Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.533exploits catalogados
35.607CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.455Referência 22.407GitHub PoC 14.247VulnCheck XDB 8.663Nuclei 4.287Metasploit 3.474✓ só verificadosrecentespopularesrisco
22.407 exploits
Referência
CVE-2025-14870
Allocation of Resources Without Limits or Throttling in GitLab
41RISCO
abrir ↗Referência
CVE-2026-3607
Access Control Check Implemented After Asset is Accessed in GitLab
33RISCO
abrir ↗Referência
CVE-2026-9478
Totolink A8000RU Web Management cstecgi.cgi setParentalRules os command injection
48RISCO
abrir ↗Referência
CVE-2026-19375
dmitriiweb article-scraper-mcp server.py fetch_article server-side request forgery
33RISCO
abrir ↗Referência
WebERP 4.15 - SQL injection
A SQL Injection issue was discovered in webERP 4.15. Payments.php accepts payment data in base64 format. After this is d
23RISCO
abrir ↗Referência
CVE-2019-1346
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Servi
28RISCO
abrir ↗Referência
CVE-2019-13494
nodeimp.exe in Castle Rock SNMPc before 9.0.12.1 and 10.x before 10.0.9 has a stack-based buffer overflow via a long var
23RISCO
abrir ↗Referência
CVE-2019-13529
An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform action
41RISCO
abrir ↗Referência
CVE-2019-13529
An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform action
41RISCO
abrir ↗Referência
CentOS Control Web Panel 0.9.8.836 - Authentication Bypass
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.838 to 0.9.8.846, remote attackers can bypass authentication in
28RISCO
abrir ↗Referência
CVE-2019-3396
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISCO
abrir ↗Referência
CVE-2026-16965
Solace Extra < 1.6.1 - Subscriber+ Post Meta Update via solace_update_sitebuilder_status
33RISCO
abrir ↗Referência
CVE-2026-16957
Slim SEO < 4.9.11 - Contributor+ Arbitrary Post Meta Disclosure
28RISCO
abrir ↗Referência
CVE-2026-16562
WP Statistics < 14.16.10 - Subscriber+ Sensitive Data Disclosure via Metabox AJAX Handlers
33RISCO
abrir ↗Referência
CVE-2026-16558
YMC Filter < 3.12.8 - Contributor+ Stored XSS via Layout Builder Schema
33RISCO
abrir ↗Referência
CVE-2026-16535
Link Library < 7.9.4 - Reflected XSS via Thumbs-Rating likelabel
33RISCO
abrir ↗Referência
CVE-2026-16282
Appointment Hour Booking < 1.5.88 - Unauthenticated Booking Price Manipulation via tcost Parameter
33RISCO
abrir ↗Referência
CVE-2026-19231
SourceCodester Simple Doctors Appointment System ajax.php delete_appointment sql injection
33RISCO
abrir ↗Referência
CVE-2026-8782
omec-project amf NGAP Message handler.go null pointer dereference
33RISCO
abrir ↗Referência
CVE-2019-5418
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISCO
abrir ↗Referência
CVE-2019-14347
Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an ad
23RISCO
abrir ↗Referência
WordPress Plugin UserPro 4.9.32 - Cross-Site Scripting
cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has X
60RISCO
abrir ↗Referência
CVE-2019-14696
Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter.
43RISCO
abrir ↗Referência
CVE-2021-47962
Savsoft Quiz 5.0 Persistent Cross-Site Scripting via User Settings
33RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.