Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.302exploits catalogados
35.469CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.301GitHub PoC 14.141VulnCheck XDB 8.646Nuclei 4.289Metasploit 3.474✓ só verificadosrecentespopularesrisco
22.301 exploits
Referência
CVE-2018-25318
Tenda FH303/A300 V5.07.68_EN Cookie Session Weakness DNS Change
48RISCO
abrir ↗Referência
CVE-2018-25317
Tenda W3002R/A302/W309R V5.07.64_en Cookie Session Weakness DNS Change
48RISCO
abrir ↗Referência
CVE-2018-25315
Alloksoft Video joiner 4.6.1217 Buffer Overflow via License Name
41RISCO
abrir ↗Referência
CVE-2018-25314
Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217 Buffer Overflow
41RISCO
abrir ↗Referência
CVE-2018-25313
SysGauge 4.5.18 Local Denial of Service via Proxy Configuration
33RISCO
abrir ↗Referência
CVE-2018-17587
AirTies Air 5750 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
23RISCO
abrir ↗Referência
CVE-2018-17587
AirTies Air 5750 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
23RISCO
abrir ↗Referência
CVE-2026-5585
Tencent AI-Infra-Guard Task Detail Endpoint task_manager.go information disclosure
33RISCO
abrir ↗Referência
CVE-2026-5584
Fosowl agenticSeek query Endpoint PyInterpreter.py PyInterpreter.execute code injection
33RISCO
abrir ↗Referência
CVE-2026-5583
PHPGurukul Online Shopping Portal Project Parameter my-profile.php sql injection
33RISCO
abrir ↗Referência
CVE-2026-5580
CodeAstro Online Classroom Parameter addvideos.php sql injection
33RISCO
abrir ↗Referência
CVE-2026-5579
CodeAstro Online Classroom Parameter updatedetailsfromfaculty.php sql injection
33RISCO
abrir ↗Referência
CVE-2026-5578
CodeAstro Online Classroom Parameter addassessment.php sql injection
33RISCO
abrir ↗Referência
CVE-2026-5577
Song-Li cross_browser details Endpoint uniquemachine_app.py sql injection
33RISCO
abrir ↗Referência
CVE-2026-5576
SourceCodester/jkev Record Management System Add Employee save_emp.php unrestricted upload
33RISCO
abrir ↗Referência
CVE-2026-5575
SourceCodester/jkev Record Management System Login index.php sql injection
33RISCO
abrir ↗Referência
CVE-2018-18763
SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection.
23RISCO
abrir ↗Referência
CVE-2018-18772
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as dem
23RISCO
abrir ↗Referência
CVE-2018-18772
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as dem
23RISCO
abrir ↗Referência
CVE-2018-18773
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demo
23RISCO
abrir ↗Referência
CVE-2018-18774
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows XSS via the admin/index.php module parameter.
23RISCO
abrir ↗Referência
CVE-2018-18774
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows XSS via the admin/index.php module parameter.
23RISCO
abrir ↗Referência
CVE-2026-5181
SourceCodester Simple Doctors Appointment System ajax.php unrestricted upload
33RISCO
abrir ↗Referência
CVE-2026-5180
SourceCodester Simple Doctors Appointment System ajax.php sql injection
33RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.