server 2019.0.0.50 Denial of Service via SMTP
33RISCO
abrir
Referência
CVE-2018-25228
NetSetMan 4.7.1 Workgroup Buffer Overflow Denial of Service
33RISCO
abrir
Referência
CVE-2018-25227
Valentina Studio 9.0.4 Denial of Service via Host Parameter
33RISCO
abrir
Referência
CVE-2018-25226
FTPShell Server 6.83 Denial of Service via Account Name
33RISCO
abrir
ReferênciaVexDay Proof
Exponent CMS 0.96.3 - 'view' Remote Command Execution
CVE-2006-4963webappsphp
Directory traversal vulnerability in index.php in Exponent CMS 0.96.3 allows remote attackers to read and execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
PHP-Nuke Module books SQL - 'cid' SQL Injection
CVE-2008-0827webappsphp
SQL injection vulnerability in the Books module of PHP-Nuke allows remote attackers to execute arbitrary SQL commands vi
23RISCO
abrir
Referência
CVE-2013-4950
Cross-site scripting (XSS) vulnerability in view.php in Machform 2 allows remote attackers to inject arbitrary web scrip
23RISCO
abrir
anteriorpágina 699 / 757próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.