Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8.883Nuclei 4.361Metasploit 3.493✓ só verificadosrecentespopularesrisco
24.695 exploits
Exploit-DB✓ VexDay Proof
Simple Food Ordering System v1.0 - Cross-Site Scripting (XSS)
SourceCodester Simple Food Ordering System process_order.php cross site scripting
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Art Gallery Management System Project in PHP v 1.0 - SQL injection
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid par
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Music Gallery Site v1.0 - SQL Injection on page view_music_details.php
SourceCodester Music Gallery Site GET Request view_music_details.php sql injection
33RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Auto Dealer Management System v1.0 - SQL Injection
SourceCodester Auto Dealer Management System sql injection
33RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Best pos Management System v1.0 - Remote Code Execution (RCE) on File Upload
SourceCodester Best POS Management System Image save_settings unrestricted upload
33RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Auto Dealer Management System v1.0 - SQL Injection on manage_user.php
SourceCodester Auto Dealer Management System sql injection
33RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Auto Dealer Management System 1.0 - Broken Access Control Exploit
SourceCodester Auto Dealer Management System Users.php access control
33RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Employee Task Management System v1.0 - Broken Authentication
SourceCodester Employee Task Management System changePasswordForEmployee.php improper authentication
41RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BTCPay Server v1.7.4 - HTML Injection
Improper Neutralization of Equivalent Special Elements in btcpayserver/btcpayserver
33RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Responsive FileManager 9.9.5 - Remote Code Execution (RCE)
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanis
41RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Answerdev 1.0.3 - Account Takeover
Improper Access Control in answerdev/answer
48RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Art Gallery Management System Project v1.0 - SQL Injection (editid) authenticated
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parame
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Paid Memberships Pro v2.9.8 (WordPress Plugin) - Unauthenticated SQL Injection
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerabilit
85RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Art Gallery Management System Project v1.0 - Reflected Cross-Site Scripting (XSS)
A reflected cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to e
38RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Art Gallery Management System Project v1.0 - SQL Injection (cid) Unauthenticated
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Roxy WI v6.1.0.0 - Improper Authentication Control
Authentication Bypass in Roxy-wi
53RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Roxy WI v6.1.0.0 - Unauthenticated Remote Code Execution (RCE)
Unauthenticated Remote Code Execution in Roxy-wi
75RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WP-file-manager v6.9 - Unauthenticated Arbitrary File Upload leading to RCE
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
GitLab v15.3 - Remote Code Execution (RCE) (Authenticated)
A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3
70RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Yahoo User Interface library (YUI2) TreeView v2.8.2 - Multiple Reflected Cross Site Scripting (XSS)
Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, Tree
38RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 2.4.x - Buffer Overflow
Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier
45RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WP All Import v3.6.7 - Remote Code Execution (RCE) (Authenticated)
Import any XML or CSV File to WordPress <= 3.6.7 - Admin+ Malicious File Upload
46RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BoxBilling<=4.22.1.5 - Remote Code Execution (RCE)
Unrestricted Upload of File with Dangerous Type in boxbilling/boxbilling
53RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
Stored Cross-Site Scripting Vulnerability In File Parameter in zoneminder
41RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
Denial of service through logs in zoneminder
33RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
CSRF key bypass using HTTP methods in zoneminder
41RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Grafana <=6.2.4 - HTML Injection
public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Composr-CMS Version <=10.0.39 - Authenticated Remote Code Execution
Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrar
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Translatepress Multilinugal WordPress plugin < 2.3.3 - Authenticated SQL Injection
Translatepress Multilinugal < 2.3.3 - Admin+ SQLi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Abantecart v1.3.2 - Authenticated Remote Code Execution
Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.