Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.302exploits catalogados
35.469CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.301GitHub PoC 14.141VulnCheck XDB 8.646Nuclei 4.289Metasploit 3.474✓ só verificadosrecentespopularesrisco
22.301 exploits
Referência
CVE-2010-2689
SQL injection vulnerability in cont_form.php in Internet DM WebDM CMS allows remote attackers to execute arbitrary SQL c
23RISCO
abrir ↗Referência
CVE-2010-2690
SQL injection vulnerability in the JOOFORGE Gamesbox (com_gamesbox) component 1.0.2, and possibly earlier, for Joomla! a
23RISCO
abrir ↗Referência✓ VexDay Proof
My Little Forum 1.7 - 'user.php?id' SQL Injection
SQL injection vulnerability in user.php in My Little Forum 1.7 and earlier allows remote attackers to execute arbitrary
23RISCO
abrir ↗Referência
CVE-2008-5322
Wysi Wiki Wyg 1.0 allows remote attackers to obtain system information via an invalid categup parameter to index.php, wh
23RISCO
abrir ↗Referência
CVE-2013-6883
Cross-site request forgery (CSRF) vulnerability in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allow
23RISCO
abrir ↗Referência
CVE-2013-6883
Cross-site request forgery (CSRF) vulnerability in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allow
23RISCO
abrir ↗Referência
CVE-2016-5063
The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote atta
23RISCO
abrir ↗Referência
CVE-2017-9129
The wav_open_read function in frontend/input.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to c
23RISCO
abrir ↗Referência
CVE-2026-58377
JeecgBoot 3.9.2 - Missing Authorization on OpenAPI Credential Management Endpoints Exposes Access/Secret Keys
41RISCO
abrir ↗Referência✓ VexDay Proof
DreamLog 0.5 - 'upload.php' Arbitrary File Upload
Unrestricted file upload vulnerability in upload.php in dreamLog (aka dreamblog) 0.5 allows remote attackers to upload a
23RISCO
abrir ↗Referência✓ VexDay Proof
CASTOR 1.1.1 - '/lib/rs.php' Remote File Inclusion
PHP remote file inclusion vulnerability in lib/rs.php in 2le.net Castor PHP Web Builder 1.1.1 allows remote attackers to
23RISCO
abrir ↗Referência✓ VexDay Proof
MiniHTTPServer Web Forum & File Sharing Server 4.0 - Add User
join.asp in MiniHTTP Web Forum & File Server PowerPack 4.0 allows remote attackers to add or modify arbitrary user accou
23RISCO
abrir ↗Referência✓ VexDay Proof
LinPHA 1.3.1 - 'new_images.php' Blind SQL Injection
SQL injection vulnerability in include/img_view.class.php in LinPHA 1.3.1 and earlier allows remote attackers to execute
23RISCO
abrir ↗Referência✓ VexDay Proof
Shop-Script FREE 2.0 - Remote Command Execution
admin.php in Shop-Script FREE 2.0 and earlier sends a redirect to the web browser but does not exit when administrative
23RISCO
abrir ↗Referência✓ VexDay Proof
Gobbl CMS 1.0 - Insecure Cookie Handling
admin/auth.php in Gobbl CMS 1.0 allows remote attackers to bypass authentication and gain administrative access by setti
23RISCO
abrir ↗Referência✓ VexDay Proof
ASPPortal 3.2.5 - Database Disclosure
ASP Portal 3.2.5 stores sensitive information under the web root with insufficient access control, which allows remote a
23RISCO
abrir ↗Referência✓ VexDay Proof
SH-News 3.0 - Insecure Cookie Handling
action.php in SH-News 3.0 allows remote attackers to bypass authentication and gain administrator privileges by setting
23RISCO
abrir ↗Referência✓ VexDay Proof
Absolute Form Processor 4.0 - Insecure Cookie Handling
Xigla Software Absolute Form Processor .NET 4.0 allows remote attackers to bypass authentication and gain administrative
23RISCO
abrir ↗Referência
CVE-2009-4319
PHP remote file inclusion vulnerability in js/bbcodepress/bbcode-form.php in eoCMS 0.9.03 and earlier, when register_glo
23RISCO
abrir ↗Referência
CVE-2018-10763
Multiple cross-site scripting (XSS) vulnerabilities in Synametrics SynaMan 4.0 build 1488 via the (1) Main heading or (2
23RISCO
abrir ↗Referência
CVE-2018-10763
Multiple cross-site scripting (XSS) vulnerabilities in Synametrics SynaMan 4.0 build 1488 via the (1) Main heading or (2
23RISCO
abrir ↗Referência
CVE-2026-58372
SeaweedFS < 4.34 - Cross-Bucket Object Deletion via DeleteObjects Request-Body Keys
41RISCO
abrir ↗Referência✓ VexDay Proof
Enthrallweb eClassifieds 1.0 - Remote User Pass Change
myprofile.asp in Enthrallweb eClassifieds does not properly validate the MM_recordId parameter during profile updates, w
23RISCO
abrir ↗Referência
CVE-2018-0492
Johnathan Nightingale beep through 1.3.4, if setuid, has a race condition that allows local privilege escalation.
23RISCO
abrir ↗Referência
CVE-2012-5917
SnackAmp 3.1.3 allows remote attackers to cause a denial of service (application crash) via a long string in an aiff fil
23RISCO
abrir ↗Referência
CVE-2010-4145
Kisisel Radyo Script stores sensitive information under the web root with insufficient access control, which allows remo
23RISCO
abrir ↗Referência
CVE-2010-4145
Kisisel Radyo Script stores sensitive information under the web root with insufficient access control, which allows remo
23RISCO
abrir ↗Referência
CVE-2009-4626
Directory traversal vulnerability in menu.php in phpNagios 1.2.0 allows remote attackers to include and execute arbitrar
23RISCO
abrir ↗Referência
CVE-2021-3186
A Stored Cross-site scripting (XSS) vulnerability in /main.html Wifi Settings in Tenda AC5 AC1200 version V15.03.06.47_m
23RISCO
abrir ↗Referência
CVE-2017-17649
Readymade Video Sharing Script 3.2 has HTML Injection via the single-video-detail.php comment parameter.
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.