Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.313exploits catalogados
34.834CVEs com exploração pública
24.695testados em laboratório
21.797 exploits
ReferênciaVexDay Proof
Power Editor 2.0 - Remote File Disclosure / Edit
CVE-2008-2115webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attacke
23RISCO
abrir
Referência
CVE-2015-7986
The index server (hdbindexserver) in SAP HANA 1.00.095 allows remote attackers to execute arbitrary code or cause a deni
23RISCO
abrir
Referência
CVE-2015-1674
The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not pr
23RISCO
abrir
ReferênciaVexDay Proof
moziloCMS 1.11 - Local File Inclusion / Full Path Disclosure / Cross-Site Scripting
CVE-2009-1368webappsphp
Directory traversal vulnerability in index.php in moziloCMS 1.11 allows remote attackers to read arbitrary files via a .
23RISCO
abrir
Referência
CVE-2019-9881
The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on
43RISCO
abrir
Referência
CVE-2017-15359
In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory t
23RISCO
abrir
Referência
CVE-2017-2442
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issu
23RISCO
abrir
Referência
CVE-2017-2367
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISCO
abrir
Referência
CVE-2022-4047
Return Refund and Exchange For WooCommerce < 4.0.9 - Unauthenticated Arbitrary File Upload
48RISCO
abrir
Referência
CVE-2017-9259
The TDStretch::acceptNewOverlapLength function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote atta
23RISCO
abrir
Referência
CVE-2026-6142
tushar-2223 Hotel Management System roomdelete.php sql injection
33RISCO
abrir
ReferênciaVexDay Proof
Vote-Pro 4.0 - 'poll_frame.php?poll_id' Remote Code Execution
CVE-2007-0504webappsphp
Eval injection vulnerability in poll_frame.php in Vote! Pro 4.0, and possibly other scripts, allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
EDraw Office Viewer Component 5.2 - ActiveX Remote Buffer Overflow (PoC)
CVE-2007-4821doswindows
Buffer overflow in a certain ActiveX control in officeviewer.ocx 5.2.218.1 in EDraw Office Viewer Component 5.2 allows r
23RISCO
abrir
ReferênciaVexDay Proof
AvailScript Article Script - Arbitrary File Upload
CVE-2008-6900webappsphp
Unrestricted file upload vulnerability in "Add Pen/Author Name" feature in addpen.php in AvailScript Article Script allo
23RISCO
abrir
Referência
Webrun 3.6.0.42 - 'P_0' SQL Injection
CVE-2021-43650webappsmultiple
WebRun 3.6.0.42 is vulnerable to SQL Injection via the P_0 parameter used to set the username during the login process.
23RISCO
abrir
ReferênciaVexDay Proof
2DayBiz Business Community Script - Multiple Vulnerabilities
CVE-2009-1652webappsphp
admin/adminaddeditdetails.php in Business Community Script does not properly restrict access, which allows remote attack
23RISCO
abrir
Referência
CVE-2016-7454
CSRF vulnerability on Technicolor TC dpc3941T (formerly Cisco dpc3941T) devices with firmware dpc3941-P20-18-v303r204217
23RISCO
abrir
Referência
CVE-2012-2740
SQL injection vulnerability in public_html/lists/admin in phpList before 2.10.18 allows remote attackers to execute arbi
23RISCO
abrir
Referência
CVE-2010-2045
Directory traversal vulnerability in the Dione Form Wizard (aka FDione or com_dioneformwizard) component 1.0.2 for Jooml
38RISCO
abrir
Referência
CVE-2021-23017
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t
35RISCO
abrir
Referência
CVE-2009-2363
Stack-based buffer overflow in KUDRSOFT AudioPLUS 2.00.215 allows remote attackers to execute arbitrary code via a .pls
23RISCO
abrir
Referência
CVE-2009-2363
Stack-based buffer overflow in KUDRSOFT AudioPLUS 2.00.215 allows remote attackers to execute arbitrary code via a .pls
23RISCO
abrir
Referência
CVE-2014-5345
Cross-site scripting (XSS) vulnerability in upgrade.php in the Disqus Comment System plugin before 2.76 for WordPress al
23RISCO
abrir
Referência
CVE-2009-4367
The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and ear
23RISCO
abrir
Referência
CVE-2014-4968
The WebView class and use of the WebView.addJavascriptInterface method in the Boat Browser application 8.0 and 8.0.1 for
23RISCO
abrir
Referência
CVE-2020-15921
Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restric
28RISCO
abrir
ReferênciaVexDay Proof
Crob FTP Server 3.6.1 build 263 - 'LIST/NLST' Denial of Service
CVE-2006-6558doswindows
Crob FTP Server 3.6.1 b.263 allows remote attackers to cause a denial of service via a long series of "?A" sequences in
23RISCO
abrir
Referência
CVE-2025-2611
ICTBroadcast <= 7.4 Unauthenticated Session Cookie RCE
63RISCO
abrir
Referência
CVE-2025-2611
ICTBroadcast <= 7.4 Unauthenticated Session Cookie RCE
63RISCO
abrir
Referência
CVE-2012-2270
Open redirect vulnerability in index.php (aka the Login Page) in ownCloud before 3.0.3 allows remote attackers to redire
23RISCO
abrir
anteriorpágina 310 / 727próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.