Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8.883Nuclei 4.361Metasploit 3.493✓ só verificadosrecentespopularesrisco
23.022 exploits
Referência✓ VexDay Proof
RunCMS Module section - 'artid' SQL Injection
SQL injection vulnerability in the sections (Section) module in RunCMS allows remote attackers to execute arbitrary SQL
23RISCO
abrir ↗Referência✓ VexDay Proof
PHP iCalendar 2.24 - 'cookie_language' Local File Inclusion / Arbitrary File Upload
Directory traversal vulnerability in print.php in PHP iCalendar 2.24 and earlier allows remote attackers to include and
23RISCO
abrir ↗Referência✓ VexDay Proof
Home FTP Server 1.4.5 - Remote Denial of Service
Home FTP Server 1.4.5.89 allows remote attackers to cause a denial of service (crash) by opening a FTP passive mode conn
23RISCO
abrir ↗Referência✓ VexDay Proof
SunOS 5.10 Sun Cluster - 'rpc.metad' Denial of Service (PoC)
rpc.metad in Sun Solaris 10 allows remote attackers to cause a denial of service (daemon crash) via a malformed RPC requ
23RISCO
abrir ↗Referência✓ VexDay Proof
PunBB 1.2.16 - Blind Password Recovery
The password reset feature in PunBB 1.2.16 and earlier uses predictable random numbers based on the system time, which a
23RISCO
abrir ↗Referência✓ VexDay Proof
ASUS DPC Proxy 2.0.0.16/19 - Remote Buffer Overflow
Stack-based buffer overflow in the DPC Proxy server (DpcProxy.exe) in ASUS Remote Console (aka ARC or ASMB3) 2.0.0.19 an
60RISCO
abrir ↗Referência✓ VexDay Proof
PEEL CMS 3.x - Admin Hash Extraction / Arbitrary File Upload
Unrestricted file upload vulnerability in administrer/produits.php in PEEL, possibly 3.x and earlier, allows remote auth
23RISCO
abrir ↗Referência✓ VexDay Proof
NetWin Surgemail 3.8k4-4 - IMAP (Authenticated) Remote LIST Universal
Stack-based buffer overflow in the IMAP service in NetWin Surgemail 3.8k4-4 and earlier allows remote authenticated user
23RISCO
abrir ↗Referência
CVE-2026-19823
Tenda W20E QoS Rule Deletion delQos formQOSRuleDel stack-based overflow
41RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component custompages 1.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in the SSTREAMTV custompages (com_custompages) 1.1 and earlier component for Joo
35RISCO
abrir ↗Referência
CVE-2019-9082
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public/
100RISCO
abrir ↗Referência✓ VexDay Proof
Danneo CMS 0.5.1 - Blind SQL Injection
SQL injection vulnerability in index.php in Danneo CMS 0.5.1 and earlier, when the Referers statistics option is enabled
23RISCO
abrir ↗Referência✓ VexDay Proof
PHP-Nuke Platinum 7.6.b.5 - 'dynamic_titles.php' SQL Injection
SQL injection vulnerability in includes/dynamic_titles.php in PHP-Nuke Platinum 7.6.b.5 allows remote attackers to execu
23RISCO
abrir ↗Referência
CVE-2019-0230
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RISCO
abrir ↗Referência
CVE-2019-0230
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RISCO
abrir ↗Referência
CVE-2026-19812
TOTOLINK A800R product.so cstecgi.cgi UploadCustomModule stack-based overflow
41RISCO
abrir ↗Referência
CVE-2026-19811
TOTOLINK A800R firewall.so cstecgi.cgi setIpQosRules stack-based overflow
41RISCO
abrir ↗Referência
CVE-2026-18039
Essential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation via Custom Profile Field Mass Assignment
41RISCO
abrir ↗Referência
CVE-2026-16739
Epeken All Kurir <= 2.1.4 - Unauthenticated Order Payment Confirmation Forgery
33RISCO
abrir ↗Referência
CVE-2017-3248
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Suppo
60RISCO
abrir ↗Referência✓ VexDay Proof
RunCMS Module Photo 3.02 - 'cid' SQL Injection
SQL injection vulnerability in viewcat.php in the Photo 3.02 module for RunCMS allows remote attackers to execute arbitr
23RISCO
abrir ↗Referência✓ VexDay Proof
Uploader & Downloader 3.0 - 'id_user' SQL Injection
SQL injection vulnerability in administration/administre2.php in Eric GUILLAUME uploader&downloader 3 allows remote atta
23RISCO
abrir ↗Referência✓ VexDay Proof
Bandwebsite 1.5 - 'LOGIN' Remote Add Admin
Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to create administrative accounts via a direct requ
23RISCO
abrir ↗Referência✓ VexDay Proof
TopperMod 2.0 - SQL Injection
SQL injection vulnerability in account/index.php in TopperMod 2.0, when magic_quotes_gpc is disabled, allows remote atta
23RISCO
abrir ↗Referência
CVE-2025-34028
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RISCO
abrir ↗Referência★ 21
watchtowrlabs/watchTowr-vs-Commvault-PreAuth-RCE-CVE-2025-34028
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RISCO
abrir ↗Referência
CVE-2023-1671
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISCO
abrir ↗Referência
CVE-2026-19791
Tenda G0 httpd web management interface module addStaticRoute stack-based overflow
41RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.