Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.589exploits catalogados
34.508CVEs com exploração pública
24.695testados em laboratório
21.554 exploits
Referência
CVE-2014-1944
Cross-site scripting (XSS) vulnerability in Ilch CMS 2.0 and earlier allows remote attackers to inject arbitrary web scr
23RISCO
abrir
Referência
CVE-2017-11120
On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, an attacker can craft a malformed RRM neighbor repo
23RISCO
abrir
ReferênciaVexDay Proof
SugarCRM Community Edition 4.5.1/5.0.0 - File Disclosure
CVE-2008-2045webappsphp
Absolute path traversal vulnerability in SugarCRM Sugar Community Edition 4.5.1 and 5.0.0 allows remote attackers to rea
23RISCO
abrir
Referência
CVE-2010-1176
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash)
23RISCO
abrir
Referência
CVE-2018-4121
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud b
28RISCO
abrir
Referência
CVE-2019-19031
Easy XML Editor through v1.7.8 is affected by: XML External Entity Injection. The impact is: Arbitrary File Read and DoS
23RISCO
abrir
Referência
CVE-2019-7652
TheHive Project UnshortenLink analyzer before 1.1, included in Cortex-Analyzers before 1.15.2, has SSRF. To exploit the
23RISCO
abrir
Referência
CVE-2025-14709
Shiguangwu sgwbox N3 WIRELESSCFGGET http_eshell_server buffer overflow
48RISCO
abrir
Referência
CVE-2011-0961
Cross-site scripting (XSS) vulnerability in cwhp/device.center.do in the Help servlet in Cisco CiscoWorks Common Service
23RISCO
abrir
ReferênciaVexDay Proof
runawaysoft haber portal 1.0 - 'tr' Multiple Vulnerabilities
CVE-2007-2753webappsasp
RunawaySoft Haber portal 1.0 stores sensitive information under the web root with insufficient access control, which all
23RISCO
abrir
Referência
CVE-2015-1368
Multiple cross-site scripting (XSS) vulnerabilities in Ansible Tower (aka Ansible UI) before 2.0.5 allow remote attacker
23RISCO
abrir
Referência
CVE-2015-1368
Multiple cross-site scripting (XSS) vulnerabilities in Ansible Tower (aka Ansible UI) before 2.0.5 allow remote attacker
23RISCO
abrir
Referência
CVE-2024-3191
MailCleaner Email os command injection
48RISCO
abrir
Referência
CVE-2018-5759
jsparse.c in Artifex MuJS through 1.0.2 does not properly maintain the AST depth for binary expressions, which allows re
23RISCO
abrir
Referência
CVE-2016-4793
The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP head
23RISCO
abrir
Referência
CVE-2010-2549
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2 and Server 2008 Gold and
23RISCO
abrir
Referência
CVE-2016-1803
CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RISCO
abrir
Referência
CVE-2016-1803
CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RISCO
abrir
Referência
CVE-2019-15092
The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in
23RISCO
abrir
Referência
CVE-2019-25699
Newsbull Haber Script 1.0.0 Authenticated SQL Injection via search parameter
41RISCO
abrir
Referência
CVE-2026-21876 PoC: WAF charset bypass (Flask, ASP.NET and Spring Boot stands)
OWASP CRS has multipart bypass using multiple content-type parts
53RISCO
abrir
ReferênciaVexDay Proof
Linksys WRT54G Firmware 1.00.9 - Security Bypass (1)
CVE-2008-1247remotehardware
The web interface on the Linksys WRT54g router with firmware 1.00.9 does not require credentials when invoking scripts,
23RISCO
abrir
ReferênciaVexDay Proof
ASP PORTAL - Remote Database Disclosure
CVE-2008-5562webappsasp
ASPPortal stores sensitive information under the web root with insufficient access control, which allows remote attacker
23RISCO
abrir
ReferênciaVexDay Proof
Total Video Player 1.31 - 'DefaultSkin.ini' Local Stack Overflow
CVE-2009-0261localwindows
Stack-based buffer overflow in EffectMatrix Total Video Player 1.31 allows user-assisted attackers to execute arbitrary
43RISCO
abrir
ReferênciaVexDay Proof
FipsCMS Light 2.1 - 'db.mdb' Remote Database Disclosure
CVE-2009-2022webappsasp
fipsCMS Light 2.1 stores sensitive information under the web root with insufficient access control, which allows remote
23RISCO
abrir
Referência
CVE-2016-1755
The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to exe
23RISCO
abrir
ReferênciaVexDay Proof
WebMatic 2.6 - 'index_album.php' Remote File Inclusion
CVE-2007-0839webappsphp
Multiple PHP remote file inclusion vulnerabilities in index/index_album.php in Valarsoft WebMatic 2.6 allow remote attac
23RISCO
abrir
Referência
CVE-2015-4591
eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remo
23RISCO
abrir
Referência
CVE-2015-4591
eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remo
23RISCO
abrir
ReferênciaVexDay Proof
STWC-Counter 3.4.0 - 'downloadcounter.php' Remote File Inclusion
CVE-2007-1233webappsphp
PHP remote file inclusion vulnerability in downloadcounter.php in STWC-Counter 3.4.0.0 and earlier allows remote attacke
23RISCO
abrir
anteriorpágina 215 / 719próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.