Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
76.496exploits catalogados
34.964CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.899GitHub PoC 13.937VulnCheck XDB 8.510Nuclei 4.239Metasploit 3.468✓ só verificadosrecentespopularesrisco
21.797 exploits
Referência
CVE-2009-3307
Multiple PHP remote file inclusion vulnerabilities in FSphp 0.2.1 allow remote attackers to execute arbitrary PHP code v
23RISCO
abrir ↗Referência
CVE-2019-6780
The Wise Chat plugin before 2.7 for WordPress mishandles external links because rendering/filters/post/WiseChatLinksPost
23RISCO
abrir ↗Referência
CVE-2026-18720
kalcaddle kodbox msgWarning Plugin action improper authorization
30RISCO
abrir ↗Referência
CVE-2026-18686
GL.iNet GL-MT3000 nas-web RPC Wrapper glc nas-web.add_user command injection
45RISCO
abrir ↗Referência
CVE-2011-0507
FTPService.exe in Blackmoon FTP 3.1 Build 1735 and Build 1736 (3.1.7.1736), and possibly other versions before 3.1.8.173
23RISCO
abrir ↗Referência
CVE-2014-1695
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) 3.1.x before 3.1.20, 3.2.x before 3.2.15,
23RISCO
abrir ↗Referência
CVE-2014-1695
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) 3.1.x before 3.1.20, 3.2.x before 3.2.15,
23RISCO
abrir ↗Referência
CVE-2018-5954
phpFreeChat 1.7 and earlier allows remote attackers to cause a denial of service by sending a large number of connect co
23RISCO
abrir ↗Referência
CVE-2018-5954
phpFreeChat 1.7 and earlier allows remote attackers to cause a denial of service by sending a large number of connect co
23RISCO
abrir ↗Referência
CVE-2012-5533
The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial o
28RISCO
abrir ↗Referência
CVE-2026-18684
GL.iNet GL-MT3000 modem.so glc remove_profile command injection
45RISCO
abrir ↗Referência✓ VexDay Proof
phpProfiles 3.1.2b - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in phpProfiles 3.1.2b and earlier allow remote attackers to execute a
23RISCO
abrir ↗Referência✓ VexDay Proof
SCart 2.0 - 'page' Remote Code Execution
scart.cgi in SCart 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the page parame
23RISCO
abrir ↗Referência✓ VexDay Proof
ViRC 2.0 - JOIN Response Remote Overwrite (SEH)
Stack-based buffer overflow in Visual IRC (ViRC) 2.0 allows remote IRC servers to execute arbitrary code via a long resp
23RISCO
abrir ↗Referência✓ VexDay Proof
Web Wiz Rich Text Editor 4.0 - Multiple Vulnerabilities
Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02,
23RISCO
abrir ↗Referência✓ VexDay Proof
FAQ Manager 1.2 - 'header.php' Remote File Inclusion
PHP remote file inclusion vulnerability in include/header.php in Werner Hilversum FAQ Manager 1.2, when register_globals
23RISCO
abrir ↗Referência
CVE-2016-9566
base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root
23RISCO
abrir ↗Referência
CVE-2018-7704
SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read arbitrary e-mail messages via the option1
23RISCO
abrir ↗Referência
CVE-2026-18645
danpros HTMLy Admin Content Endpoint admin.php add_content path traversal
30RISCO
abrir ↗Referência
CVE-2026-18644
danpros HTMLy Delete Username Endpoint htmly.php unlink path traversal
30RISCO
abrir ↗Referência
CVE-2026-18641
Sangfor Operation and Maintenance Security Management System Login Endpoint portal_login com.sbr.fort.foreignDP.DpLoginController os command injection
30RISCO
abrir ↗Referência
CVE-2026-18632
langgenius dify Jinja2 jinja2_transformer.py jinja2.Template special elements used in a template engine
30RISCO
abrir ↗Referência
CVE-2026-18631
jeequan jeepay PreAuthorize SysLogController.java WebSecurityConfig authorization
30RISCO
abrir ↗Referência
CVE-2026-67599
ClearOS 7.9 OS Command Injection via Log Viewer filter parameter
38RISCO
abrir ↗Referência
CVE-2026-18616
GL-iNet GL-MT3000 wg-server.so Native Plugin glc server.set_peer command injection
45RISCO
abrir ↗Referência
CVE-2011-5148
Multiple incomplete blacklist vulnerabilities in the Simple File Upload (mod_simplefileuploadv1.3) module before 1.3.5 f
23RISCO
abrir ↗Referência
CVE-2018-9128
DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068.
23RISCO
abrir ↗Referência
CVE-2018-9128
DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068.
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.