Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.302exploits catalogados
35.469CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.301GitHub PoC 14.141VulnCheck XDB 8.646Nuclei 4.289Metasploit 3.474✓ só verificadosrecentespopularesrisco
22.301 exploits
Referência
CVE-2011-1865
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow
60RISCO
abrir ↗Referência
CVE-2011-1865
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow
60RISCO
abrir ↗Referência
CentOS Web Panel 0.9.8.793 (Free) / 0.9.8.753 (Pro) - Cross-Site Scripting
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version) and 0.9.8.753 (Pro) is vulnerable to
23RISCO
abrir ↗Referência
CVE-2014-0329
The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account
23RISCO
abrir ↗Referência
CVE-2026-6149
code-projects Vehicle Showroom Management System BookVehicleFunction.php sql injection
33RISCO
abrir ↗Referência
D-Link DI-524 V2.06RU - Multiple Cross-Site Scripting
On D-Link DI-524 V2.06RU devices, multiple Stored and Reflected XSS vulnerabilities were found in the Web Configuration:
23RISCO
abrir ↗Referência
CVE-2026-12220
Yealink SIP-T46U Firmware Chunk Upload handler accupgradebychunk mod_upgrade.SparePartsUpload stack-based overflow
41RISCO
abrir ↗Referência
DirectAdmin 1.561 - Multiple Vulnerabilities
The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESE
23RISCO
abrir ↗Referência
CVE-2026-6597
langflow-ai langflow Flow Using API core.py has_api_terms credentials storage
33RISCO
abrir ↗Referência
CVE-2026-6596
langflow-ai langflow API Endpoint endpoints.py create_upload_file unrestricted upload
33RISCO
abrir ↗Referência
CVE-2026-6595
ProjectsAndPrograms School Management System HTTP GET Parameter buslocation.php sql injection
33RISCO
abrir ↗Referência
CVE-2014-0997
WiFiMonitor in Android 4.4.4 as used in the Nexus 5 and 4, Android 4.2.2 as used in the LG D806, Android 4.2.2 as used i
23RISCO
abrir ↗Referência
CVE-2026-6184
code-projects Simple Content Management System welcome.php cross site scripting
33RISCO
abrir ↗Referência
CVE-2026-6183
code-projects Simple Content Management System index.php sql injection
33RISCO
abrir ↗Referência
CVE-2026-6158
Totolink N300RH upgrade.so setUpgradeUboot os command injection
33RISCO
abrir ↗Referência
CVE-2026-6156
Totolink A7100RU CGI cstecgi.cgi setIpQosRules os command injection
48RISCO
abrir ↗Referência
CVE-2026-6155
Totolink A7100RU CGI cstecgi.cgi setWanCfg os command injection
48RISCO
abrir ↗Referência
CVE-2026-6154
Totolink A7100RU CGI cstecgi.cgi setWizardCfg os command injection
48RISCO
abrir ↗Referência
CVE-2026-6153
code-projects Vehicle Showroom Management System StaffDetailsFunction.php sql injection
33RISCO
abrir ↗Referência
CVE-2026-6152
code-projects Vehicle Showroom Management System StaffAddingFunction.php sql injection
33RISCO
abrir ↗Referência
CVE-2026-6151
code-projects Vehicle Showroom Management System PaymentStatusFunction.php sql injection
33RISCO
abrir ↗Referência
CVE-2026-6150
code-projects Simple Laundry System checkupdatestatus.php cross site scripting
33RISCO
abrir ↗Referência
CVE-2019-11354
The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Ori
28RISCO
abrir ↗Referência
CVE-2019-11354
The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Ori
28RISCO
abrir ↗Referência
CVE-2026-5484
BookStackApp BookStack Chapter Export ExportFormatter.php chapterToMarkdown access control
33RISCO
abrir ↗Referência
CVE-2026-5323
priyankark a11y-mcp index.js A11yServer server-side request forgery
33RISCO
abrir ↗Referência
CVE-2026-1540
Spam Protect for Contact Form 7 < 1.2.10 - Editor+ Remote Code Execution
41RISCO
abrir ↗Referência
CVE-2026-5322
AlejandroArciniegas mcp-data-vis MCP server.js request sql injection
33RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.