Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.900exploits catalogados
35.840CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.600GitHub PoC 14.323VulnCheck XDB 8.722Nuclei 4.320Metasploit 3.477✓ só verificadosrecentespopularesrisco
22.600 exploits
Referência
CVE-2016-5195
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir ↗Referência
CVE-2016-5195
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir ↗Referência
CVE-2014-0329
The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account
23RISCO
abrir ↗Referência
CVE-2014-0476
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute a
38RISCO
abrir ↗Referência
CVE-2026-7121
Totolink A8000RU CGI cstecgi.cgi setWizardCfg os command injection
48RISCO
abrir ↗Referência
CVE-2026-16632
boazsegev facil.io WebSocket Frame websocket_parser.h websocket_on_protocol_error input validation
33RISCO
abrir ↗Referência
CVE-2026-16631
publint package-manager pack.js child_process.exec os command injection
33RISCO
abrir ↗Referência
CVE-2026-65013
Onlook tRPC Insecure Direct Object Reference via multiple procedures
41RISCO
abrir ↗Referência
CVE-2010-4357
SQL injection vulnerability in comments.php in SiteEngine 7.1 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir ↗Referência
CVE-2010-4359
SQL injection vulnerability in index.php in Jurpopage 0.2.0 allows remote attackers to execute arbitrary SQL commands vi
23RISCO
abrir ↗Referência
CVE-2010-4362
Multiple SQL injection vulnerabilities in MicroNetsoft RV Dealer Website allow remote attackers to execute arbitrary SQL
23RISCO
abrir ↗Referência
CVE-2026-74899
openssl_encrypt before 1.4.0 Sandbox Escape via Type Hierarchy
48RISCO
abrir ↗Referência
CVE-2026-19986
Adblock for Youtube Extension Event Listener contentscript.js updateDynamicRules improper authorization
33RISCO
abrir ↗Referência
CVE-2026-19978
jiantao88 android-mcp-server Command Execution index.js child_process.exec os command injection
33RISCO
abrir ↗Referência
CVE-2026-19977
EFM ipTIME A3004T Session Validation httpcon_check_session_url improper authentication
48RISCO
abrir ↗Referência
CVE-2026-19969
Open Asset Import Library Assimp 3DGS MDL7 Model Output Mesh Generator MDLLoader.cpp GenerateOutputMeshes_3DGS_MDL7 buffer overflow
33RISCO
abrir ↗Referência✓ VexDay Proof
SFS EZ Hot or Not - 'phid' SQL Injection
SQL injection vulnerability in viewcomments.php in Scripts For Sites (SFS) EZ Hot or Not allows remote attackers to exec
23RISCO
abrir ↗Referência✓ VexDay Proof
MyPHP Forum 3.0 - Edit Topics / Blind SQL Injection
Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL co
23RISCO
abrir ↗Referência
CVE-2026-19968
Open Asset Import Library Assimp 3DGS MDL7 Model LWOLoader.h ReadFaces_3DGS_MDL7 heap-based overflow
33RISCO
abrir ↗Referência
CVE-2026-19966
CodeCanyon TimeCamp Integration for CRM Contact Information Update save_contact authorization
33RISCO
abrir ↗Referência
CVE-2026-16209
Gerapy Project Upload Endpoint views.py missing authentication
33RISCO
abrir ↗Referência
CVE-2026-16204
zevorn rt-claw Telegram-to-AI Tool Execution Flow script.c tool_run_script_execute code injection
33RISCO
abrir ↗Referência
CVE-2026-19965
automad Password Reset Endpoint UserController.php requestPasswordResetToken response discrepancy
33RISCO
abrir ↗Referência
CVE-2008-6779
SQL injection vulnerability in the Sarkilar module for PHP-Nuke allows remote attackers to execute arbitrary SQL command
23RISCO
abrir ↗Referência
CVE-2010-4365
SQL injection vulnerability in JE Ajax Event Calendar (com_jeajaxeventcalendar) component for Joomla! allows remote atta
23RISCO
abrir ↗Referência
CVE-2010-4365
SQL injection vulnerability in JE Ajax Event Calendar (com_jeajaxeventcalendar) component for Joomla! allows remote atta
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.