Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.302exploits catalogados
35.469CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.301GitHub PoC 14.141VulnCheck XDB 8.646Nuclei 4.289Metasploit 3.474✓ só verificadosrecentespopularesrisco
22.301 exploits
Referência
CVE-2026-16069
Brizy - Page Builder < 2.8.19 - Contributor+ Stored XSS via Featured Image Focal Point
33RISCO
abrir ↗Referência
CVE-2026-16068
Brizy - Page Builder < 2.8.19 - Author+ Stored XSS via brizy_set_project Global Project Code Asset
28RISCO
abrir ↗Referência
CVE-2020-25762
An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input v
28RISCO
abrir ↗Referência✓ VexDay Proof
Shop Script Pro 2.12 - SQL Injection
SQL injection vulnerability in index.php in Shop-Script Pro 2.12, when magic_quotes_gpc is disabled, allows remote attac
23RISCO
abrir ↗Referência
CVE-2020-25762
An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input v
28RISCO
abrir ↗Referência✓ VexDay Proof
yogurt 0.3 - Cross-Site Scripting / SQL Injection
SQL injection vulnerability in writemessage.php in Yogurt 0.3, when register_globals is enabled, allows remote authentic
23RISCO
abrir ↗Referência✓ VexDay Proof
PHPCollegeExchange 0.1.5c - 'listing_view.php?itemnr' SQL Injection
SQL injection vulnerability in house/listing_view.php in phpCollegeExchange 0.1.5c allows remote attackers to execute ar
23RISCO
abrir ↗Referência✓ VexDay Proof
PHPortal 1 - 'topicler.php?id' SQL Injection
SQL injection vulnerability in topicler.php in phPortal 1.0 allows remote attackers to execute arbitrary SQL commands vi
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component com_iJoomla_rss - Blind SQL Injection
SQL injection vulnerability in the iJoomla RSS Feeder (com_ijoomla_rss) component for Joomla! allows remote attackers to
23RISCO
abrir ↗Referência
Genexis Platinum 4410 Router 2.1 - UPnP Credential Exposure
UPNP Service listening on port 5555 in Genexis Platinum 4410 Router V2.1 (P4410-V2–1.34H) has an action 'X_GetAccess' wh
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Jumi - 'fileid' Blind SQL Injection
SQL injection vulnerability in the Jumi (com_jumi) component 2.0.3 and possibly other versions for Joomla allows remote
23RISCO
abrir ↗Referência
CVE-2020-26567
An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed
28RISCO
abrir ↗Referência✓ VexDay Proof
elvin bts 1.2.0 - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in login.php in Elvin 1.2.0 allows remote attackers to hijack the authen
23RISCO
abrir ↗Referência✓ VexDay Proof
elvin bts 1.2.0 - Multiple Vulnerabilities
Elvin 1.2.0 allows remote attackers to read the PHP source code of (1) login.ei, (2) jump_bug.ei, or (3) create_account.
23RISCO
abrir ↗Referência✓ VexDay Proof
phpWebThings 1.5.2 - MD5 Hash Retrieve/File Disclosure
SQL injection vulnerability in fdown.php in phpWebThings 1.5.2 and earlier allows remote attackers to execute arbitrary
23RISCO
abrir ↗Referência
CVE-2020-28328
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain
50RISCO
abrir ↗Referência
CVE-2020-28688
The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to uplo
28RISCO
abrir ↗Referência
OpenCart 3.0.3.6 - 'Profile Image' Stored Cross-Site Scripting (Authenticated)
OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Profile Image. An admin can upload a profile image as
23RISCO
abrir ↗Referência
CVE-2020-3452
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir ↗Referência
CVE-2021-22205
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISCO
abrir ↗Referência
CVE-2021-22205
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISCO
abrir ↗Referência
CVE-2026-16630
syncfusion ej2-javascript-ui-controls package.json child_process.exec os command injection
33RISCO
abrir ↗Referência
CVE-2026-63108
Roo Code 3.54.0 Command Injection via Parameter Expansion Parsing
41RISCO
abrir ↗Referência
CVE-2026-10724
Reviews Feed < 2.6.5 - Unauthenticated Stored Arbitrary Shortcode Execution via Google Reviews
33RISCO
abrir ↗Referência
CVE-2026-16227
SourceCodester Class and Exam Timetabling System edit_subject.php sql injection
33RISCO
abrir ↗Referência
CVE-2021-22911
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISCO
abrir ↗Referência
CVE-2021-24145
Modern Events Calendar Lite < 5.16.5 - Authenticated Arbitrary File Upload leading to RCE
60RISCO
abrir ↗Referência
CVE-2021-24276
Contact Form by Supsystic < 1.7.15 - Reflected Cross-Site scripting (XSS)
43RISCO
abrir ↗Referência
CVE-2021-24499
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
50RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.