Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.020exploits catalogados
35.276CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.446Referência 22.166GitHub PoC 14.080VulnCheck XDB 8.604Nuclei 4.251Metasploit 3.473✓ só verificadosrecentespopularesrisco
22.166 exploits
Referência
CVE-2017-6331
Prior to SEP 14 RU1 Symantec Endpoint Protection product can encounter an issue of Tamper-Protection Bypass, which is a
23RISCO
abrir ↗Referência
CVE-2009-4748
SQL injection vulnerability in mycategoryorder.php in the My Category Order plugin 2.8 and earlier for WordPress allows
23RISCO
abrir ↗Referência
CVE-2009-4748
SQL injection vulnerability in mycategoryorder.php in the My Category Order plugin 2.8 and earlier for WordPress allows
23RISCO
abrir ↗Referência✓ VexDay Proof
UBBCentral UBB.Threads 6.4.x < 6.5.2 - 'thispath' Remote File Inclusion
PHP remote file inclusion vulnerability in addpost_newpoll.php in UBB.threads 6.4 through 6.5.2 and 6.5.1.1 (trial) allo
23RISCO
abrir ↗Referência
CVE-2015-1517
SQL injection vulnerability in Piwigo before 2.7.4, when all filters are activated, allows remote authenticated users to
23RISCO
abrir ↗Referência
CVE-2010-0967
Multiple directory traversal vulnerabilities in Geekhelps ADMP 1.01, when magic_quotes_gpc is disabled, allow remote att
23RISCO
abrir ↗Referência
CVE-2024-27620
An issue in Ladder v.0.0.1 thru v.0.0.21 allows a remote attacker to obtain sensitive information via a crafted request
41RISCO
abrir ↗Referência✓ VexDay Proof
Sisfo Kampus 2006 - 'dwoprn.php?f' Arbitrary File Download
Directory traversal vulnerability in dwoprn.php in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to read arbitr
23RISCO
abrir ↗Referência✓ VexDay Proof
JShop 1.x < 2.x - 'xPage' Local File Inclusion
Directory traversal vulnerability in v2demo/page.php in Jshop Server 1.x through 2.x allows remote attackers to include
23RISCO
abrir ↗Referência
CVE-2010-1475
Directory traversal vulnerability in the Preventive & Reservation (com_preventive) component 1.0.5 for Joomla! allows re
38RISCO
abrir ↗Referência✓ VexDay Proof
VidShare Pro - Arbitrary File Upload
Unrestricted file upload vulnerability in VidSharePro allows remote authenticated users to execute arbitrary code by upl
23RISCO
abrir ↗Referência
CVE-2026-12393
WPS Bookings for WooCommerce < 3.11.7 - Subscriber+ Arbitrary Booking Order Cancellation via IDOR
33RISCO
abrir ↗Referência
CVE-2014-2022
SQL injection vulnerability in includes/api/4/breadcrumbs_create.php in vBulletin 4.2.2, 4.2.1, 4.2.0 PL2, and earlier a
23RISCO
abrir ↗Referência✓ VexDay Proof
Monalbum 0.8.7 - Remote Code Execution
Static code injection vulnerability in admin/admin_configuration.php in Monalbum 0.8.7 allows remote authenticated users
23RISCO
abrir ↗Referência
CVE-2010-4313
Unrestricted file upload vulnerability in fileman_file_upload.php in Orbis CMS 1.0.2 allows remote authenticated users t
23RISCO
abrir ↗Referência✓ VexDay Proof
Poppawid 2.7 - 'form' Remote File Inclusion
PHP remote file inclusion vulnerability in mail/childwindow.inc.php in Poppawid 2.7 allows remote attackers to execute a
23RISCO
abrir ↗Referência
CVE-2025-34054
AVTECH IP camera, DVR, and NVR Devices Unauthenticated Command Injection
48RISCO
abrir ↗Referência
CVE-2025-34054
AVTECH IP camera, DVR, and NVR Devices Unauthenticated Command Injection
48RISCO
abrir ↗Referência
CVE-2014-3138
SQL injection vulnerability in Xerox DocuShare before 6.53 Patch 6 Hotfix 2, 6.6.1 Update 1 before Hotfix 24, and 6.6.1
23RISCO
abrir ↗Referência
CVE-2015-7252
Cross-site scripting (XSS) vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_
23RISCO
abrir ↗Referência
CVE-2012-6038
admin/core/admin_func.php in razorCMS before 1.2.1 does not properly restrict access to certain administrator directorie
23RISCO
abrir ↗Referência
aiohttp 3.9.1 - directory traversal PoC
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISCO
abrir ↗Referência
CVE-2010-1477
SQL injection vulnerability in the SermonSpeaker (com_sermonspeaker) component before 3.2.1 for Joomla! allows remote at
23RISCO
abrir ↗Referência✓ VexDay Proof
RunCMS 1.6 - Multiple Vulnerabilities
RunCMS before 1.6.1 uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a m
23RISCO
abrir ↗Referência✓ VexDay Proof
AlkalinePHP 0.77.35 - 'adduser.php' Arbitrary Add Admin
AlkalinePHP 0.77.35 and earlier allows remote attackers to bypass authentication and gain administrative access by creat
23RISCO
abrir ↗Referência✓ VexDay Proof
Tlnews 2.2 - Insecure Cookie Handling
TlNews 2.2 allows remote attackers to bypass authentication and gain administrative access by setting the tlNews_login c
23RISCO
abrir ↗Referência✓ VexDay Proof
adaptweb 0.9.2 - Local File Inclusion / SQL Injection
Directory traversal vulnerability in index.php in AdaptWeb 0.9.2 allows remote attackers to read arbitrary files via a .
23RISCO
abrir ↗Referência
CVE-2018-5978
SQL Injection exists in Facebook Style Php Ajax Chat Zechat 1.5 via the login.php User field.
23RISCO
abrir ↗Referência✓ VexDay Proof
Star FTP Server 1.10 - 'RETR' Remote Denial of Service
Fightersoft Multimedia Star FTP server 1.10 allows remote attackers to cause a denial of service (crash) via multiple RE
23RISCO
abrir ↗Referência
CVE-2018-6395
SQL Injection exists in the Visual Calendar 3.1.3 component for Joomla! via the id parameter in a view=load action.
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.