Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.526exploits catalogados
34.478CVEs com exploração pública
24.695testados em laboratório
21.534 exploits
ReferênciaVexDay Proof
Moodle < 1.6.9/1.7.7/1.8.9/1.9.5 - File Disclosure
CVE-2009-1171webappsphp
The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+, 1.8 before 1.8.9, and 1.9 before 1.9.5 allows user-assist
23RISCO
abrir
Referência
CVE-2014-2579
Multiple cross-site request forgery (CSRF) vulnerabilities in XCloner Standalone 3.5 and earlier allow remote attackers
23RISCO
abrir
Referência
CVE-2015-1723
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S
23RISCO
abrir
Referência
CVE-2026-6143
farion1231 cc-switch ProxyServer server.rs cross-domain policy
33RISCO
abrir
Referência
CVE-2012-1025
Absolute path traversal vulnerability in file in Enigma2 Webinterface 1.6.0 through 1.6.8, 1.6rc3, and 1.7.0 allows remo
23RISCO
abrir
Referência
CVE-2009-2382
admin.php in phpMyBlockchecker 1.0.0055 allows remote attackers to bypass authentication and gain administrative access
23RISCO
abrir
Referência
CVE-2023-38501
copyparty vulnerable to reflected cross-site scripting via k304 parameter
48RISCO
abrir
Referência
CVE-2025-11418
Tenda CH22 HTTP Request AdvSetWrlsafeset formWrlsafeset stack-based overflow
48RISCO
abrir
Referência
CVE-2018-18762
SaltOS 3.1 r8126 contains a database download vulnerability.
23RISCO
abrir
Referência
CVE-2018-18762
SaltOS 3.1 r8126 contains a database download vulnerability.
23RISCO
abrir
Referência
CVE-2010-0982
Directory traversal vulnerability in the CARTwebERP (com_cartweberp) component 1.56.75 for Joomla! allows remote attacke
38RISCO
abrir
Referência
CVE-2009-2568
Stack-based buffer overflow in Sorinara Streaming Audio Player (SAP) 0.9 allows remote attackers to execute arbitrary co
23RISCO
abrir
Referência
CVE-2009-2568
Stack-based buffer overflow in Sorinara Streaming Audio Player (SAP) 0.9 allows remote attackers to execute arbitrary co
23RISCO
abrir
ReferênciaVexDay Proof
PortalApp 4.0 - SQL Injection / Cross-Site Scripting / Authentication Bypass
CVE-2008-4614webappsasp
PortalApp 4.0 does not require authentication for (1) forums.asp and (2) content.asp, which allows remote attackers to c
23RISCO
abrir
ReferênciaVexDay Proof
CodeAvalanche FreeForum - Database Disclosure
CVE-2008-5932webappsasp
CodeAvalanche FreeForum stores sensitive information under the web root with insufficient access control, which allows r
23RISCO
abrir
ReferênciaVexDay Proof
OraMon 2.0.1 - Remote Configuration File Disclosure
CVE-2008-6869webappsphp
Oramon Oracle Database Monitoring Tool 2.0.1 stores sensitive information under the web root with insufficient access co
23RISCO
abrir
ReferênciaVexDay Proof
Triologic Media Player 7 - '.m3u' Local Heap Buffer Overflow (PoC)
CVE-2009-0262doswindows
Stack-based buffer overflow in Triologic Media Player 7 and 8.0.0.0 allows user-assisted remote attackers to execute arb
23RISCO
abrir
ReferênciaVexDay Proof
Pinnacle Studio 12 - '.hfz' Directory Traversal
CVE-2009-1743localwindows
Directory traversal vulnerability in InstallHFZ.exe 6.5.201.0 in Pinnacle Hollywood Effects 6, a module in Pinnacle Syst
23RISCO
abrir
Referência
CVE-2015-1674
The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not pr
23RISCO
abrir
Referência
CVE-2019-9881
The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on
43RISCO
abrir
Referência
CVE-2010-0804
Cross-site scripting (XSS) vulnerability in index.php in iBoutique 4.0 allows remote attackers to inject arbitrary web s
23RISCO
abrir
ReferênciaVexDay Proof
Vote-Pro 4.0 - 'poll_frame.php?poll_id' Remote Code Execution
CVE-2007-0504webappsphp
Eval injection vulnerability in poll_frame.php in Vote! Pro 4.0, and possibly other scripts, allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
EDraw Office Viewer Component 5.2 - ActiveX Remote Buffer Overflow (PoC)
CVE-2007-4821doswindows
Buffer overflow in a certain ActiveX control in officeviewer.ocx 5.2.218.1 in EDraw Office Viewer Component 5.2 allows r
23RISCO
abrir
ReferênciaVexDay Proof
AvailScript Article Script - Arbitrary File Upload
CVE-2008-6900webappsphp
Unrestricted file upload vulnerability in "Add Pen/Author Name" feature in addpen.php in AvailScript Article Script allo
23RISCO
abrir
Referência
CVE-2023-0527
PHPGurukul Online Security Guards Hiring System search-request.php cross site scripting
43RISCO
abrir
Referência
CVE-2017-15359
In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory t
23RISCO
abrir
Referência
Webrun 3.6.0.42 - 'P_0' SQL Injection
CVE-2021-43650webappsmultiple
WebRun 3.6.0.42 is vulnerable to SQL Injection via the P_0 parameter used to set the username during the login process.
23RISCO
abrir
ReferênciaVexDay Proof
moziloCMS 1.11 - Local File Inclusion / Full Path Disclosure / Cross-Site Scripting
CVE-2009-1368webappsphp
Directory traversal vulnerability in index.php in moziloCMS 1.11 allows remote attackers to read arbitrary files via a .
23RISCO
abrir
Referência
CVE-2017-2442
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issu
23RISCO
abrir
Referência
CVE-2017-2367
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISCO
abrir
anteriorpágina 201 / 718próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.