Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8.829Nuclei 4.357Metasploit 3.489✓ só verificadosrecentespopularesrisco
22.832 exploits
Referência✓ VexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to register arbitrary users via a request to host
23RISCO
abrir ↗Referência✓ VexDay Proof
DELTAScripts PHP Shop 1.0 - Authentication Bypass
SQL injection vulnerability in admin/login.php in DeltaScripts PHP Shop 1.0 allows remote attackers to execute arbitrary
23RISCO
abrir ↗Referência✓ VexDay Proof
WinFTP Server 2.3.0 - 'PASV Mode' Remote Denial of Service
WinFTP FTP Server 2.3.0, when passive (aka PASV) mode is used, allows remote authenticated users to cause a denial of se
43RISCO
abrir ↗Referência✓ VexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a reque
23RISCO
abrir ↗Referência
CVE-2018-12602
A CSRF vulnerability exists in LFCMS 3.7.0: users can be added arbitrarily.
23RISCO
abrir ↗Referência✓ VexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
Multiple unspecified vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users
23RISCO
abrir ↗Referência✓ VexDay Proof
WordPress Plugin Page Flip Image Gallery 0.2.2 - Remote File Disclosure
Directory traversal vulnerability in getConfig.php in the Page Flip Image Gallery plugin 0.2.2 and earlier for WordPress
23RISCO
abrir ↗Referência
CVE-2008-5753
Stack-based buffer overflow in BulletProof FTP Client 2.63 and 2010 allows user-assisted attackers to execute arbitrary
23RISCO
abrir ↗Referência✓ VexDay Proof
BulletProof FTP Client 2.63 - Local Heap Overflow (PoC)
Stack-based buffer overflow in BulletProof FTP Client 2.63 and 2010 allows user-assisted attackers to execute arbitrary
23RISCO
abrir ↗Referência
CVE-2018-13108
All ADB broadband gateways / routers based on the Epicentro platform are affected by a local root jailbreak vulnerabilit
23RISCO
abrir ↗Referência
CVE-2026-38764
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kerne
41RISCO
abrir ↗Referência
CVE-2026-16015
poco-ai poco-claw executor_manager API tasks.py create_task missing authentication
33RISCO
abrir ↗Referência
CVE-2026-16628
oclif JIT Plugin Entry child_process.exec os command injection
33RISCO
abrir ↗Referência
CVE-2026-12968
Product Addons – WowAddons < 1.6.15 - Unauthenticated Stored XSS via Arbitrary SVG Upload
41RISCO
abrir ↗Referência
CVE-2026-16449
zsadmin2025 ZS-Admin com.zs.sys.dept.controller.SysDeptController page OrderItem.desc sql injection
33RISCO
abrir ↗Referência
CVE-2026-13402
Royal Elementor Addons < 1.7.1063 - Unauthenticated Private Mega Menu Template Disclosure
33RISCO
abrir ↗Referência
CVE-2026-12869
Header Footer Builder for Elementor < 1.2.1 - Contributor+ Stored XSS via Template Import
33RISCO
abrir ↗Referência
CVE-2026-15907
H3C SecPath F1000-C8300 g=log_fw_nbc_mail_jsondata sql injection
33RISCO
abrir ↗Referência
CVE-2026-63770
Glance 0.8.5 IP Spoofing Authentication Brute-Force Protection Bypass
41RISCO
abrir ↗Referência
CVE-2026-63771
Adminer < 5.4.3 Cookie Injection via X-Forwarded-Prefix Header
33RISCO
abrir ↗Referência
CVE-2026-16009
itsourcecode Hospital Management System prescriptionorderdetail.php sql injection
33RISCO
abrir ↗Referência
CVE-2026-12684
Customer Reviews for WooCommerce < 5.113.0 - Unauthenticated Arbitrary Media Upload via cr_upload_media
33RISCO
abrir ↗Referência
CVE-2026-12585
Abandoned Cart Lite for WooCommerce < 6.8.2 - Unauthenticated Account Takeover via Malleable Recovery-Link Token
41RISCO
abrir ↗Referência
CVE-2026-15520
GNU LibreDWG R2004 Section Decompression decode.c decompress_R2004_section heap-based overflow
33RISCO
abrir ↗Referência
CVE-2026-15518
AREA 17 Twill CMS Media Library Insert FileLibraryController.php storeFile unrestricted upload
33RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.