Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.386exploits catalogados
36.533CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.466Referência 23.104GitHub PoC 15.075VulnCheck XDB 8.883Nuclei 4.365Metasploit 3.493✓ só verificadosrecentespopularesrisco
24.466 exploits
Exploit-DB
IBM i Access Client Solutions v1.1.2 - 1.1.4_ v1.1.4.3 - 1.1.9.4 - Remote Credential Theft
IBM i Access Client Solutions information disclosure
33RISCO
abrir ↗Exploit-DB
Wyrestorm Apollo VX20 < 1.3.58 - Incorrect Access Control 'Credentials Disclosure'
An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext password
75RISCO
abrir ↗Exploit-DB
Wyrestorm Apollo VX20 < 1.3.58 - Incorrect Access Control 'DoS'
An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can restart the device via a /d
41RISCO
abrir ↗Exploit-DB
Wyrestorm Apollo VX20 < 1.3.58 - Account Enumeration
An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. The TELNET service prompts for a password only a
41RISCO
abrir ↗Exploit-DB
SureMDM On-premise < 6.31 - CAPTCHA Bypass User Enumeration
Bypassing CAPTCHA & Enumerating Usernames via Password Reset Page
33RISCO
abrir ↗Exploit-DB
BoidCMS v2.0.0 - authenticated file upload vulnerability
File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header t
60RISCO
abrir ↗Exploit-DB
Clcknshop 1.0.0 - SQL Injection
Infosoftbd Clcknshop GET Parameter all sql injection
45RISCO
abrir ↗Exploit-DB
Cacti 1.2.24 - Authenticated command injection when using SNMP options
Authenticated command injection in SNMP options of a Device
63RISCO
abrir ↗Exploit-DB
Media Library Assistant Wordpress Plugin - RCE and LFI
Media Library Assistant <= 3.09 - Unauthenticated Local/Remote File Inclusion & Remote Code Execution
85RISCO
abrir ↗Exploit-DB
Wordpress Plugin Masterstudy LMS - 3.0.17 - Unauthenticated Instructor Account Creation
MasterStudy LMS < 3.0.18 - Unauthenticated Instructor Account Creation
41RISCO
abrir ↗Exploit-DB
Splunk 9.0.5 - admin account take over
‘edit_user’ Capability Privilege Escalation
78RISCO
abrir ↗Exploit-DB
Minio 2022-07-29T19-40-48Z - Path traversal
Authenticated requests for server update admin API allows path traversal in minio
53RISCO
abrir ↗Exploit-DB
Wordpress Plugin Elementor 3.5.5 - Iframe Injection
Elementor < 3.5.5 - Iframe Injection
23RISCO
abrir ↗Exploit-DB
Techview LA-5570 Wireless Gateway Home Automation Controller - Multiple Vulnerabilities
An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows attackers to gain sensitive information
23RISCO
abrir ↗Exploit-DB
Axigen < 10.3.3.47_ 10.2.3.12 - Reflected XSS
An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12
50RISCO
abrir ↗Exploit-DB
SPA-Cart eCommerce CMS 1.9.0.3 - SQL Injection
SPA-Cart eCommerce CMS GET Parameter search sql injection
38RISCO
abrir ↗Exploit-DB
Hyip Rio 2.1 - Arbitrary File Upload
tdevs Hyip Rio Profile Settings settings cross site scripting
28RISCO
abrir ↗Exploit-DB
Ivanti Avalanche <v6.4.0.0 - Remote Code Execution
An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disrup
78RISCO
abrir ↗Exploit-DB
SPA-Cart eCommerce CMS 1.9.0.3 - Reflected XSS
SPA-Cart eCommerce CMS search cross site scripting
55RISCO
abrir ↗Exploit-DB
WP Statistics Plugin 13.1.5 current_page_id - Time based SQL injection (Unauthenticated)
WP Statistics <= 13.1.5 Unauthenticated Blind SQL Injection via current_page_id
85RISCO
abrir ↗Exploit-DB
Credit Lite 1.5.4 - SQL Injection
Codecanyon Credit Lite POST Request account_statement sql injection
33RISCO
abrir ↗Exploit-DB
FileMage Gateway 1.10.9 - Local File Inclusion
Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker t
43RISCO
abrir ↗Exploit-DB
AdminLTE PiHole 5.18 - Broken Access Control
Pi-Hole/AdminLTE vulnerable due to improper access control in queryads endpoint
45RISCO
abrir ↗Exploit-DB
Crypto Currency Tracker (CCT) 9.5 - Admin Account Creation (Unauthenticated)
Incorrect access control in the User Registration page of Crypto Currency Tracker (CCT) before v9.5 allows unauthenticat
23RISCO
abrir ↗Exploit-DB
TP-Link Archer AX21 - Unauthenticated Command Injection
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability i
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Social-Commerce 3.1.6 - Reflected XSS
mooSocial mooStore cross site scripting
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
mooSocial 3.1.8 - Reflected XSS
mooSocial mooStore index cross site scripting
43RISCO
abrir ↗Exploit-DB
Adlisting Classified Ads 2.14.0 - WebPage Content Information Disclosure
Templatecookie Adlisting Redirect ad-list information disclosure
60RISCO
abrir ↗Exploit-DB
Emagic Data Center Management Suite v6.0 - OS Command Injection
OS Command Injection Vulnerability in Emagic Data Center Management Suite
53RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.