Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.107exploits catalogados
34.679CVEs com exploração pública
24.695testados em laboratório
21.692 exploits
Referência
CVE-2017-6896
Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from
23RISCO
abrir
Referência
CVE-2018-20418
index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab.
23RISCO
abrir
Referência
CVE-2018-11091
An issue was discovered in MyBiz MyProcureNet 5.0.0. A malicious file can be uploaded to the webserver by an attacker. I
48RISCO
abrir
ReferênciaVexDay Proof
2WIRE Modems/Routers - 'CRLF' Denial of Service
CVE-2006-4523doshardware
The web-based management interface in 2Wire, Inc. HomePortal and OfficePortal Series modems and routers allows remote at
23RISCO
abrir
Referência
CVE-2014-9558
Multiple SQL injection vulnerabilities in SmartCMS v.2.
23RISCO
abrir
Referência
CVE-2015-7346
SQL injection vulnerability in ZCMS 1.1.
23RISCO
abrir
Referência
CVE-2015-7346
SQL injection vulnerability in ZCMS 1.1.
23RISCO
abrir
Referência
CVE-2014-9179
Cross-site scripting (XSS) vulnerability in the SupportEzzy Ticket System plugin 1.2.5 for WordPress allows remote authe
23RISCO
abrir
ReferênciaVexDay Proof
TCExam 4.0.011 - 'SessionUserLang' Shell Injection
CVE-2007-2430webappsphp
shared/code/tce_tmx.php in TCExam 4.0.011 and earlier allows remote attackers to create arbitrary PHP files in cache/ by
23RISCO
abrir
Referência
CVE-2008-7010
Skalfa Software SkaLinks Exchange Script 1.5 allows remote attackers to add new administrators and gain privileges via a
23RISCO
abrir
ReferênciaVexDay Proof
eIQnetworks ESA SEARCHREPORT - Remote Overflow (Metasploit)
CVE-2007-5699remotewindows
Stack-based buffer overflow in eIQNetworks Enterprise Security Analyzer (ESA) 2.5 allows remote attackers to execute arb
23RISCO
abrir
Referência
CVE-2023-7304
Ruijie RG-UAC nmc_sync.php Command Injection
48RISCO
abrir
ReferênciaVexDay Proof
snap - seccomp BBlacklist for TIOCSTI can be Circumvented
CVE-2019-7303MEDIUMdoslinux
Snapd seccomp filter TIOCSTI ioctl bypass
33RISCO
abrir
ReferênciaVexDay Proof
PolDoc CMS 0.96 - 'download_file.php' File Disclosure
CVE-2007-6400webappsphp
Directory traversal vulnerability in download_file.php in PolDoc CMS (aka PDDMS) 0.96 allows remote attackers to read ar
23RISCO
abrir
ReferênciaVexDay Proof
MX-System 2.7.3 - 'index.php' SQL Injection
CVE-2008-2477webappsphp
SQL injection vulnerability in index.php in MxBB (aka MX-System) Portal 2.7.3 allows remote attackers to execute arbitra
23RISCO
abrir
ReferênciaVexDay Proof
SkaLinks 1.5 - 'register.php' Arbitrary Add Editor
CVE-2008-7010webappsphp
Skalfa Software SkaLinks Exchange Script 1.5 allows remote attackers to add new administrators and gain privileges via a
23RISCO
abrir
Referência
CVE-2018-14888
inc/plugins/thankyoulike.php in the Eldenroot Thank You/Like plugin before 3.1.0 for MyBB allows XSS via a post or threa
23RISCO
abrir
Referência
CVE-2018-14888
inc/plugins/thankyoulike.php in the Eldenroot Thank You/Like plugin before 3.1.0 for MyBB allows XSS via a post or threa
23RISCO
abrir
Referência
CVE-2013-1604
Directory traversal vulnerability in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers
23RISCO
abrir
Referência
CVE-2018-5405
The Quest Kace K1000 Appliance is vulnerable to JavaScript injection.
23RISCO
abrir
Referência
CVE-2023-3848
mooSocial mooDating URL view cross site scripting
43RISCO
abrir
Referência
CVE-2017-8708
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RISCO
abrir
Referência
CVE-2019-16173
LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example,
23RISCO
abrir
Referência
CVE-2022-2841
CrowdStrike Falcon Uninstallation authorization
28RISCO
abrir
Referência
CVE-2014-2340
Cross-site request forgery (CSRF) vulnerability in the XCloner plugin before 3.1.1 for WordPress allows remote attackers
23RISCO
abrir
Referência
CVE-2015-7567
SQL injection vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary SQL commands via the "passw
23RISCO
abrir
Referência
CVE-2015-7567
SQL injection vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary SQL commands via the "passw
23RISCO
abrir
ReferênciaVexDay Proof
@lex Guestbook 4.0.2 - Remote Command Execution
CVE-2007-0202webappsphp
SQL injection vulnerability in index.php in @lex Guestbook 4.0.2 and earlier, when magic_quotes_gpc is disabled, allows
23RISCO
abrir
Referência
CVE-2021-21465
The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the b
48RISCO
abrir
Referência
CVE-2018-14840
uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it does not block .html file uploads (but does block, for exam
23RISCO
abrir
anteriorpágina 295 / 724próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.