Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
76.496exploits catalogados
34.964CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.899GitHub PoC 13.937VulnCheck XDB 8.510Nuclei 4.239Metasploit 3.468✓ só verificadosrecentespopularesrisco
21.899 exploits
Referência
CVE-2017-13713
T&W WIFI Repeater BE126 allows remote authenticated users to execute arbitrary code via shell metacharacters in the user
23RISCO
abrir ↗Referência
CVE-2017-13867
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISCO
abrir ↗Referência
CVE-2026-58057
Flowise - Custom MCP Environment Variable Denylist Bypass via Case Sensitivity
28RISCO
abrir ↗Referência
CVE-2017-2482
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RISCO
abrir ↗Referência
CVE-2016-0073
The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 160
23RISCO
abrir ↗Referência
CVE-2018-12095
A Reflected Cross-Site Scripting web vulnerability has been discovered in the OEcms v3.1 web-application. The vulnerabil
38RISCO
abrir ↗Referência
CVE-2013-5578
Buffer overflow in the ToDot method in the WINGRAPHVIZLib.NEATO ActiveX control in WinGraphviz.dll in StarUML allows rem
23RISCO
abrir ↗Referência
CVE-2023-29983
Cross Site Scripting vulnerability found in Maximilian Vogt cmaps v.8.0 allows a remote attacker to execute arbitrary co
33RISCO
abrir ↗Referência
CVE-2017-2447
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISCO
abrir ↗Referência✓ VexDay Proof
Docebo 3.0.3 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow
23RISCO
abrir ↗Referência
CVE-2017-9127
The quicktime_user_atoms_read_atom function in useratoms.c in libquicktime 1.2.4 allows remote attackers to cause a deni
23RISCO
abrir ↗Referência
CVE-2022-2941
WP-UserOnline <= 2.88.0 - Authenticated (Admin+) Stored Cross-Site Scripting
33RISCO
abrir ↗Referência
CVE-2016-7617
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Bluetooth"
23RISCO
abrir ↗Referência
CVE-2009-3752
SQL injection vulnerability in home.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands via the g
23RISCO
abrir ↗Referência✓ VexDay Proof
MoviePlay 4.76 - '.lst' Local Buffer Overflow
Stack-based buffer overflow in MoviePlay 4.76 allows remote attackers to execute arbitrary code via a long filename in a
23RISCO
abrir ↗Referência
CVE-2015-10137
Website Contact Form With File Upload <= 1.3.4 - Arbitrary File Upload
63RISCO
abrir ↗Referência✓ VexDay Proof
Advanced Login 0.7 - 'root' Remote File Inclusion
PHP remote file inclusion vulnerability in login/engine/db/profiledit.php in Advanced Login 0.76 and earlier allows remo
23RISCO
abrir ↗Referência✓ VexDay Proof
TCExam 4.0.011 - 'SessionUserLang' Shell Injection
Dynamic variable evaluation vulnerability in shared/config/tce_config.php in TCExam 4.0.011 and earlier allows remote at
23RISCO
abrir ↗Referência✓ VexDay Proof
Madirish Webmail 2.0 - 'addressbook.php' Remote File Inclusion
PHP remote file inclusion vulnerability in lib/addressbook.php in Madirish Webmail 2.0 allows remote attackers to execut
23RISCO
abrir ↗Referência
CVE-2013-5092
Cross-site scripting (XSS) vulnerability in afa/php/Login.php in AlgoSec Firewall Analyzer 6.1-b86 allows remote attacke
23RISCO
abrir ↗Referência
CVE-2013-3538
Multiple cross-site scripting (XSS) vulnerabilities in todooforum.php in Todoo Forum 2.0 allow remote attackers to injec
23RISCO
abrir ↗Referência
CVE-2017-1002002
Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http:
28RISCO
abrir ↗Referência
CVE-2014-100030
Cross-site scripting (XSS) vulnerability in module/search/function.php in Ganesha Digital Library (GDL) 4.2 allows remot
23RISCO
abrir ↗Referência
CVE-2018-9172
The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.
23RISCO
abrir ↗Referência
CVE-2016-1609
Multiple cross-site scripting (XSS) vulnerabilities in Novell Filr before 1.2 Security Update 3 and 2.0 before Security
23RISCO
abrir ↗Referência
CVE-2011-4879
miniweb.exe in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA po
28RISCO
abrir ↗Referência
CVE-2019-7541
Rukovoditel through 2.4.1 allows XSS via a URL that lacks a module=users%2flogin substring.
23RISCO
abrir ↗Referência
CVE-2019-7541
Rukovoditel through 2.4.1 allows XSS via a URL that lacks a module=users%2flogin substring.
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.