Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.526exploits catalogados
34.478CVEs com exploração pública
24.695testados em laboratório
21.534 exploits
Referência
CVE-2011-1670
Cross-site scripting (XSS) vulnerability in actions/add.php in InTerra Blog Machine 1.84, and possibly earlier versions,
23RISCO
abrir
Referência
CVE-2009-0855
Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 6.1 bef
23RISCO
abrir
Referência
CVE-2012-2602
Multiple cross-site request forgery (CSRF) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before
23RISCO
abrir
Referência
CVE-2009-3664
Multiple directory traversal vulnerabilities in index.php in Nullam Blog 0.1.2 allow remote attackers to include or exec
23RISCO
abrir
Referência
CVE-2014-3849
The iMember360 plugin 3.8.012 through 3.9.001 for WordPress does not properly restrict access, which allows remote attac
23RISCO
abrir
Referência
CVE-2014-3849
The iMember360 plugin 3.8.012 through 3.9.001 for WordPress does not properly restrict access, which allows remote attac
23RISCO
abrir
Referência
CVE-2021-24145
Modern Events Calendar Lite < 5.16.5 - Authenticated Arbitrary File Upload leading to RCE
60RISCO
abrir
Referência
CVE-2013-0663
Cross-site request forgery (CSRF) vulnerability on the Schneider Electric Quantum 140NOE77111, 140NOE77101, and 140NWM10
23RISCO
abrir
Referência
CVE-2017-6074
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST p
23RISCO
abrir
Referência
CVE-2017-6074
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST p
23RISCO
abrir
ReferênciaVexDay Proof
Advanced Webhost Billing System (AWBS) 2.4.0 - 'cart2.php' Remote File Inclusion
CVE-2007-2272webappsphp
PHP remote file inclusion vulnerability in docs/front-end-demo/cart2.php in Advanced Webhost Billing System (AWBS) 2.4.0
23RISCO
abrir
Referência
CVE-2016-8523
A Remote Arbitrary Code Execution vulnerability in HPE Smart Storage Administrator version before v2.60.18.0 was found.
28RISCO
abrir
Referência
CVE-2017-7183
The TFTP server in ExtraPuTTY 0.30 and earlier allows remote attackers to cause a denial of service (crash) via a large
23RISCO
abrir
Referência
CVE-2009-3019
Microsoft Internet Explorer 6 on Windows XP SP2 and SP3, and Internet Explorer 7 on Vista, allows remote attackers to ca
28RISCO
abrir
Referência
CVE-2017-7183
The TFTP server in ExtraPuTTY 0.30 and earlier allows remote attackers to cause a denial of service (crash) via a large
23RISCO
abrir
Referência
CVE-2018-16606
In ProConf before 6.1, an Insecure Direct Object Reference (IDOR) allows any author to view and grab all submitted paper
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft FoxServer - 'vfp6r.dll 6.0.8862.0' ActiveX Command Execution
CVE-2008-0236remotewindows
An ActiveX control for Microsoft Visual FoxPro (vfp6r.dll 6.0.8862.0) allows remote attackers to execute arbitrary comma
28RISCO
abrir
ReferênciaVexDay Proof
PhpAddEdit 1.3 - 'cookie' Authentication Bypass
CVE-2008-6581webappsphp
login.php in PhpAddEdit 1.3 allows remote attackers to bypass authentication and gain administrative access by setting t
23RISCO
abrir
ReferênciaVexDay Proof
eZip Wizard 3.0 - Local Stack Buffer Overflow (PoC) (SEH)
CVE-2009-1058doswindows
Stack-based buffer overflow in ZipGenius might allow remote attackers to execute arbitrary code via a crafted .zip file
23RISCO
abrir
Referência
CVE-2018-6323
The elf_object_p function in elfcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU B
23RISCO
abrir
ReferênciaVexDay Proof
PHPCollab 2.x / NetOffice 2.x - 'sendpassword.php' SQL Injection
CVE-2006-1495webappsphp
SQL injection vulnerability in general/sendpassword.php in (1) PHPCollab 2.4 and 2.5.rc3, and (2) NetOffice 2.5.3-pl1 an
23RISCO
abrir
Referência
CVE-2017-5850
httpd in OpenBSD allows remote attackers to cause a denial of service (memory consumption) via a series of requests for
28RISCO
abrir
Referência
CVE-2010-2045
Directory traversal vulnerability in the Dione Form Wizard (aka FDione or com_dioneformwizard) component 1.0.2 for Jooml
38RISCO
abrir
Referência
CVE-2019-12189
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field.
23RISCO
abrir
Referência
CVE-2009-2396
PHP remote file inclusion vulnerability in template/album.php in DM Albums 1.9.2, as used standalone or as a WordPress p
23RISCO
abrir
Referência
CVE-2017-5850
httpd in OpenBSD allows remote attackers to cause a denial of service (memory consumption) via a series of requests for
28RISCO
abrir
Referência
CVE-2017-14939
decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.
23RISCO
abrir
ReferênciaVexDay Proof
PHP 4.4.6/5.2.1 - ext/gd Already Freed Resources Usage
CVE-2007-1582locallinux
The resource system in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to execute arb
23RISCO
abrir
Referência
CVE-2009-2653
The NtUserConsoleControl function in win32k.sys in Microsoft Windows XP SP2 and SP3, and Server 2003 before SP1, allows
23RISCO
abrir
Referência
Nagios Log Server 2024R1.3.1 - Stored XSS
CVE-2025-29471HIGHwebappsmultiple
Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code
41RISCO
abrir
anteriorpágina 207 / 718próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.