Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
76.569exploits catalogados
34.981CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 21.899GitHub PoC 13.965VulnCheck XDB 8.542Nuclei 4.248Metasploit 3.472✓ só verificadosrecentespopularesrisco
21.899 exploits
Referência
CVE-2017-11330
The DivFixppCore::avi_header_fix function in DivFix++Core.cpp in DivFix++ v0.34 allows remote attackers to cause a denia
23RISCO
abrir ↗Referência
CVE-2008-7185
GNOME Rhythmbox 0.11.5 allows remote attackers to cause a denial of service (segmentation fault and crash) via a playlis
23RISCO
abrir ↗Referência
CVE-2021-37531
SAP NetWeaver Knowledge Management XML Forms versions - 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, contains an XSLT vulnerabili
48RISCO
abrir ↗Referência
CVE-2007-5982
Multiple cross-site scripting (XSS) vulnerabilities in X7 Chat 2.0.4, 2.0.5, and possibly other versions allow remote at
23RISCO
abrir ↗Referência
CVE-2015-1482
Ansible Tower (aka Ansible UI) before 2.0.5 allows remote attackers to bypass authentication and obtain sensitive inform
23RISCO
abrir ↗Referência
CVE-2015-1482
Ansible Tower (aka Ansible UI) before 2.0.5 allows remote attackers to bypass authentication and obtain sensitive inform
23RISCO
abrir ↗Referência
CVE-2010-3213
Cross-site request forgery (CSRF) vulnerability in Microsoft Outlook Web Access (owa/ev.owa) 2007 through SP2 allows rem
23RISCO
abrir ↗Referência
CVE-2014-6030
Multiple SQL injection vulnerabilities in ClassApps SelectSurvey.NET before 4.125.002 allow (1) remote attackers to exec
23RISCO
abrir ↗Referência
CVE-2009-4264
PHP remote file inclusion vulnerability in components/core/connect.php in AROUNDMe 1.1 and earlier, when register_global
23RISCO
abrir ↗Referência
CVE-2017-13260
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead
23RISCO
abrir ↗Referência
CVE-2012-5858
Samsung Kies Air 2.1.207051 and 2.1.210161 relies on the IP address for authentication, which allows remote man-in-the-m
23RISCO
abrir ↗Referência✓ VexDay Proof
mxBB Module calsnails 1.06 - 'mx_common.php' File Inclusion
PHP remote file inclusion vulnerability in includes/mx_common.php in the CalSnails Module for MxBB Portal 1.06 allows re
23RISCO
abrir ↗Referência✓ VexDay Proof
phpLinkat 0.1 - Insecure Cookie Handling / SQL Injection
phpLinkat 0.1 allows remote attackers to bypass authentication and access unspecified pages under admin/ by sending a lo
23RISCO
abrir ↗Referência
Core FTP 2.0 - 'XRMD' Denial of Service (PoC)
The server in Core FTP 2.0 build 653 on 32-bit platforms allows remote attackers to cause a denial of service (daemon cr
23RISCO
abrir ↗Referência✓ VexDay Proof
Camera Life 2.6.2b4 - Arbitrary File Upload
Unrestricted file upload vulnerability in the image upload component in Camera Life 2.6.2b4 allows remote authenticated
23RISCO
abrir ↗Referência✓ VexDay Proof
KwsPHP - 'Upload' Remote Code Execution
Directory traversal vulnerability in help.php in the eskuel module in KwsPHP 1.3.456, as available before 20080416, allo
23RISCO
abrir ↗Referência✓ VexDay Proof
zeeproperty 1.0 - Arbitrary File Upload / Cross-Site Scripting
Unrestricted file upload vulnerability in viewprofile.php in Zeeways ZEEPROPERTY 1.0 allows remote authenticated users t
23RISCO
abrir ↗Referência
CVE-2008-4601
Cross-site scripting (XSS) vulnerability in the login feature in Habari CMS 0.5.1 allows remote attackers to inject arbi
23RISCO
abrir ↗Referência
CVE-2018-19135
ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an
23RISCO
abrir ↗Referência
CVE-2018-7449
SEGGER FTP Server for Windows before 3.22a allows remote attackers to cause a denial of service (daemon crash) via an in
23RISCO
abrir ↗Referência✓ VexDay Proof
Max.Blog 1.0.6 - Arbitrary Delete Post
delete.php in Max.Blog 1.0.6 does not properly restrict access, which allows remote attackers to delete arbitrary blog p
23RISCO
abrir ↗Referência
CVE-2009-4431
PHP remote file inclusion vulnerability in cal_popup.php in the Anything Digital Development JCal Pro (aka com_jcalpro o
23RISCO
abrir ↗Referência
CVE-2009-4432
SQL injection vulnerability in index.php in CodeMight VideoCMS 3.1 allows remote attackers to execute arbitrary SQL comm
23RISCO
abrir ↗Referência✓ VexDay Proof
Mambo Component MMP 1.2 - Remote File Inclusion
PHP remote file inclusion vulnerability in help.mmp.php in the MMP Component (com_mmp) 1.2 and earlier for Mambo allows
23RISCO
abrir ↗Referência
CVE-2009-4432
SQL injection vulnerability in index.php in CodeMight VideoCMS 3.1 allows remote attackers to execute arbitrary SQL comm
23RISCO
abrir ↗Referência✓ VexDay Proof
AEP SmartGate 4.3b - 'GET' Arbitrary File Download
Directory traversal vulnerability in the SSL server in AEP Smartgate 4.3b allows remote attackers to download arbitrary
23RISCO
abrir ↗Referência✓ VexDay Proof
EasyNews PRO News Publishing 4.0 - Password Disclosure
STphp EasyNews PRO 4.0 stores sensitive information under the web root with insufficient access control, which allows re
23RISCO
abrir ↗Referência
CVE-2009-4433
Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot iSupport 1.8 and earlier allow remote attackers to injec
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.