Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.324exploits catalogados
36.054CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.721GitHub PoC 14.477VulnCheck XDB 8.829Nuclei 4.350Metasploit 3.489✓ só verificadosrecentespopularesrisco
22.697 exploits
Referência
CVE-2016-6256
SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML
23RISCO
abrir ↗Referência
CVE-2016-6256
SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML
23RISCO
abrir ↗Referência
CVE-2010-5043
SQL injection vulnerability in the DJ-ArtGallery (com_djartgallery) component 0.9.1 for Joomla! allows remote authentica
23RISCO
abrir ↗Referência
CVE-2026-15672
itsourcecode Electronic Judging System add_judges.php sql injection
33RISCO
abrir ↗Referência✓ VexDay Proof
Empire CMS 3.7 - 'checklevel.php' Remote File Inclusion
PHP remote file inclusion vulnerability in e/class/CheckLevel.php in Phome Empire CMS 3.7 and earlier allows remote atta
23RISCO
abrir ↗Referência
CVE-2020-37250
TFTP Broadband 4.3.0.1465 Unquoted Service Path Privilege Escalation
41RISCO
abrir ↗Referência
CVE-2021-47931
Exponent CMS 2.6 Multiple Vulnerabilities Stored XSS Authentication
33RISCO
abrir ↗Referência
CVE-2026-10298
ggml-org whisper.cpp ggml.c whisper_model_load null pointer dereference
33RISCO
abrir ↗Referência
CVE-2026-10198
Assimp glTFImporter glTFImporter.cpp ImportMeshes null pointer dereference
33RISCO
abrir ↗Referência
CVE-2026-10197
Assimp TF File glTF2Importer.cpp ImportEmbeddedTextures null pointer dereference
33RISCO
abrir ↗Referência
CVE-2016-6277
NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.B
100RISCO
abrir ↗Referência
CVE-2026-15669
louisho5 picobot exec Tool exec.go ExecTool.Execute os command injection
33RISCO
abrir ↗Referência
CVE-2026-15668
louisho5 picobot web Tool web.go WebTool.Execute server-side request forgery
33RISCO
abrir ↗Referência
CVE-2026-15624
nextlevelbuilder GoClaw invoke Endpoint create_video_byteplus.go bytePlusDownloadVideo server-side request forgery
33RISCO
abrir ↗Referência
CVE-2026-56789
RTKLIB 2.4.3 - Heap Buffer Overflow and Stack Read via Oversized RINEX Epoch Satellite Count
41RISCO
abrir ↗Referência
CVE-2026-56787
RTKLIB 2.4.3 - Off-by-One Out-of-Bounds Read in decode_ssr3 via RTCM3 SSR Message
33RISCO
abrir ↗Referência
CVE-2026-56774
Kanboard - Cross-User Deletion of Persistent Login Sessions via Unvalidated Session ID
33RISCO
abrir ↗Referência
CVE-2026-56770
libais 0.15 - Out-of-bounds Vector Access in VdmStream::AddLine via Invalid Sequential Message ID
41RISCO
abrir ↗Referência
CVE-2026-7023
ByteDance coze-studio databaseTool database_impl.go ExecuteSQL sql injection
33RISCO
abrir ↗Referência
CVE-2026-7022
SmythOS sre HTTP Header AgentRuntime.class.ts AgentRuntime improper authentication
33RISCO
abrir ↗Referência
CVE-2026-12206
Grit42 Grit data_table_entity.rb DataTableEntity sql injection
33RISCO
abrir ↗Referência
CVE-2026-12204
ShopXO Scheduled Task Endpoint Crontab.php GoodsGiveIntegral authorization
33RISCO
abrir ↗Referência
CVE-2018-13458
qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to
23RISCO
abrir ↗Referência
CVE-2026-19717
CatFolders Document Gallery < 2.0.7 - Unauthenticated Attachment Disclosure via REST API
41RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.