Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.900exploits catalogados
35.840CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.600GitHub PoC 14.323VulnCheck XDB 8.722Nuclei 4.320Metasploit 3.477✓ só verificadosrecentespopularesrisco
22.600 exploits
Referência
CVE-2010-2316
Multiple cross-site scripting (XSS) vulnerabilities in default.asp in WmsCms 2.0 and earlier allow remote attackers to i
23RISCO
abrir ↗Referência
CVE-2011-4899
wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not ensure that the specifie
23RISCO
abrir ↗Referência
CVE-2019-0730
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RISCO
abrir ↗Referência
CVE-2019-0730
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RISCO
abrir ↗Referência
CVE-2019-0731
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RISCO
abrir ↗Referência
CVE-2010-4233
The Linux installation on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1
23RISCO
abrir ↗Referência
CVE-2019-14749
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the ex
23RISCO
abrir ↗Referência
CVE-2017-6803
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly
23RISCO
abrir ↗Referência
CVE-2017-6803
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly
23RISCO
abrir ↗Referência
CVE-2017-8665
The Xamarin.iOS update component on systems running macOS allows an attacker to run arbitrary code as root, aka "Xamarin
23RISCO
abrir ↗Referência
CVE-2014-3415
SQL injection vulnerability in Sharetronix before 3.4 allows remote authenticated users to execute arbitrary SQL command
23RISCO
abrir ↗Referência
CVE-2024-25736
An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can restart the device via a /d
41RISCO
abrir ↗Referência
CVE-2013-5755
config/.htpasswd in Yealink IP Phone SIP-T38G has a hardcoded password of (1) user (s7C9Cx.rLsWFA) for the user account,
23RISCO
abrir ↗Referência✓ VexDay Proof
PA168 Chipset IP Phones - Weak Session Management
The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and ear
23RISCO
abrir ↗Referência
CVE-2014-5380
Grand MA 300 allows retrieval of the access PIN from sniffed data.
23RISCO
abrir ↗Referência✓ VexDay Proof
NEPT Image Uploader 1.0 - Arbitrary File Upload
Unrestricted file upload vulnerability in uploadp.php in New Earth Programming Team (NEPT) imgupload (aka Image Uploader
23RISCO
abrir ↗Referência✓ VexDay Proof
SpeedStream 5200 - Authentication Bypass Configuration Download
Siemens SpeedStream 5200 with NetPort Software 1.1 allows remote attackers to bypass authentication via an invalid Host
23RISCO
abrir ↗Referência✓ VexDay Proof
Remote Display Dev kit 1.2.1.0 - 'RControl.dll' Denial of Service
Multiple buffer overflows in RControl.dll in Remote Display Dev kit 1.2.1.0 allow remote attackers to cause a denial of
23RISCO
abrir ↗Referência✓ VexDay Proof
PHP recommend 1.3 - Authentication Bypass / Remote File Inclusion / Code Injection
Static code injection vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to inj
23RISCO
abrir ↗Referência
CVE-2011-5165
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RISCO
abrir ↗Referência
CVE-2019-14328
The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section.
23RISCO
abrir ↗Referência
CVE-2010-0757
Unrestricted file upload vulnerability in index.php/Attach in WikyBlog 1.7.3rc2 allows remote authenticated users to exe
23RISCO
abrir ↗Referência
CVE-2015-7259
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow user accounts to have multiple valid
23RISCO
abrir ↗Referência
CVE-2014-1665
Cross-site scripting (XSS) vulnerability in ownCloud before 6.0.1 allows remote authenticated users to inject arbitrary
23RISCO
abrir ↗Referência
CVE-2014-1665
Cross-site scripting (XSS) vulnerability in ownCloud before 6.0.1 allows remote authenticated users to inject arbitrary
23RISCO
abrir ↗Referência
CVE-2010-3899
IBM OmniFind Enterprise Edition 8.x and 9.x performs web crawls with an unlimited recursion depth, which allows remote w
23RISCO
abrir ↗Referência
CVE-2020-25270
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, o
23RISCO
abrir ↗Referência
CVE-2015-7259
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow user accounts to have multiple valid
23RISCO
abrir ↗Referência
CVE-2026-6109
FoundationAgents MetaGPT Mineflayer HTTP API index.js evaluateCode cross-site request forgery
33RISCO
abrir ↗Referência
CVE-2010-1718
Directory traversal vulnerability in archeryscores.php in the Archery Scores (com_archeryscores) component 1.0.6 for Joo
38RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.