Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8.829Nuclei 4.357Metasploit 3.489✓ só verificadosrecentespopularesrisco
22.832 exploits
Referência✓ VexDay Proof
OneCMS 2.4 - 'abc' SQL Injection
SQL injection vulnerability in userreviews.php in OneCMS 2.4 allows remote attackers to execute arbitrary SQL commands v
23RISCO
abrir ↗Referência✓ VexDay Proof
Airsensor M520 - HTTPd Remote Denial of Service / Buffer Overflow (PoC)
Multiple buffer overflows in the AirDefense Airsensor M520 with firmware 4.3.1.1 and 4.4.1.4 allow remote authenticated
23RISCO
abrir ↗Referência
CVE-2017-9810
There are no Anti-CSRF tokens in any forms on the web interface in Kaspersky Anti-Virus for Linux File Server before Mai
23RISCO
abrir ↗Referência✓ VexDay Proof
neuron news 1.0 - 'index.php?q' Local File Inclusion
Directory traversal vulnerability in index.php in Neuron News 1.0 allows remote attackers to include and execute arbitra
23RISCO
abrir ↗Referência✓ VexDay Proof
PhFiTo 1.3.0 - 'SRC_PATH' Remote File Inclusion
PHP remote file inclusion vulnerability in phfito-post.php in Alex Kocharin PHP Fidonet Tosser (PhFiTo) 1.3.0 in phpFido
23RISCO
abrir ↗Referência✓ VexDay Proof
PHP Links 1.3 - 'id' SQL Injection
SQL injection vulnerability in vote.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arb
23RISCO
abrir ↗Referência
CVE-2018-1002007
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re
23RISCO
abrir ↗Referência
CVE-2018-1002008
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component MCQuiz 0.9 Final - 'tid' SQL Injection
SQL injection vulnerability in index.php in the McQuiz (com_mcquiz) 0.9 Final component for Joomla! allows remote attack
23RISCO
abrir ↗Referência
CVE-2018-2628
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISCO
abrir ↗Referência
CVE-2018-2628
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISCO
abrir ↗Referência
CVE-2024-57708
An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __
33RISCO
abrir ↗Referência
CVE-2026-19384
SourceCodester Simple Doctors Appointment System ajax.php set_appointment sql injection
33RISCO
abrir ↗Referência✓ VexDay Proof
Dream4 Koobi Pro 6.25 Poll - 'poll_id' SQL Injection
SQL injection vulnerability in index.php in dream4 Koobi Pro 6.25 allows remote attackers to execute arbitrary SQL comma
23RISCO
abrir ↗Referência
CVE-2026-14318
GiveWP < 4.16.3 - GiveWP Worker+ Stored XSS via Donation Form Template Settings
33RISCO
abrir ↗Referência
CVE-2026-15235
Hotel Booking Lite < 6.0.4 - Subscriber+ Sensitive Data Disclosure via Admin Calendar AJAX Action
33RISCO
abrir ↗Referência
CVE-2026-15153
WP Hotel Booking < 2.3.2 - Hotel Manager+ SQL Injection via Booking List Search
33RISCO
abrir ↗Referência
CVE-2026-11974
Media folder Addon < 4.1.7 - Unauthenticated Arbitrary File Download
41RISCO
abrir ↗Referência
CVE-2026-12082
Praison AI SEO < 5.0.7 - Unauthenticated Multiple Missing Authorization (Post Permalink Modification, Plugin Settings Disclosure)
41RISCO
abrir ↗Referência
CVE-2018-10661
An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.
60RISCO
abrir ↗Referência
CVE-2026-67181
Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Transfer-Encoding Header
33RISCO
abrir ↗Referência
CVE-2026-18038
nextlevelbuilder GoClaw jq Handler tools_invoke.go ExecTool.Execute information disclosure
33RISCO
abrir ↗Referência
CVE-2018-10809
In 2345 Security Guard 3.7, the driver file (2345NetFirewall.sys) allows local users to cause a denial of service (BSOD)
23RISCO
abrir ↗Referência
CVE-2026-66731
facil.io 0.7.5 - 0.7.6 HTTP/1.1 Chunked Transfer Encoding Parser Crash DoS
41RISCO
abrir ↗Referência
CVE-2026-17432
NousResearch hermes-agent SimpleX Gateway Authorization adapter.py access control
28RISCO
abrir ↗Referência
CVE-2026-65694
Microweber CMS 2.0.20 Path Traversal via ServeStaticFileController
56RISCO
abrir ↗Referência✓ VexDay Proof
ASPilot Pilot Cart 7.3 - 'article' SQL Injection
SQL injection vulnerability in pilot.asp in ASPilot Pilot Cart 7.3 allows remote attackers to execute arbitrary SQL comm
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.