Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
75.526exploits catalogados
34.478CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.534GitHub PoC 13.654VulnCheck XDB 8.213Nuclei 4.218Metasploit 3.464✓ só verificadosrecentespopularesrisco
75.526 exploits
Exploit-DB
OpenRepeater 2.1 - OS Command Injection
OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_sy
28RISCO
abrir ↗Exploit-DB
MobileDetect 2.8.31 - Cross-Site Scripting (XSS)
MobileDetect Example session_example.php initLayoutType cross site scripting
28RISCO
abrir ↗Exploit-DB
RosarioSIS 6.7.2 - Cross Site Scripting (XSS)
RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Preferences.php scrip
23RISCO
abrir ↗GitHub PoC
Untested completition of the Redishell PoC made by AI
Redis Lua Use-After-Free may lead to remote code execution
85RISCO
abrir ↗GitHub PoC★ 796
CVE-2025-55182 POC
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗Exploit-DB
RosarioSIS 6.7.2 - Cross-Site Scripting (XSS)
RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php sc
38RISCO
abrir ↗Exploit-DB
phpIPAM 1.4 - SQL-Injection
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.
23RISCO
abrir ↗Exploit-DB
PluckCMS 4.7.10 - Unrestricted File Upload
File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_resto
41RISCO
abrir ↗Exploit-DB
MaNGOSWebV4 4.0.6 - Reflected XSS
paintballrefjosh/MaNGOSWebV4 before 4.0.8 is vulnerable to a reflected XSS in install/index.php (step parameter).
38RISCO
abrir ↗Exploit-DB
phpMyAdmin 5.0.0 - SQL Injection
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could
35RISCO
abrir ↗Exploit-DB
phpMyFAQ 2.9.8 - Cross-Site Request Forgery(CSRF)
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.main.php.
23RISCO
abrir ↗Exploit-DB
phpMyFAQ 2.9.8 - Cross-Site Request Forgery (CSRF)
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for modifying a glossary.
23RISCO
abrir ↗Metasploit600
Unauthenticated RCE in React Server Components (React2Shell)
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISCO
abrir ↗Exploit-DB
phpMyFaq 2.9.8 - Cross Site Request Forgery (CSRF)
In phpMyFaq before 2.9.9, there is CSRF in admin/ajax.config.php.
23RISCO
abrir ↗Metasploit600
WordPress ACF Extended Unauthenticated RCE via prepare_form()
Advanced Custom Fields: Extended 0.9.0.5 - 0.9.1.1 - Unauthenticated Remote Code Execution in prepare_form
85RISCO
abrir ↗Exploit-DB
phpIPAM 1.6 - Reflected-Cross-Site Scripting (XSS)
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.
41RISCO
abrir ↗Exploit-DB
phpIPAM 1.6 - Reflected Cross-Site Scripting (XSS)
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php.
33RISCO
abrir ↗VulnCheck XDB
local
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RISCO
abrir ↗VulnCheck XDB
client-side
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1
83RISCO
abrir ↗Exploit-DB
YOURLS 1.8.2 - Cross-Site Request Forgery (CSRF)
Cross-Site Request Forgery (CSRF) in yourls/yourls
28RISCO
abrir ↗Exploit-DB
phpMyFAQ 3.1.7 - Reflected Cross-Site Scripting (XSS)
Cross-site Scripting (XSS) - Reflected in thorsten/phpmyfaq
56RISCO
abrir ↗GitHub PoC
boro03/CVE-2021-4034
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir ↗Exploit-DB
Piwigo 13.6.0 - SQL Injection
Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function.
48RISCO
abrir ↗GitHub PoC
This repo contain a PoC I have done when blind analysis the dbutil_2_3.sys driver for vulnerability. This was created by personal analysis without looking at writeups or even know which CVE exist in this driver. All the knowledge I have is that this driver is vulnerable in some way.
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RISCO
abrir ↗GitHub PoC
Vulnerable environment for testing CVE-2021-22941 Nuclei template
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacke
90RISCO
abrir ↗GitHub PoC
sudlit/CVE-2017-7494
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.