Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.313exploits catalogados
34.834CVEs com exploração pública
24.695testados em laboratório
21.796 exploits
Referência
CVE-2021-43339
In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file
23RISCO
abrir
Referência
CVE-2009-3066
Multiple cross-site scripting (XSS) vulnerabilities in PropertyWatchScript.com Property Watch 2.0 allow remote attackers
23RISCO
abrir
Referência
CVE-2009-4985
SQL injection vulnerability in browse.php in Accessories Me PHP Affiliate Script 1.4 allows remote attackers to execute
23RISCO
abrir
Referência
CVE-2010-4231
Directory traversal vulnerability in the web-based administration interface on the Camtron CMNC-200 Full HD IP Camera an
43RISCO
abrir
Referência
CVE-2020-9467
Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function.
28RISCO
abrir
Referência
CVE-2017-17876
Biometric Shift Employee Management System 3.0 allows remote attackers to bypass intended file-read restrictions via a u
23RISCO
abrir
Referência
CVE-2020-14461
Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI.
23RISCO
abrir
Referência
CVE-2022-26521
Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable
23RISCO
abrir
Referência
CVE-2016-10043
An issue was discovered in Radisys MRF Web Panel (SWMS) 9.0.1. The MSM_MACRO_NAME POST parameter in /swms/ms.cgi was dis
23RISCO
abrir
ReferênciaVexDay Proof
Simple PHP Blog 0.4.7.1 - Remote Command Execution
CVE-2006-1243webappsphp
Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers
23RISCO
abrir
Referência
CVE-2012-1010
Unrestricted file upload vulnerability in actions.php in the AllWebMenus plugin before 1.1.8 for WordPress allows remote
23RISCO
abrir
Referência
CVE-2022-4063
InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE
63RISCO
abrir
Referência
CVE-2026-10812
zilliztech GPTCache Cache Key pre.py BufferedReader.peek weak hash
28RISCO
abrir
ReferênciaVexDay Proof
Fundanemt 2.2.0 - 'spellcheck.php' Remote Code Execution
CVE-2007-2935webappsphp
core/spellcheck/spellcheck.php in Fundanemt before 2.2.0.1 allows remote attackers to execute arbitrary commands via she
23RISCO
abrir
Referência
CVE-2014-0372
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
23RISCO
abrir
Referência
CVE-2012-4878
Absolute path traversal vulnerability in controlcenter.php in FlatnuX CMS 2011 08.09.2 allows remote administrators to r
38RISCO
abrir
Referência
CVE-2020-8655
CVE-2020-8655HIGHsob ataque
An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability
98RISCO
abrir
Referência
CVE-2014-4643
Multiple heap-based buffer overflows in the client in Core FTP LE 2.2 build 1798 allow remote FTP servers to cause a den
23RISCO
abrir
Referência
CVE-2020-8655
CVE-2020-8655HIGHsob ataque
An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability
98RISCO
abrir
Referência
CVE-2018-18759
Modbus Slave 7.0.0 in modbus tools has a Buffer Overflow.
23RISCO
abrir
Referência
CVE-2018-18759
Modbus Slave 7.0.0 in modbus tools has a Buffer Overflow.
23RISCO
abrir
Referência
CVE-2014-10079
In Vembu StoreGrid 4.4.x, the front page of the server web interface leaks the private IP address in the "ipaddress" hid
23RISCO
abrir
Referência
CVE-2014-10079
In Vembu StoreGrid 4.4.x, the front page of the server web interface leaks the private IP address in the "ipaddress" hid
23RISCO
abrir
Referência
CVE-2019-10969
Moxa EDR 810, all versions 5.1 and prior, allows an authenticated attacker to abuse the ping feature to execute unauthor
28RISCO
abrir
Referência
CVE-2018-10751
A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Ex
23RISCO
abrir
Referência
CVE-2021-45425
Reflected Cross Site Scripting (XSS) in SAFARI Montage versions 8.3 and 8.5 allows remote attackers to execute JavaScrip
23RISCO
abrir
Referência
CVE-2018-10751
A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Ex
23RISCO
abrir
Referência
CVE-2010-3847
elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not pro
38RISCO
abrir
Referência
CVE-2010-3847
elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not pro
38RISCO
abrir
Referência
CVE-2009-3119
SQL injection vulnerability in screen.php in the Download System mSF (dsmsf) module for PHP-Fusion allows remote attacke
23RISCO
abrir
anteriorpágina 301 / 727próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.