Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.286exploits catalogados
35.467CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.301GitHub PoC 14.136VulnCheck XDB 8.635Nuclei 4.289Metasploit 3.474✓ só verificadosrecentespopularesrisco
22.301 exploits
Referência
CVE-2026-7152
Totolink A8000RU CGI cstecgi.cgi setTelnetCfg os command injection
48RISCO
abrir ↗Referência
CVE-2026-7151
Tenda HG3 formIPv6Routing formUploadConfig stack-based overflow
41RISCO
abrir ↗Referência
CVE-2026-7150
dh1011 auto-favicon MCP Tool server.py generate_favicon_from_url server-side request forgery
33RISCO
abrir ↗Referência
CVE-2026-7149
dexhunter kaggle-mcp server.py prepare_kaggle_dataset path traversal
33RISCO
abrir ↗Referência
CVE-2026-7147
JoeCastrom mcp-chat-studio LLM Models API llm.js server-side request forgery
33RISCO
abrir ↗Referência
CVE-2019-1003001
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins
60RISCO
abrir ↗Referência
CVE-2019-12181
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
50RISCO
abrir ↗Referência
CVE-2019-12372
Petraware pTransformer ADC before 2.1.7.22827 allows SQL Injection via the User ID parameter to the login form.
23RISCO
abrir ↗Referência
CVE-2019-12477
Supra Smart Cloud TV allows remote file inclusion in the openLiveURL function, which allows a local attacker to broadcas
43RISCO
abrir ↗Referência
CVE-2019-12725
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISCO
abrir ↗Referência
CVE-2014-2008
SQL injection vulnerability in confirm.php in the mPAY24 payment module before 1.6 for PrestaShop allows remote attacker
23RISCO
abrir ↗Referência
CVE-2014-2008
SQL injection vulnerability in confirm.php in the mPAY24 payment module before 1.6 for PrestaShop allows remote attacker
23RISCO
abrir ↗Referência
CVE-2026-34101
Guardian Language-System Unauthenticated SQL Injection via id Parameter in text_file.php
48RISCO
abrir ↗Referência✓ VexDay Proof
Atom Photoblog 1.1.5b1 - 'photoId' SQL Injection
SQL injection vulnerability in atomPhotoBlog.php in Atom PhotoBlog 1.0.9.1 and 1.1.5b1 allows remote attackers to execut
23RISCO
abrir ↗Referência✓ VexDay Proof
Webmin 1.910 - 'Package Updates' Remote Command Execution (Metasploit)
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RISCO
abrir ↗Referência
phpMyAdmin 4.9.0.1 - Cross-Site Request Forgery
A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.
28RISCO
abrir ↗Referência
CVE-2019-13235
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form.
23RISCO
abrir ↗Referência
CVE-2014-2299
Buffer overflow in the mpeg_read function in wiretap/mpeg.c in the MPEG parser in Wireshark 1.8.x before 1.8.13 and 1.10
50RISCO
abrir ↗Referência
CVE-2014-2303
Multiple SQL injection vulnerabilities in the file browser component (we_fs.php) in webEdition CMS before 6.2.7-s1.2 and
23RISCO
abrir ↗Referência
CVE-2014-2399
Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 2.2.2 allows remote attacker
23RISCO
abrir ↗Referência
CVE-2025-71326
AVAST Antivirus 25.11 Unquoted Service Path Privilege Escalation
41RISCO
abrir ↗Referência✓ VexDay Proof
F-PROT AntiVirus 6.2.1.4252 - Malformed Archive Infinite Loop Denial of Service
The scanning engine in F-Prot Antivirus 6.2.1 4252 allows remote attackers to cause a denial of service (infinite loop)
23RISCO
abrir ↗Referência
CVE-2014-2424
Unspecified vulnerability in the Oracle Event Processing component in Oracle Fusion Middleware 11.1.1.7.0 allows remote
50RISCO
abrir ↗Referência✓ VexDay Proof
eNdonesia 8.4 (Calendar Module) - SQL Injection
SQL injection vulnerability in the Calendar module in eNdonesia 8.4 allows remote attackers to execute arbitrary SQL com
23RISCO
abrir ↗Referência
CVE-2019-13272
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir ↗Referência
CVE-2019-13272
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir ↗Referência✓ VexDay Proof
PHP Hosting Directory 2.0 - Insecure Cookie Handling
JnSHosts PHP Hosting Directory 2.0 allows remote attackers to bypass authentication and gain administrative access by se
23RISCO
abrir ↗Referência
CVE-2019-13272
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.