Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.533exploits catalogados
35.607CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.455Referência 22.407GitHub PoC 14.247VulnCheck XDB 8.663Nuclei 4.287Metasploit 3.474✓ só verificadosrecentespopularesrisco
22.407 exploits
Referência
CVE-2014-7176
SQL injection vulnerability in Enalean Tuleap before 7.5.99.4 allows remote authenticated users to execute arbitrary SQL
23RISCO
abrir ↗Referência
CVE-2009-3949
cp/profile.php in VivaPrograms Infinity 2.0.5 and earlier does not require administrative authentication for the donewau
23RISCO
abrir ↗Referência
CVE-2020-28092
PESCMS Team 2.3.2 has multiple reflected XSS via the id parameter:?g=Team&m=Task&a=my&status=3&id=,?g=Team&m=Task&a=my&s
23RISCO
abrir ↗Referência
CVE-2018-10109
Monstra CMS 3.0.4 has a stored XSS vulnerability when an attacker has access to the editor role, and enters the payload
23RISCO
abrir ↗Referência
CVE-2025-13188
D-Link DIR-816L authentication.cgi authenticationcgi_main stack-based overflow
48RISCO
abrir ↗Referência
CVE-2015-5285
CRLF injection vulnerability in Kallithea before 0.3 allows remote attackers to inject arbitrary HTTP headers and conduc
23RISCO
abrir ↗Referência
CVE-2009-3065
PHP remote file inclusion vulnerability in editor/edit_htmlarea.php in Ve-EDIT 0.1.4 allows remote attackers to execute
23RISCO
abrir ↗Referência
CVE-2018-1203
In Dell EMC Isilon OneFS, the compadmin is able to run tcpdump binary with root privileges. In versions between 8.1.0.0
23RISCO
abrir ↗Referência
CVE-2006-5209
PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Admin Topic Action Logging Mod 0.95 a
23RISCO
abrir ↗Referência
CVE-2010-2005
Multiple PHP remote file inclusion vulnerabilities in DataLife Engine (DLE) 8.3 allow remote attackers to execute arbitr
23RISCO
abrir ↗Referência
CVE-2016-7385
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RISCO
abrir ↗Referência✓ VexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
Unspecified vulnerability in IIS/iibind.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticate
23RISCO
abrir ↗Referência
CVE-2015-5287
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain perm
38RISCO
abrir ↗Referência
CVE-2009-3545
DataWizard Technologies FtpXQ FTP Server 3.0 allows remote authenticated users to cause a denial of service (crash) via
23RISCO
abrir ↗Referência
CVE-2021-33353
Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows at
48RISCO
abrir ↗Referência
CVE-2007-6191
Multiple PHP remote file inclusion vulnerabilities in Armin Burger p.mapper 3.2.0 beta3 allow remote attackers to execut
23RISCO
abrir ↗Referência
CVE-2012-1613
Cross-site scripting (XSS) vulnerability in edit_one_pic.php in Coppermine Photo Gallery before 1.5.20 allows remote aut
23RISCO
abrir ↗Referência
CVE-2012-1613
Cross-site scripting (XSS) vulnerability in edit_one_pic.php in Coppermine Photo Gallery before 1.5.20 allows remote aut
23RISCO
abrir ↗Referência
CVE-2017-16962
The WebMail components (Crystal, pronto, and pronto4) in CommuniGate Pro before 6.2.1 have stored XSS vulnerabilities vi
23RISCO
abrir ↗Referência
CVE-2017-16962
The WebMail components (Crystal, pronto, and pronto4) in CommuniGate Pro before 6.2.1 have stored XSS vulnerabilities vi
23RISCO
abrir ↗Referência
CVE-2011-4673
SQL injection vulnerability in modules/sharedaddy.php in the Jetpack plugin for WordPress allows remote attackers to exe
23RISCO
abrir ↗Referência
MyT Project Management 1.5.1 - User[username] Persistent Cross-Site Scripting
In MyT 1.5.1, the User[username] parameter has XSS.
23RISCO
abrir ↗Referência
CVE-2026-10230
Assimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_animations heap-based overflow
33RISCO
abrir ↗Referência✓ VexDay Proof
CcMail 1.0.1 - Insecure Cookie Handling
Cicoandcico CcMail 1.0.1 and earlier does not verify that the this_cookie cookie corresponds to an authenticated session
23RISCO
abrir ↗Referência✓ VexDay Proof
4Images 1.7.7 - Filter Bypass HTML Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in 4images 1.7.7 and earlier allows remote authenticated users to inject arbitr
23RISCO
abrir ↗Referência✓ VexDay Proof
Download Accelerator Plus DAP 8.x - '.m3u' File Buffer Overflow
Stack-based buffer overflow in DAP.exe in Download Accelerator Plus (DAP) 7.0.1.3, 8.6.6.3, and other 8.x versions allow
23RISCO
abrir ↗Referência✓ VexDay Proof
CCLeague Pro 1.2 - Insecure Cookie Authentication
admin.php in CCleague Pro 1.2 allows remote attackers to bypass authentication by setting the type cookie value to admin
23RISCO
abrir ↗Referência
CVE-2010-0665
JAG (Just Another Guestbook) 1.14 stores sensitive information under the web root with insufficient access control, whic
23RISCO
abrir ↗Referência
CVE-2015-5287
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain perm
38RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.