Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
76.894exploits catalogados
35.202CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.443Referência 22.103GitHub PoC 14.055VulnCheck XDB 8.571Nuclei 4.250Metasploit 3.472✓ só verificadosrecentespopularesrisco
21.899 exploits
Referência
CVE-2018-18774
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows XSS via the admin/index.php module parameter.
23RISCO
abrir ↗Referência✓ VexDay Proof
Omegaboard 1.0beta4 - 'functions.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/functions.php in Omegaboard 1.0beta4 and earlier allows remote attac
23RISCO
abrir ↗Referência✓ VexDay Proof
Htaccess Passwort Generator 1.1 - 'ht_pfad' Remote File Inclusion
PHP remote file inclusion vulnerability in generate.php in VirtualSystem Htaccess Passwort Generator 1.1 allows remote a
23RISCO
abrir ↗Referência
CVE-2014-100017
Cross-site scripting (XSS) vulnerability in canned_opr.php in PhpOnlineChat 3.0 allows remote attackers to inject arbitr
23RISCO
abrir ↗Referência
CVE-2014-100017
Cross-site scripting (XSS) vulnerability in canned_opr.php in PhpOnlineChat 3.0 allows remote attackers to inject arbitr
23RISCO
abrir ↗Referência
CVE-2021-40868
In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS.
38RISCO
abrir ↗Referência
CVE-2021-40868
In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS.
38RISCO
abrir ↗Referência
CVE-2018-11511
The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability
43RISCO
abrir ↗Referência
CVE-2017-9978
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response
23RISCO
abrir ↗Referência
CVE-2017-9978
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response
23RISCO
abrir ↗Referência
CVE-2016-1821
IOAudioFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a
23RISCO
abrir ↗Referência
CVE-2009-3968
Multiple SQL injection vulnerabilities in ITechBids 8.0 allow remote attackers to execute arbitrary SQL commands via the
23RISCO
abrir ↗Referência
CVE-2009-3969
Stack-based buffer overflow in Faslo Player 7.0 allows remote attackers to cause a denial of service (application crash)
23RISCO
abrir ↗Referência✓ VexDay Proof
IrayoBlog 0.2.4 - '/inc/irayofuncs.php' Remote File Inclusion
PHP remote file inclusion vulnerability in inc/irayofuncs.php in IrayoBlog alpha-0.2.4 allows remote attackers to execut
23RISCO
abrir ↗Referência✓ VexDay Proof
Nessus Vulnerability Scanner 3.0.6 - ActiveX Command Execution
Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attac
28RISCO
abrir ↗Referência✓ VexDay Proof
Scripteen Free Image Hosting Script 1.2 - 'cookie' Pass Grabber
Scripteen Free Image Hosting Script 1.2 and 1.2.1 allows remote attackers to bypass authentication and gain administrati
23RISCO
abrir ↗Referência✓ VexDay Proof
Debian OpenSSH - (Authenticated) Remote SELinux Privilege Escalation
sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain ac
23RISCO
abrir ↗Referência
CVE-2015-4010
Cross-site request forgery (CSRF) vulnerability in the Encrypted Contact Form plugin before 1.1 for WordPress allows rem
23RISCO
abrir ↗Referência
CVE-2015-7767
Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code or cause a denial of
23RISCO
abrir ↗Referência
CVE-2015-7767
Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code or cause a denial of
23RISCO
abrir ↗Referência
CVE-2017-11322
The chroothole_client executable in UCOPIA Wireless Appliance before 5.1.8 allows remote attackers to gain root privileg
23RISCO
abrir ↗Referência
CVE-2014-9260
The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users
28RISCO
abrir ↗Referência
CVE-2026-6118
AstrBotDevs AstrBot MCP Endpoint tools.py add_mcp_server command injection
48RISCO
abrir ↗Referência✓ VexDay Proof
Achievo 1.3.2 - 'FCKeditor' Arbitrary File Upload
Unrestricted file upload in the mcpuk file editor (atk/attributes/fck/editor/filemanager/browser/mcpuk/connectors/php/co
23RISCO
abrir ↗Referência
CVE-2012-0981
Directory traversal vulnerability in phpShowtime 2.0 allows remote attackers to list arbitrary directories and image fil
43RISCO
abrir ↗Referência
CVE-2019-0543
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka "Microsoft W
71RISCO
abrir ↗Referência
CVE-2018-5725
MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Change, as demonstrated by the port number of t
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.