Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.302exploits catalogados
35.469CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.301GitHub PoC 14.141VulnCheck XDB 8.646Nuclei 4.289Metasploit 3.474✓ só verificadosrecentespopularesrisco
22.301 exploits
Referência✓ VexDay Proof
Fastpublish CMS 1.6.9 - config[fsBase] Remote File Inclusion
PHP remote file inclusion vulnerability in Fastpublish CMS 1.6.9.d allows remote attackers to include arbitrary files vi
28RISCO
abrir ↗Referência✓ VexDay Proof
Informium 0.12.0 - 'common-menu.php' Remote File Inclusion
PHP remote file inclusion vulnerability in common-menu.php in Cameron McKay Informium 0.12.0 allows remote attackers to
23RISCO
abrir ↗Referência✓ VexDay Proof
Redaxo 3.2 - 'INCLUDE_PATH' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Redaxo 3.0 allow remote attackers to execute arbitrary PHP code vi
23RISCO
abrir ↗Referência✓ VexDay Proof
Wikiwig 4.1 - 'wk_lang.php' Remote File Inclusion
PHP remote file inclusion vulnerability in _wk/wk_lang.php in Wikiwig 4.1 and earlier allows remote attackers to execute
23RISCO
abrir ↗Referência
CVE-2026-23760
SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API
100RISCO
abrir ↗Referência
CVE-2023-6553
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RISCO
abrir ↗Referência
glibc 2.38 - Buffer Overflow
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISCO
abrir ↗Referência✓ VexDay Proof
Linux Kernel 2.6.x - 'sys_timer_create()' Local Denial of Service
The sys_timer_create function in posix-timers.c for Linux kernel 2.6.x allows local users to cause a denial of service (
23RISCO
abrir ↗Referência
CVE-2019-10068
An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions
100RISCO
abrir ↗Referência
CVE-2026-7228
SourceCodester Pizzafy Ecommerce System ajax.php get_cart_count sql injection
33RISCO
abrir ↗Referência✓ VexDay Proof
PHPWind 5.0.1 - 'AdminUser' Blind SQL Injection
SQL injection vulnerability in admin.php in PHPWind 5.0.1 and earlier allows remote attackers to execute arbitrary SQL c
23RISCO
abrir ↗Referência
CVE-2012-1125
Unrestricted file upload vulnerability in uploadify/scripts/uploadify.php in the Kish Guest Posting plugin before 1.2 fo
28RISCO
abrir ↗Referência✓ VexDay Proof
Power Phlogger 2.0.9 - 'config.inc.php3' File Inclusion
PHP remote file inclusion vulnerability in config.inc.php3 in Power Phlogger 2.0.9 and earlier allows remote attackers t
23RISCO
abrir ↗Referência✓ VexDay Proof
FreePBX 2.1.3 - 'upgrade.php' Remote File Inclusion
PHP remote file inclusion vulnerability in upgrade.php in Coalescent Systems freePBX 2.1.3 allows remote attackers to ex
23RISCO
abrir ↗Referência
CVE-2020-17530
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISCO
abrir ↗Referência✓ VexDay Proof
PHP-Stats 0.1.9.1b - 'ip' SQL Injection
Multiple SQL injection vulnerabilities in php-stats.recphp.php in PHP-Stats 0.1.9.1b and earlier allow remote attackers
23RISCO
abrir ↗Referência✓ VexDay Proof
PHP-Stats 0.1.9.1b - 'PC-REMOTE-ADDR' SQL Injection
Multiple SQL injection vulnerabilities in php-stats.recphp.php in PHP-Stats 0.1.9.1b and earlier allow remote attackers
23RISCO
abrir ↗Referência
CVE-2020-24186
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RISCO
abrir ↗Referência
CVE-2020-24186
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RISCO
abrir ↗Referência✓ VexDay Proof
phpBP RC3 (2.204) - SQL Injection / Remote Code Execution
SQL injection vulnerability in phpBP RC3 (2.204) and earlier allows remote attackers to execute arbitrary SQL commands v
23RISCO
abrir ↗Referência✓ VexDay Proof
BrowseDialog Class 'ccrpbds6.dll' Internet Explorer 7 - Denial of Service
A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allo
23RISCO
abrir ↗Referência
CVE-2016-5674
__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR Rea
60RISCO
abrir ↗Referência
CVE-2018-1111
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RISCO
abrir ↗Referência
CVE-2018-1111
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.