Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8.829Nuclei 4.350Metasploit 3.489✓ só verificadosrecentespopularesrisco
22.721 exploits
Referência
CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗Referência
CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir ↗Referência
CVE-2026-18853
ZomboDroid Meme Generator App com.zombodroid.MemeGenerator t5.l.c path traversal
33RISCO
abrir ↗Referência
CVE-2026-18852
epsilla-cloud vectordb Filter expr.cpp ShuntingYard unusual condition
33RISCO
abrir ↗Referência
CVE-2026-70619
Odysseus Missing Admin Authorization via Embedding Endpoint Routes
41RISCO
abrir ↗Referência
CVE-2015-8427
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RISCO
abrir ↗Referência
CVE-2026-14322
Timetics < 1.0.57 - Unauthenticated Booking Auto-Approval via Arbitrary payment_method
33RISCO
abrir ↗Referência
CVE-2026-12965
Super Store Finder <= 7.8 - Unauthenticated SQL Injection via ssf_tracking
48RISCO
abrir ↗Referência
CVE-2015-8428
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RISCO
abrir ↗Referência
CVE-2025-15673
Import and export users and customers < 2.4.3 - Admin+ Arbitrary File Read
33RISCO
abrir ↗Referência
CVE-2015-8431
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RISCO
abrir ↗Referência✓ VexDay Proof
phpMyTeam 2.0 - 'smileys_dir' Remote File Inclusion
PHP remote file inclusion vulnerability in images/smileys/smileys_packs.php in phpMyTeam 2.0, when register_globals is e
23RISCO
abrir ↗Referência✓ VexDay Proof
phpBB SpamBlocker Mod 1.0.2 - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/antispam.php in the SpamBlockerMODv 1.0.2 and earlier module for php
23RISCO
abrir ↗Referência✓ VexDay Proof
Redaction System 1.0 - 'lang_prefix' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Redaction System 1.0000 allow remote attackers to execute arbitrar
23RISCO
abrir ↗Referência✓ VexDay Proof
Transmit.app 3.5.5 - 'ftps://' URL Handler Heap Buffer Overflow (PoC)
Heap-based buffer overflow in the SFTP protocol handler for Panic Transmit (Transmit.app) up to 3.5.5 allows remote atta
23RISCO
abrir ↗Referência✓ VexDay Proof
Yahoo! Music Jukebox 2.2 - 'AddImage()' ActiveX Remote Buffer Overflow (1)
Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows
23RISCO
abrir ↗Referência✓ VexDay Proof
Yahoo! Music Jukebox 2.2 - 'AddImage()' ActiveX Remote Buffer Overflow (2)
Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows
23RISCO
abrir ↗Referência✓ VexDay Proof
Yahoo! Music JukeBox 2.2 - 'AddButton()' ActiveX Remote Buffer Overflow
Buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! JukeBox 2.2.2.56 allows remote attackers to
23RISCO
abrir ↗Referência
CVE-2016-0051
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RISCO
abrir ↗Referência
CVE-2016-0094
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, W
23RISCO
abrir ↗Referência
CVE-2026-14226
Easy Appointments < 3.12.28 - Subscriber+ Sensitive Information Disclosure via REST Appointments Listing
33RISCO
abrir ↗Referência
CVE-2026-14223
Easy Appointments < 3.12.28 - Subscriber+ Customer PII Disclosure via IDOR
33RISCO
abrir ↗Referência
CVE-2016-0099
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RISCO
abrir ↗Referência✓ VexDay Proof
phpBB Prillian French Mod 0.8.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in language/lang_french/lang_prillian_faq.php in the Prillian French 0.8.0 and e
23RISCO
abrir ↗Referência✓ VexDay Proof
PHPMyConferences 8.0.2 - 'menu.inc.php' File Inclusion
PHP remote file inclusion vulnerability in common/visiteurs/include/menus.inc.php in J-Pierre DEZELUS Les Visiteurs 2.0.
23RISCO
abrir ↗Referência
CVE-2016-0953
Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to exec
28RISCO
abrir ↗Referência
CVE-2016-0964
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on
28RISCO
abrir ↗Referência
CVE-2016-10009
Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute
53RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.