Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.386exploits catalogados
36.533CVEs com exploração pública
24.695testados em laboratório
24.466 exploits
Exploit-DB
Daily Habit Tracker 1.0 - Broken Access Control
CVE-2024-24496CRITICALwebappsphp02 abr 2024
An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php,
53RISCO
abrir
Exploit-DB
Employee Management System 1.0 - _txtusername_ and _txtpassword_ SQL Injection (Admin Login)
CVE-2024-24497webappsphp02 abr 2024
20RISCO
abrir
Exploit-DB
Daily Habit Tracker 1.0 - SQL Injection
CVE-2024-24495CRITICALwebappsphp02 abr 2024
SQL Injection vulnerability in delete-tracker.php in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbit
48RISCO
abrir
Exploit-DB
Employee Management System 1.0 - _txtfullname_ and _txtphone_ SQL Injection
CVE-2024-24499webappsphp02 abr 2024
20RISCO
abrir
Exploit-DB
Gibbon LMS v26.0.00 - SSTI vulnerability
CVE-2024-24724CRITICALwebappsphp02 abr 2024
Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Re
53RISCO
abrir
Exploit-DB
GL-iNet MT6000 4.5.5 - Arbitrary File Download
CVE-2024-27356HIGHremotehardware02 abr 2024
An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially
46RISCO
abrir
Exploit-DB
Casdoor < v1.331.0 - '/api/set-password' CSRF
CVE-2023-34927webappsgo02 abr 2024
Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-passwo
23RISCO
abrir
Exploit-DB
HNAS SMU 14.8.7825 - Information Disclosure
CVE-2023-6538HIGHremotehardware20 mar 2024
System Management Unit (SMU) versions prior to 14.8.7825.01, used to manage Hitachi Vantara NAS products is susceptible to unintended information disclosure via unprivileged access to SMU configuration backup data.
41RISCO
abrir
Exploit-DB
Blood Bank 1.0 - 'bid' SQLi
CVE-2023-46022webappsphp20 mar 2024
SQL Injection vulnerability in delete.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands
23RISCO
abrir
Exploit-DB
Employee Management System 1.0 - 'admin_id' SQLi
CVE-2024-28595CRITICALwebappsphp20 mar 2024
SQL Injection vulnerability in Employee Management System v1.0 allows attackers to run arbitrary SQL commands via the ad
48RISCO
abrir
Exploit-DB
Teacher Subject Allocation Management System 1.0 - 'searchdata' SQLi
CVE-2023-46024webappsphp20 mar 2024
SQL Injection vulnerability in index.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers
23RISCO
abrir
Exploit-DB
Viessmann Vitogate 300 2.1.3.0 - Remote Code Execution (RCE)
CVE-2023-5702MEDIUMremotehardware14 mar 2024
Viessmann Vitogate 300 direct request
38RISCO
abrir
Exploit-DB
Honeywell PM43 < P10.19.050004 - Remote Code Execution (RCE)
CVE-2023-3710CRITICALremotehardware14 mar 2024
Printer web page invalid command execution
75RISCO
abrir
Exploit-DB
KiTTY 0.76.1.13 - 'Start Duplicated Session Username' Buffer Overflow
CVE-2024-25004HIGHlocalwindows14 mar 2024
KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the username, occurs due to insuf
41RISCO
abrir
Exploit-DB
Viessmann Vitogate 300 2.1.3.0 - Remote Code Execution (RCE)
CVE-2023-5222MEDIUMremotehardware14 mar 2024
Viessmann Vitogate 300 Web Management Interface vitogate.cgi isValidUser hard-coded password
70RISCO
abrir
Exploit-DB
KiTTY 0.76.1.13 - Command Injection
CVE-2024-23749HIGHlocalwindows14 mar 2024
KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insuffic
41RISCO
abrir
Exploit-DB
JetBrains TeamCity 2023.05.3 - Remote Code Execution (RCE)
CVE-2023-42793CRITICALsob ataqueransomwareremotejava14 mar 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISCO
abrir
Exploit-DB
SolarView Compact 6.00 - Command Injection
CVE-2023-23333CRITICALremotehardware14 mar 2024
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RISCO
abrir
Exploit-DB
GitLab CE/EE < 16.7.2 - Password Reset
CVE-2023-7028CRITICALsob ataqueremotejava14 mar 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISCO
abrir
Exploit-DB
KiTTY 0.76.1.13 - 'Start Duplicated Session Hostname' Buffer Overflow
CVE-2024-25003HIGHlocalwindows14 mar 2024
KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the hostname, occurs due to insuf
41RISCO
abrir
Exploit-DB
Hide My WP < 6.2.9 - Unauthenticated SQLi
CVE-2022-4681CRITICALwebappsphp10 mar 2024
Hide My WP < 6.2.9 - Unauthenticated SQLi
48RISCO
abrir
Exploit-DB
Ladder v0.0.21 - Server-side request forgery (SSRF)
CVE-2024-27620HIGHwebappsgo10 mar 2024
An issue in Ladder v.0.0.1 thru v.0.0.21 allows a remote attacker to obtain sensitive information via a crafted request
41RISCO
abrir
Exploit-DB
DataCube3 v1.0 - Unrestricted file upload 'RCE'
CVE-2024-25832HIGHwebappsphp10 mar 2024
F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to
46RISCO
abrir
Exploit-DB
Akaunting < 3.1.3 - RCE
CVE-2024-22836CRITICALwebappsphp10 mar 2024
An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company loc
60RISCO
abrir
Exploit-DB
Numbas < v7.3 - Remote Code Execution
CVE-2024-27612MEDIUMwebappsnodejs10 mar 2024
Numbas editor before 7.3 mishandles editing of themes and extensions.
38RISCO
abrir
Exploit-DB
DataCube3 v1.0 - Unrestricted file upload 'RCE'
CVE-2024-25830CRITICALwebappsphp10 mar 2024
F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An una
53RISCO
abrir
Exploit-DB
Petrol Pump Management Software v.1.0 - Stored Cross Site Scripting via SVG file
CVE-2024-27744MEDIUMremotephp03 mar 2024
Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code
33RISCO
abrir
Exploit-DB
Petrol Pump Management Software v.1.0 - SQL Injection
CVE-2024-27746CRITICALremotephp03 mar 2024
SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a c
53RISCO
abrir
Exploit-DB
Petrol Pump Management Software v1.0 - Remote Code Execution via File Upload
CVE-2024-27747CRITICALremotephp03 mar 2024
File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a cra
53RISCO
abrir
Exploit-DB
Petrol Pump Management Software v1.0 - 'Address' Stored Cross Site Scripting
CVE-2024-27743MEDIUMremotephp03 mar 2024
Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code
33RISCO
abrir
anteriorpágina 17 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.