Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.020exploits catalogados
35.276CVEs com exploração pública
24.695testados em laboratório
22.166 exploits
Referência
CVE-2018-6941
A /shell?cmd= CSRF issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remot
23RISCO
abrir
Referência
CVE-2018-6941
A /shell?cmd= CSRF issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remot
23RISCO
abrir
Referência
CVE-2007-0843
The ReadDirectoryChangesW API function on Microsoft Windows 2000, XP, Server 2003, and Vista does not check permissions
23RISCO
abrir
Referência
CVE-2016-0891
Multiple cross-site request forgery (CSRF) vulnerabilities in administrative pages in EMC ViPR SRM before 3.7 allow remo
23RISCO
abrir
Referência
CVE-2010-1315
Directory traversal vulnerability in weberpcustomer.php in the webERPcustomer (com_weberpcustomer) component 1.2.1 and 1
38RISCO
abrir
Referência
CVE-2019-12905
FileRun 2019.05.21 allows XSS via the filename to the ?module=fileman&section=do&page=up URI. This issue has been fixed
23RISCO
abrir
ReferênciaVexDay Proof
OpenDock Easy Blog 1.4 - 'doc_directory' File Inclusion
CVE-2006-5244webappsphp
Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Blog 1.4 and earlier, when register_globals is enabl
23RISCO
abrir
ReferênciaVexDay Proof
CPCommerce 1.1.0 - Cross-Site Scripting / Local File Inclusion
CVE-2008-1908webappsphp
Multiple directory traversal vulnerabilities in cpCommerce 1.1.0 allow remote attackers to include and execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
PHP Visit Counter 0.4 - 'datespan' SQL Injection
CVE-2008-2556webappsphp
SQL injection vulnerability in read.php in PHP Visit Counter 0.4 and earlier allows remote attackers to execute arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
Tizag Countdown Creator 3 - Insecure Upload
CVE-2008-6492webappsphp
Unrestricted file upload vulnerability in process.php in Tizag Countdown Creator 3 allows remote attackers to execute ar
23RISCO
abrir
ReferênciaVexDay Proof
ReVou Twitter Clone - Arbitrary File Upload
CVE-2008-6751webappsphp
Unrestricted file upload vulnerability in index.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging allows
23RISCO
abrir
Referência
CVE-2014-2995
Multiple cross-site scripting (XSS) vulnerabilities in twitget.php in the Twitget plugin before 3.3.3 for WordPress allo
23RISCO
abrir
Referência
CVE-2009-3716
Unrestricted file upload vulnerability in admin.php in MCshoutbox 1.1 allows remote authenticated users to execute arbit
23RISCO
abrir
Referência
CVE-2017-8840
Debug information disclosure exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before f
23RISCO
abrir
Referência
CVE-2012-0699
Multiple cross-site request forgery (CSRF) vulnerabilities in Family Connections CMS (aka FCMS) 2.9 and earlier allow re
23RISCO
abrir
Referência
CVE-2020-9038
Joplin through 1.0.184 allows Arbitrary File Read via XSS.
23RISCO
abrir
Referência
CVE-2023-37759
Incorrect access control in the User Registration page of Crypto Currency Tracker (CCT) before v9.5 allows unauthenticat
23RISCO
abrir
Referência
CVE-2021-33570
Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can
23RISCO
abrir
Referência
CVE-2021-33570
Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can
23RISCO
abrir
Referência
CVE-2010-1340
Directory traversal vulnerability in jresearch.php in the J!Research (com_jresearch) component for Joomla! allows remote
43RISCO
abrir
ReferênciaVexDay Proof
PhpHostBot 1.06 - 'svr_rootscript' Remote File Inclusion
CVE-2007-4231webappsphp
PHP remote file inclusion vulnerability in order/login.php in IDevSpot PhpHostBot 1.06 and earlier allows remote attacke
23RISCO
abrir
Referência
CVE-2008-2565
Multiple SQL injection vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
e107 module 123 flash chat 6.8.0 - Remote File Inclusion
CVE-2008-1989webappsphp
PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when register_g
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component Jotloader 1.2.1.a - Blind SQL Injection
CVE-2008-2564webappsphp
SQL injection vulnerability in the JotLoader (com_jotloader) component 1.2.1.a and earlier for Joomla! allows remote att
23RISCO
abrir
Referência
CVE-2010-0366
Multiple unrestricted file upload vulnerabilities in (1) register.php and (2) addvideo.php in BitScripts Bits Video Scri
23RISCO
abrir
Referência
CVE-2012-1059
Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Shop/Application/Cart/pages/main.php in OSCommerce O
23RISCO
abrir
Referência
CVE-2012-1059
Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Shop/Application/Cart/pages/main.php in OSCommerce O
23RISCO
abrir
Referência
CVE-2016-6253
mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or
38RISCO
abrir
Referência
CVE-2016-6253
mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or
38RISCO
abrir
Referência
CVE-2016-6253
mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or
38RISCO
abrir
anteriorpágina 386 / 739próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.