Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.533exploits catalogados
35.607CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.455Referência 22.407GitHub PoC 14.247VulnCheck XDB 8.663Nuclei 4.287Metasploit 3.474✓ só verificadosrecentespopularesrisco
22.367 exploits
Referência
CVE-2020-16040
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially explo
60RISCO
abrir ↗Referência
CVE-2017-13209
In the ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the
23RISCO
abrir ↗Referência
CVE-2020-16040
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially explo
60RISCO
abrir ↗Referência
CVE-2017-13216
In ashmem_ioctl of ashmem.c, there is an out-of-bounds write due to insufficient locking when accessing asma. This could
23RISCO
abrir ↗Referência
CVE-2020-17456
SEOWON INTECH SLC-130 And SLR-120S devices allow Remote Code Execution via the ipAddr parameter to the system_log.cgi pa
60RISCO
abrir ↗Referência
CVE-2017-13258
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead
23RISCO
abrir ↗Referência
CVE-2017-13258
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead
23RISCO
abrir ↗Referência
CVE-2017-13794
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RISCO
abrir ↗Referência
CVE-2011-5283
Cross-site scripting (XSS) vulnerability in the web management interface in httpd/cgi-bin/ipinfo.cgi in Smoothwall Expre
23RISCO
abrir ↗Referência
CVE-2011-5283
Cross-site scripting (XSS) vulnerability in the web management interface in httpd/cgi-bin/ipinfo.cgi in Smoothwall Expre
23RISCO
abrir ↗Referência
CVE-2026-16070
Brizy - Page Builder < 2.8.19 - Contributor+ Template Type Update via IDOR
28RISCO
abrir ↗Referência
CVE-2026-16069
Brizy - Page Builder < 2.8.19 - Contributor+ Stored XSS via Featured Image Focal Point
33RISCO
abrir ↗Referência
CVE-2026-16068
Brizy - Page Builder < 2.8.19 - Author+ Stored XSS via brizy_set_project Global Project Code Asset
28RISCO
abrir ↗Referência
CVE-2020-25762
An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input v
28RISCO
abrir ↗Referência
CVE-2020-25762
An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input v
28RISCO
abrir ↗Referência
CVE-2020-26567
An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed
28RISCO
abrir ↗Referência✓ VexDay Proof
Xcode OpenBase 10.0.0 (OSX) - Symlink Privilege Escalation
openexec in OpenBase SQL before 10.0.1 allows local users to create arbitrary files via a symlink attack on the /tmp/out
23RISCO
abrir ↗Referência✓ VexDay Proof
Xcode OpenBase 10.0.0 (OSX) - Unsafe System Call Privilege Escalation
Untrusted search path vulnerability in openexec in OpenBase SQL before 10.0.1 allows local users to gain privileges via
23RISCO
abrir ↗Referência
Genexis Platinum 4410 Router 2.1 - UPnP Credential Exposure
UPNP Service listening on port 5555 in Genexis Platinum 4410 Router V2.1 (P4410-V2–1.34H) has an action 'X_GetAccess' wh
23RISCO
abrir ↗Referência✓ VexDay Proof
UPublisher 1.0 - 'viewarticle.asp' SQL Injection
SQL injection vulnerability in viewarticle.asp in Superfreaker Studios UPublisher 1.0 allows remote attackers to execute
23RISCO
abrir ↗Referência✓ VexDay Proof
BrewBlogger 1.3.1 - 'printLog.php' SQL Injection
SQL injection vulnerability in printLog.php in BrewBlogger (BB) 1.3.1 allows remote attackers to execute arbitrary SQL c
23RISCO
abrir ↗Referência✓ VexDay Proof
AspPired2Poll 1.0 - 'MoreInfo.asp' SQL Injection
SQL injection vulnerability in MoreInfo.asp in The Net Guys ASPired2Poll 1.0 and earlier allows remote attackers to exec
23RISCO
abrir ↗Referência✓ VexDay Proof
StoryStream 4.0 - 'baseDir' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in iWonder Designs Storystream 0.4.0.0 allow remote attackers to exec
23RISCO
abrir ↗Referência✓ VexDay Proof
Rama CMS 0.68 - Cookie: lang Local File Inclusion
Directory traversal vulnerability in lang.php in Rama CMS 0.68 and earlier, when register_globals is enabled, allows rem
23RISCO
abrir ↗Referência✓ VexDay Proof
EncapsCMS 0.3.6 - '/core/core.php' Remote File Inclusion
PHP remote file inclusion vulnerability in core/core.php in EncapsCMS 0.3.6 allows remote attackers to execute arbitrary
23RISCO
abrir ↗Referência
CVE-2026-14820
Quiz And Survey Master < 11.1.3 - Unauthenticated User Enumeration and Password Oracle via Quiz Login
33RISCO
abrir ↗Referência✓ VexDay Proof
Helix Server 11.0.1 (Windows 2000 SP4) - Remote Heap Overflow
Heap-based buffer overflow in Real Networks Helix Server and Helix Mobile Server before 11.1.3, and Helix DNA Server 11.
28RISCO
abrir ↗Referência✓ VexDay Proof
Powies pForum 1.29a - 'editpoll.php' SQL Injection
SQL injection vulnerability in editpoll.php in Powie's PHP Forum (pForum) 1.29a and earlier allows remote attackers to e
23RISCO
abrir ↗Referência✓ VexDay Proof
XMPlay 3.3.0.4 - '.M3U' Filename Local Buffer Overflow
Stack-based buffer overflow in Un4seen XMPlay 3.3.0.5 and earlier allows remote attackers to execute arbitrary code via
50RISCO
abrir ↗Referência
CVE-2026-12979
FunnelKit < 3.15.0.6 - Admin+ Arbitrary File Deletion via Path Traversal in Template Importer
33RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.