Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.620exploits catalogados
35.647CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.455Referência 22.429GitHub PoC 14.270VulnCheck XDB 8.693Nuclei 4.299Metasploit 3.474✓ só verificadosrecentespopularesrisco
22.429 exploits
Referência
CVE-2019-8927
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zon
23RISCO
abrir ↗Referência
CVE-2019-8928
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in /netflow/jspui/userMan
23RISCO
abrir ↗Referência
CVE-2019-9082
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public/
100RISCO
abrir ↗Referência
CVE-2026-42626
HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage concurrent TCP connections to port 9100 (JetD
33RISCO
abrir ↗Referência
CVE-2026-4929
Simple Hierarchical Select (Drupal 7) XSS in term-derived output
33RISCO
abrir ↗Referência
CVE-2019-9162
In the Linux kernel before 4.20.12, net/ipv4/netfilter/nf_nat_snmp_basic_main.c in the SNMP NAT module has insufficient
23RISCO
abrir ↗Referência
CVE-2019-9213
In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which make
38RISCO
abrir ↗Referência
CVE-2019-9213
In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which make
38RISCO
abrir ↗Referência
CVE-2019-9491
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to
28RISCO
abrir ↗Referência✓ VexDay Proof
Millewin 13.39.146.1 - Local Privilege Escalation
Millennium Millewin (also known as "Cartella clinica") 13.39.028, 13.39.28.3342, and 13.39.146.1 has insecure folder per
23RISCO
abrir ↗Referência
CVE-2026-9450
code-projects Employee Management System psubmit.php sql injection
33RISCO
abrir ↗Referência
CVE-2026-9449
code-projects Employee Management System changepassemp.php sql injection
33RISCO
abrir ↗Referência
CVE-2026-9448
code-projects Employee Management System applyleave.php cross site scripting
33RISCO
abrir ↗Referência
CVE-2026-9447
SourceCodester Simple POS and Inventory System search.php sql injection
33RISCO
abrir ↗Referência
CVE-2026-9446
SourceCodester Simple POS and Inventory System edit_customer.php sql injection
33RISCO
abrir ↗Referência
CVE-2026-9445
SourceCodester Simple POS and Inventory System File Extension addproduct.php unrestricted upload
33RISCO
abrir ↗Referência
CVE-2026-9444
SourceCodester Simple POS and Inventory System GET Parameter deleteproduct.php delete sql injection
33RISCO
abrir ↗Referência
CVE-2020-37232
Advanced System Care Service 13.0.0.157 Unquoted Service Path Privilege Escalation
41RISCO
abrir ↗Referência
CVE-2020-37231
Privacy Drive 3.17.0 Unquoted Service Path Privilege Escalation
41RISCO
abrir ↗Referência
Bolt CMS 3.6.4 - Cross-Site Scripting
Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and
23RISCO
abrir ↗Referência
CVE-2026-9432
Totolink A8000RU Web Management cstecgi.cgi setWiFiAdvancedCfg os command injection
48RISCO
abrir ↗Referência
CVE-2026-9430
Tenda F1202 GstDhcpSetSerof formGstDhcpSetSer stack-based overflow
41RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.