Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.302exploits catalogados
35.469CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.301GitHub PoC 14.141VulnCheck XDB 8.646Nuclei 4.289Metasploit 3.474✓ só verificadosrecentespopularesrisco
22.301 exploits
Referência✓ VexDay Proof
eXchange POP3 5.0.050203 - RPCT TO Remote Buffer Overflow
Buffer overflow in the POP3 server in Kinesphere Corporation eXchange before 5.0.060125 allows remote attackers to execu
35RISCO
abrir ↗Referência
CVE-2019-0539
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RISCO
abrir ↗Referência
CVE-2019-0539
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RISCO
abrir ↗Referência
CVE-2019-0708
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir ↗Referência
CVE-2019-0708
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir ↗Referência✓ VexDay Proof
Motorola Timbuktu Pro 8.6.5 - File Deletion/Creation
Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu P
50RISCO
abrir ↗Referência
CVE-2011-1048
SQL injection vulnerability in product.php in MihanTools 1.33 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir ↗Referência✓ VexDay Proof
Motorola Timbuktu Pro 8.6.5/8.7 - Directory Traversal / Log Injection
Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu P
50RISCO
abrir ↗Referência✓ VexDay Proof
eazyPortal 1.0 - 'cookie' SQL Injection
SQL injection vulnerability in index.php in eazyPortal 1.0 and earlier allows remote attackers to execute arbitrary SQL
23RISCO
abrir ↗Referência
CVE-2013-5758
cgi-bin/cgiServer.exx in Yealink VoIP Phone SIP-T38G allows remote authenticated users to execute arbitrary commands by
28RISCO
abrir ↗Referência✓ VexDay Proof
QuickTalk Forum 1.6 - Blind SQL Injection
SQL injection vulnerability in qtf_ind_search_ov.php in QT-cute QuickTalk Forum 1.6 and earlier allows remote attackers
23RISCO
abrir ↗Referência✓ VexDay Proof
Alt-N MDaemon IMAP server 9.6.4 - 'FETCH' Remote Buffer Overflow
Stack-based buffer overflow in the IMAP server in Alt-N Technologies MDaemon 9.6.4 allows remote authenticated users to
50RISCO
abrir ↗Referência✓ VexDay Proof
AuraCMS 2.2.1 - 'X-Forwarded-For' HTTP Header Blind SQL Injection
SQL injection vulnerability in online.php in AuraCMS 2.0 through 2.2.1 allows remote attackers to execute arbitrary SQL
23RISCO
abrir ↗Referência✓ VexDay Proof
eXV2 Module Viso 2.0.4.3 - 'kid' SQL Injection
SQL injection vulnerability in index.php in the Viso (Industry Book) 2.04 and 2.03 module for eXV2 allows remote attacke
23RISCO
abrir ↗Referência
CVE-2026-41471
Easy PayPal Events & Tickets < 1.4 Information Disclosure via QR Code Endpoint
41RISCO
abrir ↗Referência
CVE-2013-7091
Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zim
60RISCO
abrir ↗Referência✓ VexDay Proof
Prediction Football 1.x - 'matchid' SQL Injection
SQL injection vulnerability in showpredictionsformatch.php in Prediction Football 1.x allows remote attackers to execute
23RISCO
abrir ↗Referência✓ VexDay Proof
LiveCart 1.1.1 - 'id' Blind SQL Injection
SQL injection vulnerability in Integry Systems LiveCart 1.1.1 and earlier allows remote attackers to execute arbitrary S
23RISCO
abrir ↗Referência✓ VexDay Proof
KwsPHP Module ConcoursPhoto 2.0 - 'C_ID' SQL Injection
SQL injection vulnerability in the ConcoursPhoto module for KwsPHP allows remote attackers to execute arbitrary SQL comm
23RISCO
abrir ↗Referência
CVE-2016-20087
Fortitude HTTP 1.0.4.0 Unquoted Service Path Elevation of Privilege
41RISCO
abrir ↗Referência✓ VexDay Proof
Archangel Weblog 0.90.02 - 'post_id' SQL Injection
SQL injection vulnerability in index.php in Archangel Weblog 0.90.02 and earlier allows remote attackers to execute arbi
23RISCO
abrir ↗Referência
CVE-2019-1003002
A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src
60RISCO
abrir ↗Referência
CVE-2019-1003002
A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src
60RISCO
abrir ↗Referência
CVE-2019-10149
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISCO
abrir ↗Referência
CVE-2019-10149
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISCO
abrir ↗Referência
CVE-2019-10149
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISCO
abrir ↗Referência
CentOS Web Panel 0.9.8.789 - NameServer Field Persistent Cross-Site Scripting
CentOS Web Panel (CWP) 0.9.8.789 is vulnerable to Stored/Persistent XSS for the "Name Server 1" and "Name Server 2" fiel
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.