Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8.829Nuclei 4.350Metasploit 3.489✓ só verificadosrecentespopularesrisco
22.721 exploits
Referência✓ VexDay Proof
ForumApp 3.3 - Remote Database Disclosure
ForumApp 3.3 stores sensitive information under the web root with insufficient access control, which allows remote attac
23RISCO
abrir ↗Referência
CVE-2020-25223
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511
100RISCO
abrir ↗Referência✓ VexDay Proof
KsIRC 1.3.12 - 'PRIVMSG' Remote Buffer Overflow (PoC)
KsIRC 1.3.12 allows remote attackers to cause a denial of service (crash) via a long PRIVMSG string when connecting to a
28RISCO
abrir ↗Referência✓ VexDay Proof
Butterfly ORGanizer 2.0.0 - Arbitrary Delete (Category/Account)
Butterfly Organizer 2.0.0 allows remote attackers to (1) delete arbitrary categories via a modified tablehere parameter
23RISCO
abrir ↗Referência✓ VexDay Proof
EgyPlus 7ml 1.0.1 - Authentication Bypass
Multiple SQL injection vulnerabilities in cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier, when magic_quo
23RISCO
abrir ↗Referência
CVE-2026-10236
SourceCodester Water Billing Management System User Management Endpoint Users.php save improper authorization
33RISCO
abrir ↗Referência
CVE-2019-15107
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir ↗Referência
CVE-2019-15107
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir ↗Referência✓ VexDay Proof
Comdev News Publisher 4.1.2 - SQL Injection
SQL injection vulnerability in home.news.php in Comdev News Publisher 4.1.2 allows remote attackers to execute arbitrary
23RISCO
abrir ↗Referência
CVE-2026-23760
SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API
100RISCO
abrir ↗Referência
CVE-2026-9377
SourceCodester SUP Online Shopping productedit.php cross site scripting
33RISCO
abrir ↗Referência✓ VexDay Proof
XPOZE Pro 3.05 - 'reed' SQL Injection
SQL injection vulnerability in account/user/mail.html in Xpoze Pro 3.05 and earlier allows remote authenticated users to
23RISCO
abrir ↗Referência✓ VexDay Proof
Xine-Lib 1.1.12 - NSF demuxer Stack Overflow (PoC)
Stack-based buffer overflow in the demux_nsf_send_chunk function in src/demuxers/demux_nsf.c in xine-lib 1.1.12 and earl
28RISCO
abrir ↗Referência✓ VexDay Proof
VideoLAN VLC Media Player 0.8.6e - Subtitle Parsing Local Buffer Overflow
Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle.c) in VLC 0.8.6e allows remote attackers to
28RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component xsstream-dm 0.01b - SQL Injection
SQL injection vulnerability in the xsstream-dm (com_xsstream-dm) component 0.01 Beta for Joomla! allows remote attackers
23RISCO
abrir ↗Referência✓ VexDay Proof
KwsPHP 1.3.456 Module Galerie - 'id_gal' SQL Injection
SQL injection vulnerability in index.php in the galerie module for KwsPHP 1.3.456 allows remote attackers to execute arb
23RISCO
abrir ↗Referência
CVE-2019-10068
An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions
100RISCO
abrir ↗Referência
CVE-2026-7228
SourceCodester Pizzafy Ecommerce System ajax.php get_cart_count sql injection
33RISCO
abrir ↗Referência
CVE-2019-15637
Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to informat
46RISCO
abrir ↗Referência
CVE-2012-1125
Unrestricted file upload vulnerability in uploadify/scripts/uploadify.php in the Kish Guest Posting plugin before 1.2 fo
28RISCO
abrir ↗Referência✓ VexDay Proof
LaserNet CMS 1.5 - SQL Injection
SQL injection vulnerability in index.php in Lasernet CMS 1.5 and 1.11, when magic_quotes_gpc is disabled, allows remote
23RISCO
abrir ↗Referência
CVE-2020-17530
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISCO
abrir ↗Referência✓ VexDay Proof
Web Calendar 4.1 - Blind SQL Injection
SQL injection vulnerability in one_day.php in Web Calendar Pro 4.1 and earlier allows remote attackers to execute arbitr
23RISCO
abrir ↗Referência
CVE-2019-7609
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISCO
abrir ↗Referência
CVE-2019-15889
The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by t
53RISCO
abrir ↗Referência✓ VexDay Proof
TR News 2.1 - 'nb' SQL Injection
SQL injection vulnerability in news.php in Tr Script News 2.1 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir ↗Referência✓ VexDay Proof
SFS EZ Webstore - 'where' SQL Injection
SQL injection vulnerability in SearchResults.php in Scripts For Sites (SFS) EZ e-store allows remote attackers to execut
23RISCO
abrir ↗Referência
CVE-2026-17434
nanocoai NanoClaw add_mcp_server request.ts handleAddMcpServer improper authorization
33RISCO
abrir ↗Referência
CVE-2026-65711
sysPass 3.2.11 Authenticated OS Command Injection via Backup Path
41RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.