Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.206exploits catalogados
35.418CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.266GitHub PoC 14.124VulnCheck XDB 8.617Nuclei 4.274Metasploit 3.474✓ só verificadosrecentespopularesrisco
22.266 exploits
Referência
D-Link DI-524 V2.06RU - Multiple Cross-Site Scripting
On D-Link DI-524 V2.06RU devices, multiple Stored and Reflected XSS vulnerabilities were found in the Web Configuration:
23RISCO
abrir ↗Referência
CVE-2026-12220
Yealink SIP-T46U Firmware Chunk Upload handler accupgradebychunk mod_upgrade.SparePartsUpload stack-based overflow
41RISCO
abrir ↗Referência
DirectAdmin 1.561 - Multiple Vulnerabilities
The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESE
23RISCO
abrir ↗Referência
CVE-2026-6597
langflow-ai langflow Flow Using API core.py has_api_terms credentials storage
33RISCO
abrir ↗Referência
CVE-2026-6596
langflow-ai langflow API Endpoint endpoints.py create_upload_file unrestricted upload
33RISCO
abrir ↗Referência
CVE-2026-6595
ProjectsAndPrograms School Management System HTTP GET Parameter buslocation.php sql injection
33RISCO
abrir ↗Referência
CVE-2014-0997
WiFiMonitor in Android 4.4.4 as used in the Nexus 5 and 4, Android 4.2.2 as used in the LG D806, Android 4.2.2 as used i
23RISCO
abrir ↗Referência
CVE-2026-6184
code-projects Simple Content Management System welcome.php cross site scripting
33RISCO
abrir ↗Referência
CVE-2026-6183
code-projects Simple Content Management System index.php sql injection
33RISCO
abrir ↗Referência
CVE-2026-6158
Totolink N300RH upgrade.so setUpgradeUboot os command injection
33RISCO
abrir ↗Referência
CVE-2026-6156
Totolink A7100RU CGI cstecgi.cgi setIpQosRules os command injection
48RISCO
abrir ↗Referência
CVE-2026-6155
Totolink A7100RU CGI cstecgi.cgi setWanCfg os command injection
48RISCO
abrir ↗Referência
CVE-2026-6154
Totolink A7100RU CGI cstecgi.cgi setWizardCfg os command injection
48RISCO
abrir ↗Referência
CVE-2026-6153
code-projects Vehicle Showroom Management System StaffDetailsFunction.php sql injection
33RISCO
abrir ↗Referência
CVE-2026-6152
code-projects Vehicle Showroom Management System StaffAddingFunction.php sql injection
33RISCO
abrir ↗Referência
CVE-2026-6151
code-projects Vehicle Showroom Management System PaymentStatusFunction.php sql injection
33RISCO
abrir ↗Referência
CVE-2026-6150
code-projects Simple Laundry System checkupdatestatus.php cross site scripting
33RISCO
abrir ↗Referência
CVE-2019-11354
The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Ori
28RISCO
abrir ↗Referência
CVE-2019-11354
The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Ori
28RISCO
abrir ↗Referência
CVE-2014-1564
Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 do not properly initialize m
23RISCO
abrir ↗Referência
CVE-2014-1619
Multiple SQL injection vulnerabilities in Cubic CMS 5.1.1, 5.1.2, and 5.2 allow remote attackers to execute arbitrary SQ
23RISCO
abrir ↗Referência
CVE-2019-1153
Microsoft Graphics Component Information Disclosure Vulnerability
33RISCO
abrir ↗Referência✓ VexDay Proof
osTicket 1.11 - Cross-Site Scripting / Local File Inclusion
In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.ph
23RISCO
abrir ↗Referência
CVE-2019-11539
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R
100RISCO
abrir ↗Referência
CVE-2019-11539
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R
100RISCO
abrir ↗Referência
CVE-2019-11539
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R
100RISCO
abrir ↗Referência
CVE-2019-11599
The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma la
23RISCO
abrir ↗Referência
CVE-2019-11599
The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma la
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.