Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.056exploits catalogados
35.925CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.640GitHub PoC 14.392VulnCheck XDB 8.755Nuclei 4.333Metasploit 3.478✓ só verificadosrecentespopularesrisco
22.640 exploits
Referência
CVE-2026-61511
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
75RISCO
abrir ↗Referência
CVE-2012-2584
Multiple cross-site scripting (XSS) vulnerabilities in Alt-N MDaemon Free 12.5.4 allow remote attackers to inject arbitr
23RISCO
abrir ↗Referência
CVE-2026-14189
WPBot AI ChatBot < 8.5.2 - Admin+ Second-Order SQL Injection via qc_bot_str_fields
28RISCO
abrir ↗Referência
CVE-2012-2591
Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect Email Server 10.0 and 10.0.0.3 allow remote attack
23RISCO
abrir ↗Referência
CVE-2025-71408
NLTK < 3.9.3 Eval Injection via collocations.py Command-Line Arguments
41RISCO
abrir ↗Referência
CVE-2026-65709
sysPass 3.2.11 Missing Object-Level Authorization via JSON-RPC API
41RISCO
abrir ↗Referência
CVE-2012-2601
SQL injection vulnerability in WrVMwareHostList.asp in Ipswitch WhatsUp Gold 15.02 allows remote attackers to execute ar
23RISCO
abrir ↗Referência
CVE-2010-1472
Directory traversal vulnerability in the Daily Horoscope (com_horoscope) component 1.5.0 for Joomla! allows remote attac
43RISCO
abrir ↗Referência
CVE-2026-8188
Wavlink NU516U1 adm.cgi change_wifi_password os command injection
33RISCO
abrir ↗Referência
CVE-2010-0672
SQL injection vulnerability in index.php in WSN Guest 1.02 allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir ↗Referência
CVE-2010-1723
Directory traversal vulnerability in the iNetLanka Contact Us Draw Root Map (com_drawroot) component 1.1 for Joomla! all
38RISCO
abrir ↗Referência
CVE-2026-12724
Kirki < 6.0.12 - Unauthenticated HTML Injection in Password Reset Email via kirki-forgot-password
33RISCO
abrir ↗Referência
CVE-2022-30190
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir ↗Referência
CVE-2012-2614
Buffer overflow in programmer.exe in Lattice Diamond Programmer 1.4.2 allows user-assisted remote attackers to cause a d
23RISCO
abrir ↗Referência
CVE-2017-8680
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RISCO
abrir ↗Referência
CVE-2026-16219
Croogo CMS Admin File Manager FileManager.php isEditable path traversal
33RISCO
abrir ↗Referência
CVE-2026-8119
Open5GS NSSF nghttp2-server.c ogs_sbi_stream_find_by_id denial of service
33RISCO
abrir ↗Referência
CVE-2017-8681
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RISCO
abrir ↗Referência
CVE-2014-6278
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi
100RISCO
abrir ↗Referência
CVE-2014-6278
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi
100RISCO
abrir ↗Referência
CVE-2014-6278
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi
100RISCO
abrir ↗Referência
CVE-2014-6278
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi
100RISCO
abrir ↗Referência
CVE-2014-6287
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir ↗Referência
CVE-2010-1944
Multiple PHP remote file inclusion vulnerabilities in openMairie openCimetiere 2.01, when register_globals is enabled, a
23RISCO
abrir ↗Referência
CVE-2010-1946
Multiple PHP remote file inclusion vulnerabilities in openMairie Openregistrecil 1.02, when register_globals is enabled,
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.