Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
76.507exploits catalogados
34.969CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.899GitHub PoC 13.944VulnCheck XDB 8.510Nuclei 4.243Metasploit 3.468✓ só verificadosrecentespopularesrisco
21.899 exploits
Referência
CVE-2026-48559
Lightweight Music Server 3.76.0 Stored XSS via Media File Metadata Tags
33RISCO
abrir ↗Referência
CVE-2026-10258
itsourcecode Content Management System add_sub_topic.php sql injection
33RISCO
abrir ↗Referência
CVE-2026-10253
itsourcecode Online House Rental System manage_payment.php sql injection
33RISCO
abrir ↗Referência✓ VexDay Proof
N/X WCMS 4.1 - 'nxheader.inc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in wwwdev/nxheader.inc.php in N/X 2002 Professional Edition Web Content Manageme
23RISCO
abrir ↗Referência✓ VexDay Proof
phpProfiles 2.1 Beta - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in phpProfiles 2.1 Beta allow remote attackers to execute arbitrary P
23RISCO
abrir ↗Referência
CVE-2022-22954
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISCO
abrir ↗Referência
CVE-2018-11776
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir ↗Referência
CVE-2018-11776
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir ↗Referência✓ VexDay Proof
Techno Dreams Guestbook 1.0 - 'key' SQL Injection
SQL injection vulnerability in guestbookview.asp in Techno Dreams Guest Book 1.0 earlier allows remote attackers to exec
23RISCO
abrir ↗Referência
CVE-2009-4624
SQL injection vulnerability in download.php in Nicecoder iDesk allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir ↗Referência✓ VexDay Proof
Techno Dreams Announcement - 'key' SQL Injection
SQL injection vulnerability in MainAnnounce2.asp in Techno Dreams Announcement allows remote attackers to execute arbitr
23RISCO
abrir ↗Referência
CVE-2020-8515
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow
100RISCO
abrir ↗Referência
CVE-2018-7600
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir ↗Referência
CVE-2018-7600
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir ↗Referência
CVE-2018-7600
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir ↗Referência✓ VexDay Proof
phpBB Spider Friendly Module 1.3.10 - Remote File Inclusion
PHP remote file inclusion vulnerability in admin/modules_data.php in the phpBB module Spider Friendly 1.3.10 and earlier
23RISCO
abrir ↗Referência✓ VexDay Proof
MySource CMS 2.16.2 - 'init_mysource.php' Remote File Inclusion
PHP remote file inclusion vulnerability in web/init_mysource.php in MySource CMS 2.16.2 and earlier allows remote attack
23RISCO
abrir ↗Referência✓ VexDay Proof
MiniBB 2.0.2 - 'bb_func_txt.php' Remote File Inclusion
PHP remote file inclusion vulnerability in bb_func_txt.php in miniBB 2.0.2 and earlier, when register_globals is enabled
23RISCO
abrir ↗Referência✓ VexDay Proof
Easy File Sharing Web Server 4 - Remote Information Stealer
Easy File Sharing (EFS) Web Server 4.0, when running on an NTFS file system, allows remote attackers to read arbitrary f
23RISCO
abrir ↗Referência✓ VexDay Proof
EFS Easy Address Book Web Server 1.2 - Remote File Stream
Easy File Sharing (EFS) Easy Address Book 1.2, when run on an NTFS file system, allows remote attackers to read arbitrar
23RISCO
abrir ↗Referência✓ VexDay Proof
AEP SmartGate 4.3b - 'GET' Arbitrary File Download
The SSL server in AEP Smartgate 4.3b allows remote attackers to determine existence of directories via a direct request
23RISCO
abrir ↗Referência✓ VexDay Proof
XM Easy Personal FTP Server 5.2.1 - Remote Denial of Service
XM Easy Personal FTP Server 5.2.1 and earlier allows remote authenticated users to cause a denial of service via a long
23RISCO
abrir ↗Referência✓ VexDay Proof
FreeWebShop.org script 2.2.2 - Multiple Vulnerabilities
Directory traversal vulnerability in index.php in FreeWebshop 2.2.1 and earlier allows remote attackers to read arbitrar
23RISCO
abrir ↗Referência✓ VexDay Proof
Creasito E-Commerce Content Manager - 'admin' Authentication Bypass
Creasito E-Commerce Content Manager 1.3.08 allows remote attackers to bypass authentication and perform privileged funct
23RISCO
abrir ↗Referência✓ VexDay Proof
iPrimal Forums - '/admin/index.php' Change User Password
admin/index.php in IPrimal Forums as of 20061105 allows remote attackers to bypass authentication and modify user passwo
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.