Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.589exploits catalogados
34.508CVEs com exploração pública
24.695testados em laboratório
21.554 exploits
ReferênciaVexDay Proof
AlkalinePHP 0.77.35 - 'adduser.php' Arbitrary Add Admin
CVE-2008-2346webappsphp
AlkalinePHP 0.77.35 and earlier allows remote attackers to bypass authentication and gain administrative access by creat
23RISCO
abrir
ReferênciaVexDay Proof
Tlnews 2.2 - Insecure Cookie Handling
CVE-2008-4752webappsphp
TlNews 2.2 allows remote attackers to bypass authentication and gain administrative access by setting the tlNews_login c
23RISCO
abrir
Referência
CVE-2018-5978
SQL Injection exists in Facebook Style Php Ajax Chat Zechat 1.5 via the login.php User field.
23RISCO
abrir
ReferênciaVexDay Proof
TorrentTrader Classic 1.09 - Multiple Vulnerabilities
CVE-2009-2159webappsphp
backup-database.php in TorrentTrader Classic 1.09 does not require administrative authentication, which allows remote at
23RISCO
abrir
Referência
CVE-2018-6395
SQL Injection exists in the Visual Calendar 3.1.3 component for Joomla! via the id parameter in a view=load action.
23RISCO
abrir
Referência
CVE-2018-6398
SQL Injection exists in the CP Event Calendar 3.0.1 component for Joomla! via the id parameter in a task=load action.
23RISCO
abrir
Referência
CVE-2023-0904
SourceCodester Employee Task Management System task-details.php sql injection
33RISCO
abrir
ReferênciaVexDay Proof
OPT Max 1.2.0 - 'CRM_inc' Remote File Inclusion
CVE-2006-4239webappsphp
PHP remote file inclusion vulnerability in include/urights.php in Outreach Project Tool (OPT) Max 1.2.6 and earlier allo
23RISCO
abrir
Referência
CVE-2021-36520
A SQL injection vulnerability in I-Tech Trainsmart r1044 exists via a evaluation/assign-evaluation?id= URI.
41RISCO
abrir
ReferênciaVexDay Proof
phpFullAnnu 5.1 - 'repmod' Remote File Inclusion
CVE-2006-4644webappsphp
PHP remote file inclusion vulnerability in modules/home.module.php in phpFullAnnu 5.1 and earlier allows remote attacker
23RISCO
abrir
Referência
CVE-2018-8584
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A
23RISCO
abrir
ReferênciaVexDay Proof
Star FTP Server 1.10 - 'RETR' Remote Denial of Service
CVE-2006-6643doswindows
Fightersoft Multimedia Star FTP server 1.10 allows remote attackers to cause a denial of service (crash) via multiple RE
23RISCO
abrir
Referência
CVE-2023-0902
SourceCodester Simple Food Ordering System process_order.php cross site scripting
28RISCO
abrir
ReferênciaVexDay Proof
photokron 1.7 - Remote Database Disclosure
CVE-2008-0297webappsphp
PhotoKorn allows remote attackers to obtain database credentials via a direct request to update/update3.php, which inclu
23RISCO
abrir
ReferênciaVexDay Proof
BolinOS 4.6.1 - Local File Inclusion / Cross-Site Scripting
CVE-2008-1557webappsphp
BolinOS 4.6.1 allows remote attackers to obtain sensitive information via a direct request to system/actionspages/_b/con
23RISCO
abrir
ReferênciaVexDay Proof
FREEze Greetings 1.0 - Remote Password Retrieve
CVE-2008-5218webappsphp
ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote a
23RISCO
abrir
ReferênciaVexDay Proof
Noticeware E-mail Server 5.1.2.2 - 'POP3' Denial of Service
CVE-2008-6185doswindows
NoticeWare Email Server NG 5.1.2.2 allows remote attackers to cause a denial of service (crash) via multiple POP3 reques
23RISCO
abrir
Referência
CVE-2010-2340
SQL injection vulnerability in members.php in Arab Portal 2.2, when magic_quotes_gpc is disabled, allows remote attacker
23RISCO
abrir
Referência
CVE-2010-2505
Soft SaschArt SasCAM Webcam Server 2.6.5, 2.7, and earlier allows remote attackers to cause a denial of service (crash)
23RISCO
abrir
Referência
CVE-2010-2342
SQL injection vulnerability in onlinenotebookmanager.asp in DMXReady Online Notebook Manager 1.0 allows remote attackers
23RISCO
abrir
Referência
CVE-2019-1364
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle o
23RISCO
abrir
Referência
CVE-2025-34121
Idera Up.Time ≤ 7.2 post2file.php Arbitrary File Upload RCE
63RISCO
abrir
Referência
CVE-2025-34121
Idera Up.Time ≤ 7.2 post2file.php Arbitrary File Upload RCE
63RISCO
abrir
Referência
CVE-2025-34121
Idera Up.Time ≤ 7.2 post2file.php Arbitrary File Upload RCE
63RISCO
abrir
Referência
CVE-2009-20007
Talkative IRC v0.4.4.16 Response Buffer Overflow
63RISCO
abrir
Referência
CVE-2009-20007
Talkative IRC v0.4.4.16 Response Buffer Overflow
63RISCO
abrir
Referência
CVE-2009-3366
Directory traversal vulnerability in navigation.php in An image gallery 1.0 allows remote attackers to list arbitrary di
23RISCO
abrir
ReferênciaVexDay Proof
WoW Roster 1.5.1 - 'subdir' Remote File Inclusion
CVE-2006-3998webappsphp
PHP remote file inclusion vulnerability in conf.php in WoWRoster (aka World of Warcraft Roster) 1.5.1 and earlier allows
23RISCO
abrir
Referência
CVE-2011-2944
SQL injection vulnerability in login.php in MegaLab The Uploader before 2.0.5 allows remote attackers to execute arbitra
23RISCO
abrir
Referência
CVE-2011-2944
SQL injection vulnerability in login.php in MegaLab The Uploader before 2.0.5 allows remote attackers to execute arbitra
23RISCO
abrir
anteriorpágina 219 / 719próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.