Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8.829Nuclei 4.357Metasploit 3.489✓ só verificadosrecentespopularesrisco
22.721 exploits
Referência✓ VexDay Proof
Internet Download Accelerator 5.2 - Remote Buffer Overflow (PoC)
Buffer overflow in the NotSafe function in the idaiehlp ActiveX control in idaiehlp.dll 1.9.1.74 in Internet Download Ac
23RISCO
abrir ↗Referência
CVE-2026-12188
Grit42 Grit GritEntityController grit_entity_controller.rb sql injection
33RISCO
abrir ↗Referência
CVE-2026-11477
hs-web hsweb-framework OAuth2 Client OAuth2Client.java OAuth2Client redirect
33RISCO
abrir ↗Referência✓ VexDay Proof
EDraw Office Viewer Component - Unsafe Method
A certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions befo
23RISCO
abrir ↗Referência
CVE-2026-14746
code-projects Real State Services addprojectrent.php sql injection
33RISCO
abrir ↗Referência
CVE-2026-14745
code-projects Real State Services single-list_rent.php sql injection
33RISCO
abrir ↗Referência
CVE-2026-14738
exo-explore exo Vision Feature Cache vision.py _image_cache_key weak hash
33RISCO
abrir ↗Referência
CVE-2026-14737
Hanwang e-Face General Management Platform querySysAuthStr.do sql injection
33RISCO
abrir ↗Referência
CVE-2026-15387
Acceptance of Extraneous Untrusted Data With Trusted Data in GitLab
33RISCO
abrir ↗Referência
CVE-2026-18252
Inclusion of Functionality from Untrusted Control Sphere in GitLab
41RISCO
abrir ↗Referência
CVE-2018-0974
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISCO
abrir ↗Referência
CVE-2017-17641
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
23RISCO
abrir ↗Referência
CVE-2017-17642
Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job.
23RISCO
abrir ↗Referência
CVE-2018-1002002
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re
23RISCO
abrir ↗Referência
CVE-2017-17642
Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job.
23RISCO
abrir ↗Referência
CVE-2017-17643
FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.
23RISCO
abrir ↗Referência
CVE-2017-17643
FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.
23RISCO
abrir ↗Referência
CVE-2017-17645
Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.
23RISCO
abrir ↗Referência
CVE-2017-17645
Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.
23RISCO
abrir ↗Referência
CVE-2026-79622
dekdee adobe-xd-mcp file-access-from-request Endpoint xd-parser.ts path traversal
33RISCO
abrir ↗Referência
CVE-2026-57863
Crater Invoice 6.0.6 Path Traversal RCE via update/unzip endpoint
41RISCO
abrir ↗Referência
CVE-2026-78435
Faveo Helpdesk Logo SettingsController.php unlink path traversal
33RISCO
abrir ↗Referência✓ VexDay Proof
paBugs 2.0 Beta 3 - 'main.php?cid' SQL Injection
SQL injection vulnerability in main.php in paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary SQ
23RISCO
abrir ↗Referência
CVE-2016-4372
HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01,
28RISCO
abrir ↗Referência✓ VexDay Proof
Remote Mouse GUI 3.008 - Local Privilege Escalation
Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.