Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.231exploits catalogados
35.420CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.266GitHub PoC 14.131VulnCheck XDB 8.635Nuclei 4.274Metasploit 3.474✓ só verificadosrecentespopularesrisco
22.266 exploits
Referência
CVE-2026-43500
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
78RISCO
abrir ↗Referência
CVE-2026-34103
Guardian Language-System Unauthenticated SQL Injection via id Parameter in subtitles.php
48RISCO
abrir ↗Referência
CVE-2017-6086
Multiple cross-site request forgery (CSRF) vulnerabilities in the addAction and purgeAction functions in ViMbAdmin 3.0.1
23RISCO
abrir ↗Referência
CVE-2017-6090
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authentica
60RISCO
abrir ↗Referência
CVE-2010-3962
Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary cod
100RISCO
abrir ↗Referência
CVE-2017-6090
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authentica
60RISCO
abrir ↗Referência
CVE-2010-5004
SQL injection vulnerability in searchvote.php in 2daybiz Polls (aka Advanced Poll) Script allows remote attackers to exe
23RISCO
abrir ↗Referência✓ VexDay Proof
Mumbo Jumbo Media OP4 - Blind SQL Injection
SQL injection vulnerability in Mumbo Jumbo Media OP4 allows remote attackers to execute arbitrary SQL commands via the i
23RISCO
abrir ↗Referência
CVE-2017-6178
The IofCallDriver function in USBPcap 1.1.0.0 allows local users to gain privileges via a crafted 0x00090028 IOCTL call,
23RISCO
abrir ↗Referência
CVE-2017-6371
Synchronet BBS 3.16c for Windows allows remote attackers to cause a denial of service (service crash) via a long string
23RISCO
abrir ↗Referência
CVE-2017-6444
The MikroTik Router hAP Lite 6.25 has no protection mechanism for unsolicited TCP ACK packets in the case of a fast netw
28RISCO
abrir ↗Referência
CVE-2017-6506
In Azure Data Expert Ultimate 2.2.16, the SMTP verification function suffers from a buffer overflow vulnerability, leadi
28RISCO
abrir ↗Referência
CVE-2017-7180
Net Monitor for Employees Pro through 5.3.4 has an unquoted service path, which allows a Security Feature Bypass of its
23RISCO
abrir ↗Referência
CVE-2017-7228
An issue (known as XSA-212) was discovered in Xen, with fixes available for 4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x. The e
23RISCO
abrir ↗Referência
CVE-2017-7269
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISCO
abrir ↗Referência
CVE-2017-7269
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISCO
abrir ↗Referência
CVE-2026-6492
arnobt78 Hotel Booking Management System Health Check Endpoint detailed information disclosure
33RISCO
abrir ↗Referência
CVE-2026-6490
QueryMine sms GET Request Parameter deletecourse.php sql injection
33RISCO
abrir ↗Referência
CVE-2026-6489
QueryMine sms Background Management addteacher.php unrestricted upload
33RISCO
abrir ↗Referência
CVE-2026-6488
QueryMine sms GET Request Parameter editcourse.php sql injection
33RISCO
abrir ↗Referência
CVE-2026-6486
classroombookings User Display Name layout.php read cross site scripting
33RISCO
abrir ↗Referência
CVE-2026-6148
code-projects Vehicle Showroom Management System MonthTotalReportUpdateFunction.php sql injection
33RISCO
abrir ↗Referência
CVE-2026-6140
Totolink A7100RU CGI cstecgi.cgi UploadFirmwareFile os command injection
48RISCO
abrir ↗Referência
CVE-2026-6139
Totolink A7100RU CGI cstecgi.cgi UploadOpenVpnCert os command injection
48RISCO
abrir ↗Referência
CVE-2026-6138
Totolink A7100RU CGI cstecgi.cgi setAccessDeviceCfg os command injection
48RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.