Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.302exploits catalogados
35.469CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.301GitHub PoC 14.141VulnCheck XDB 8.646Nuclei 4.289Metasploit 3.474✓ só verificadosrecentespopularesrisco
22.301 exploits
Referência
CVE-2018-19862
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST re
28RISCO
abrir ↗Referência
CVE-2018-20062
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RISCO
abrir ↗Referência
CVE-2017-0144
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir ↗Referência
Inosoft VisiWin 7 2022-2.1 - Insecure Folders Permissions
An issue was discovered in Inosoft VisiWin 7 through 2022-2.1 (Runtime RT7.3 RC3 20221209.5). The "%PROGRAMFILES(X86)%\I
41RISCO
abrir ↗Referência
CVE-2023-31747
Wondershare Filmora 12 (Build 12.2.1.2088) was discovered to contain an unquoted service path vulnerability via the comp
41RISCO
abrir ↗Referência
CVE-2017-8601
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute
35RISCO
abrir ↗Referência✓ VexDay Proof
Student Study Center Management System v1.0 - Stored Cross-Site Scripting (XSS)
Phpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" f
23RISCO
abrir ↗Referência
Thruk Monitoring Web Interface 3.06 - Path Traversal
Thruk has Path Traversal Vulnerability in panorama.pm
45RISCO
abrir ↗Referência✓ VexDay Proof
Service Provider Management System v1.0 - SQL Injection
Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/
23RISCO
abrir ↗Referência
CVE-2023-33592
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lf
23RISCO
abrir ↗Referência
CVE-2023-34581
Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/
23RISCO
abrir ↗Referência
CVE-2003-0727
Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to
50RISCO
abrir ↗Referência✓ VexDay Proof
ashNews 0.83 - 'pathtoashnews' Remote File Inclusion
PHP remote file include vulnerability in Derek Ashauer ashNews 0.83 allows remote attackers to include and execute arbit
23RISCO
abrir ↗Referência✓ VexDay Proof
Eznet 3.5.0 - Remote Stack Overflow / Denial of Service
Stack-based buffer overflow in eZnet.exe, as used in eZ (a) eZphotoshare, (b) eZmeeting, (c) eZnetwork, and (d) eZshare
35RISCO
abrir ↗Referência
CVE-2026-19384
SourceCodester Simple Doctors Appointment System ajax.php set_appointment sql injection
33RISCO
abrir ↗Referência
CVE-2024-57708
An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __
33RISCO
abrir ↗Referência
CVE-2026-67620 - Flowise SSRF via incomplete cloud-metadata deny-list (Oracle OCI 192.0.0.192 + Alibaba 100.100.100.200 bypass the DEFAULT_DENY_LIST)
Flowise 3.1.4 SSRF via fetch-links Endpoint Incomplete Deny-List
33RISCO
abrir ↗Referência
CVE-2026-19268
abdullah1854 MCPGateway Claude Usage Range Endpoint claude-usage.ts getUsageByDateRange command injection
33RISCO
abrir ↗Referência
CVE-2026-16955
AI Engine < 3.6.6 - Subscriber+ Arbitrary File Read via Audio Transcription
33RISCO
abrir ↗Referência
CVE-2026-16953
AI Engine < 3.6.4 - Unauthenticated Cross-Session Chatbot File Deletion via Forgeable Session Cookie
33RISCO
abrir ↗Referência
CVE-2026-16948
Solace Extra < 1.6.1 - Subscriber+ Multiple Missing Authorization via Site-Wide Nonce Exposure
41RISCO
abrir ↗Referência
CVE-2026-16608
Download Monitor < 5.2.6 - Unauthenticated Download Log Injection
33RISCO
abrir ↗Referência
CVE-2026-16595
WP Directory Kit < 1.5.5 - Subscriber+ User and Unpublished Listing Disclosure
33RISCO
abrir ↗Referência
CVE-2026-16594
WP Directory Kit < 1.5.5 - Subscriber+ Plugin Settings and API Key Disclosure
41RISCO
abrir ↗Referência
CVE-2026-16590
WP Directory Kit < 1.5.5 - Subscriber+ Contact Message and User Data Disclosure
33RISCO
abrir ↗Referência
CVE-2026-16589
WP Directory Kit < 1.5.5 - Subscriber+ SQL Injection via data_fields_list Parameter
41RISCO
abrir ↗Referência
CVE-2026-16578
Admin Safety Guard < 1.4.0 - Unauthenticated User Data Disclosure via 2fa/app/users REST Route
41RISCO
abrir ↗Referência
CVE-2026-16574
Dokan < 5.0.11 - Vendor+ Cross-Vendor Downloadable Product Access Grant via Order Downloads REST Endpoint
33RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.