Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.302exploits catalogados
35.469CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.301GitHub PoC 14.141VulnCheck XDB 8.646Nuclei 4.289Metasploit 3.474✓ só verificadosrecentespopularesrisco
22.266 exploits
Referência✓ VexDay Proof
NewzCrawler 1.8 - invalid string Remote Denial of Service
Unspecified vulnerability in NewzCrawler 1.8 allows remote attackers to cause a denial of service (application instabili
23RISCO
abrir ↗Referência
CVE-2018-16763
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir ↗Referência
CVE-2026-6623
BichitroGan ISP Billing Software Profile users-view cross site scripting
33RISCO
abrir ↗Referência
CVE-2026-6622
BichitroGan ISP Billing Software Customer edit cross site scripting
33RISCO
abrir ↗Referência
CVE-2026-6620
SonicCloudOrg sonic-server File Upload Endpoint FileTool.java upload path traversal
33RISCO
abrir ↗Referência
CVE-2026-6619
langgenius dify ImagePreview image-preview.tsx openInNewTab cross site scripting
33RISCO
abrir ↗Referência
CVE-2026-6618
langgenius dify ApiBasedToolSchemaParser parser.py parse_openai_plugin_json_to_tool_bundle server-side request forgery
33RISCO
abrir ↗Referência
CVE-2026-6616
TransformerOptimus SuperAGI WebScraperTool webpage_extractor.py extract_with_lxml server-side request forgery
33RISCO
abrir ↗Referência
CVE-2012-2396
VideoLAN VLC media player 2.0.1 allows remote attackers to cause a denial of service (divide-by-zero error and applicati
23RISCO
abrir ↗Referência
CVE-2026-7612
itsourcecode Courier Management System edit_user.php sql injection
33RISCO
abrir ↗Referência
CVE-2026-7609
TRENDnet TEW-821DAP Firmware Udpate diagnostic tools_diagnostic os command injection
33RISCO
abrir ↗Referência
CVE-2026-7545
SourceCodester Advanced School Management System checkEmail Endpoint commonController.php sql injection
33RISCO
abrir ↗Referência
CVE-2026-7538
Totolink A8000RU CGI cstecgi.cgi vulnerability os command injection
48RISCO
abrir ↗Referência
CVE-2026-7536
Open5GS BSF pcfBindings bsf_sess_add_by_ip_address denial of service
33RISCO
abrir ↗Referência
CVE-2012-2572
Cross-site scripting (XSS) vulnerability in the ThreeWP Email Reflector plugin before 1.16 for WordPress allows remote a
23RISCO
abrir ↗Referência
CVE-2018-17128
A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode.
45RISCO
abrir ↗Referência
CVE-2018-17173
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getT
50RISCO
abrir ↗Referência
CVE-2018-17173
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getT
50RISCO
abrir ↗Referência
CVE-2018-17173
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getT
50RISCO
abrir ↗Referência
CVE-2018-17376
SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter
23RISCO
abrir ↗Referência✓ VexDay Proof
Kravchuk letter script 1.0 - 'scdir' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Kravchuk letter (K-letter) 1.0 allow remote attackers to execute a
23RISCO
abrir ↗Referência
CVE-2026-6011
OpenClaw assertPublicHostname web-fetch.ts server-side request forgery
33RISCO
abrir ↗Referência
CVE-2026-6003
code-projects Simple IT Discussion Forum user.php cross site scripting
33RISCO
abrir ↗Referência
CVE-2018-25310
VideoFlow Digital Video Protection DVP 2.10 - Authenticated Remote Code Execution
33RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.