Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.902exploits catalogados
34.597CVEs com exploração pública
24.695testados em laboratório
21.624 exploits
Referência
CVE-2019-17504
An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. A reflected Cross-site scripting (XSS) vuln
23RISCO
abrir
Referência
CVE-2021-26078
The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before
23RISCO
abrir
ReferênciaVexDay Proof
Mambo Component 'com_a6mambohelpdesk' 18RC1 - Remote File Inclusion
CVE-2006-3930webappsphp
PHP remote file inclusion vulnerability in admin.a6mambohelpdesk.php in a6mambohelpdesk Mambo Component 18RC1 and earlie
23RISCO
abrir
ReferênciaVexDay Proof
AllMyGuests 0.4.1 - 'cfg_serverpath' Remote File Inclusion
CVE-2006-4993webappsphp
Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.4.1 and earlier allow remote attackers to execute ar
23RISCO
abrir
Referência
CVE-2019-12460
Web Port 1.19.1 allows XSS via the /access/setup type parameter.
23RISCO
abrir
ReferênciaVexDay Proof
Webfwlog 0.92 - 'debug.php' Remote File Disclosure
CVE-2007-0585webappsphp
include/debug.php in Webfwlog 0.92 and earlier, when register_globals is enabled, allows remote attackers to obtain sour
23RISCO
abrir
ReferênciaVexDay Proof
plusphp url shortening software 1.6 - Remote File Inclusion
CVE-2008-2480webappsphp
PHP remote file inclusion vulnerability in plus.php in plusPHP Short URL Multi-User Script 1.6 allows remote attackers t
23RISCO
abrir
ReferênciaVexDay Proof
PHP recommend 1.3 - Authentication Bypass / Remote File Inclusion / Code Injection
CVE-2009-1779webappsphp
PHP remote file inclusion vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to
23RISCO
abrir
Referência
CVE-2014-0476
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute a
38RISCO
abrir
Referência
CVE-2014-0476
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute a
38RISCO
abrir
Referência
CVE-2017-9124
The quicktime_match_32 function in util.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (NU
23RISCO
abrir
Referência
CVE-2017-9123
The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of se
23RISCO
abrir
Referência
CVE-2012-5897
The (1) SimpleTree and (2) ReportTree classes in the ARDoc ActiveX control (ARDoc.dll) in Quest InTrust 10.4.0.853 and e
23RISCO
abrir
Referência
CVE-2016-6283
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitra
23RISCO
abrir
Referência
CVE-2016-6283
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitra
23RISCO
abrir
Referência
CVE-2025-34151
Shenzhen Aitemi M300 Wi-Fi Repeater PPPoE Password Command Injection
48RISCO
abrir
Referência
CVE-2018-1563
IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) is vulnerable to cross-site
33RISCO
abrir
Referência
CVE-2023-28489
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All ver
48RISCO
abrir
ReferênciaVexDay Proof
TSEP 0.942 - 'colorswitch.php' Remote File Inclusion
CVE-2006-4055webappsphp
Multiple PHP remote file inclusion vulnerabilities in Olaf Noehring The Search Engine Project (TSEP) 0.942 and earlier a
23RISCO
abrir
Referência
CVE-2011-10019
Spreecommerce < 0.60.2 Search Parameter RCE
63RISCO
abrir
Referência
CVE-2011-10019
Spreecommerce < 0.60.2 Search Parameter RCE
63RISCO
abrir
Referência
CVE-2012-2913
Multiple cross-site scripting (XSS) vulnerabilities in the Leaflet plugin 0.0.1 for WordPress allow remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
PHP-revista 1.1.2 - Remote File Inclusion / SQL Injection / Authentication Bypass / Cross-Site Scripting
CVE-2006-4605webappsphp
PHP remote file inclusion vulnerability in index.php in Longino Jacome php-Revista 1.1.2 allows remote attackers to exec
23RISCO
abrir
ReferênciaVexDay Proof
phpMyProfiler 0.9.6 - Remote File Inclusion
CVE-2006-5186webappsphp
PHP remote file inclusion vulnerability in functions.php in phpMyProfiler 0.9.6 and earlier, when register_globals is en
23RISCO
abrir
ReferênciaVexDay Proof
PHP-Stats 0.1.9.1b - 'PHP-stats-options.php' Command Execution
CVE-2006-7173webappsphp
Direct static code injection vulnerability in admin.php in PHP-Stats 0.1.9.1b and earlier allows remote attackers to exe
23RISCO
abrir
ReferênciaVexDay Proof
CrystalPlayer 1.98 - '.mls' Local Buffer Overflow
CVE-2007-4032localwindows
Buffer overflow in CrystalPlayer Pro 1.98 allows user-assisted remote attackers to execute arbitrary code via a long str
23RISCO
abrir
ReferênciaVexDay Proof
Flatnuke 3 - Remote Cookie Manipulation / Privilege Escalation
CVE-2007-5772webappsphp
Direct static code injection vulnerability in the download module in Flatnuke 3 allows remote authenticated administrato
23RISCO
abrir
Referência
CVE-2012-4344
Cross-site scripting (XSS) vulnerability in Ipswitch WhatsUp Gold 15.02 allows remote attackers to inject arbitrary web
23RISCO
abrir
ReferênciaVexDay Proof
Claroline E-Learning 1.75 - 'ldap.inc.php' Remote File Inclusion
CVE-2006-2284webappsphp
Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP co
23RISCO
abrir
Referência
CVE-2012-2156
Multiple cross-site scripting (XSS) vulnerabilities in Plume CMS 1.2.4 and earlier allow remote attackers to inject arbi
23RISCO
abrir
anteriorpágina 241 / 721próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.