Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.231exploits catalogados
35.420CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.266GitHub PoC 14.131VulnCheck XDB 8.635Nuclei 4.274Metasploit 3.474✓ só verificadosrecentespopularesrisco
22.266 exploits
Referência
CVE-2026-16205
Pluck CMS Albums albums.admin.php htmlspecialchars_decode cross site scripting
33RISCO
abrir ↗Referência
CVE-2014-8998
lib/message.php in X7 Chat 2.0.0 through 2.0.5.1 allows remote authenticated users to execute arbitrary PHP code via a c
50RISCO
abrir ↗Referência
CVE-2014-8998
lib/message.php in X7 Chat 2.0.0 through 2.0.5.1 allows remote authenticated users to execute arbitrary PHP code via a c
50RISCO
abrir ↗Referência
CVE-2014-9004
Cross-site scripting (XSS) vulnerability in vldPersonals before 2.7.1 allows remote attackers to inject arbitrary web sc
23RISCO
abrir ↗Referência
CVE-2014-9014
Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin b
28RISCO
abrir ↗Referência
CVE-2026-9515
Totolink CA750-PoE Setting cstecgi.cgi setUnloadUserData os command injection
38RISCO
abrir ↗Referência
CVE-2026-9514
Totolink CA750-PoE Setting cstecgi.cgi setNetworkDiag os command injection
38RISCO
abrir ↗Referência✓ VexDay Proof
Active Web Helpdesk 2 - 'categoryId' Blind SQL Injection
SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL
23RISCO
abrir ↗Referência
CVE-2011-4825
Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinym
50RISCO
abrir ↗Referência
CVE-2014-9456
Buffer overflow in NotePad++ 6.6.9 allows remote attackers to have unspecified impact via a long Time attribute in an Ev
28RISCO
abrir ↗Referência
CVE-2026-9468
dazeb cline-mcp-memory-bank index.ts handleInitializeMemoryBank path traversal
33RISCO
abrir ↗Referência✓ VexDay Proof
Quick Tree View .NET 3.1 - Database Disclosure
Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows
23RISCO
abrir ↗Referência
CVE-2019-9162
In the Linux kernel before 4.20.12, net/ipv4/netfilter/nf_nat_snmp_basic_main.c in the SNMP NAT module has insufficient
23RISCO
abrir ↗Referência
CVE-2014-9613
Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL co
23RISCO
abrir ↗Referência
CVE-2014-9641
The tmeext.sys driver before 2.0.0.1015 in Trend Micro Antivirus Plus, Internet Security, and Maximum Security allows lo
23RISCO
abrir ↗Referência
CVE-2011-4829
SQL injection vulnerability in the com_listing component in Barter Sites component 1.3 for Joomla! allows remote attacke
23RISCO
abrir ↗Referência
CVE-2019-9193
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISCO
abrir ↗Referência
CVE-2019-9193
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISCO
abrir ↗Referência
CVE-2019-9213
In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which make
38RISCO
abrir ↗Referência
CVE-2019-9213
In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which make
38RISCO
abrir ↗Referência
CVE-2019-9491
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to
28RISCO
abrir ↗Referência
Bolt CMS 3.6.4 - Cross-Site Scripting
Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and
23RISCO
abrir ↗Referência
Craft CMS 3.1.12 Pro - Cross-Site Scripting
In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at
23RISCO
abrir ↗Referência
CVE-2019-9581
phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitra
28RISCO
abrir ↗Referência
Savsoft Quiz 5 - Stored Cross-Site Scripting
TechKshetra Info Solutions Pvt. Ltd Savsoft Quiz 5.5 and earlier has XSS which can result in an attacker injecting the X
23RISCO
abrir ↗Referência
Savsoft Quiz Enterprise Version 5.5 - Persistent Cross-Site Scripting
TechKshetra Info Solutions Pvt. Ltd Savsoft Quiz 5.5 and earlier has XSS which can result in an attacker injecting the X
23RISCO
abrir ↗Referência
CVE-2020-25213
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISCO
abrir ↗Referência
CVE-2020-2555
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.