Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.058exploits catalogados
35.300CVEs com exploração pública
24.695testados em laboratório
22.175 exploits
Referência
CVE-2009-4800
Directory traversal vulnerability in Sysax Multi Server 4.3 and 4.5 allows remote authenticated users to delete arbitrar
23RISCO
abrir
Referência
CVE-2017-0128
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
28RISCO
abrir
Referência
CVE-2017-0143
CVE-2017-0143HIGHsob ataqueransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Referência
CVE-2017-0143
CVE-2017-0143HIGHsob ataqueransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Referência
CVE-2017-0143
CVE-2017-0143HIGHsob ataqueransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Referência
CVE-2021-28420
A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via alerts.php and th
23RISCO
abrir
Referência
CVE-2023-7311
BYTEVALUE Intelligent Flow Control Router Command Injection
48RISCO
abrir
Referência
CVE-2018-11502
An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display t
23RISCO
abrir
Referência
CVE-2014-5288
A CSRF Vulnerability exists in Kemp Load Master before 7.0-18a via unspecified vectors in administrative pages.
23RISCO
abrir
Referência
CVE-2014-5288
A CSRF Vulnerability exists in Kemp Load Master before 7.0-18a via unspecified vectors in administrative pages.
23RISCO
abrir
Referência
CVE-2013-7316
Cross-site scripting (XSS) vulnerability in GitLab 6.0 and other versions before 6.5.0 allows remote attackers to inject
23RISCO
abrir
Referência
CVE-2022-34668
NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage ma
48RISCO
abrir
Referência
CVE-2013-5094
Cross-site scripting (XSS) vulnerability in index.exp in McAfee Vulnerability Manager 7.5 allows remote attackers to inj
23RISCO
abrir
Referência
CVE-2009-4543
PHP remote file inclusion vulnerability in index.php in Cromosoft Technologies Facil Helpdesk 2.3 Lite allows remote att
23RISCO
abrir
Referência
CVE-2009-3426
PHP remote file inclusion vulnerability in includes/file_manager/special.php in MaxCMS 3.11.20b allows remote attackers
23RISCO
abrir
Referência
CVE-2018-10752
The Tagregator plugin 0.6 for WordPress has stored XSS via the title field in an Add New action.
23RISCO
abrir
Referência
CVE-2010-1300
SQL injection vulnerability in index.php in Yamamah (aka Dove Photo Album) 1.00 allows remote attackers to execute arbit
23RISCO
abrir
Referência
CVE-2010-1300
SQL injection vulnerability in index.php in Yamamah (aka Dove Photo Album) 1.00 allows remote attackers to execute arbit
23RISCO
abrir
Referência
CVE-2010-1300
SQL injection vulnerability in index.php in Yamamah (aka Dove Photo Album) 1.00 allows remote attackers to execute arbit
23RISCO
abrir
Referência
CVE-2010-1300
SQL injection vulnerability in index.php in Yamamah (aka Dove Photo Album) 1.00 allows remote attackers to execute arbit
23RISCO
abrir
ReferênciaVexDay Proof
Liquid-Silver CMS 0.1 - 'update' Local File Inclusion
CVE-2008-0459webappsphp
Directory traversal vulnerability in update/index.php in Liquid-Silver CMS 0.35, when magic_quotes_gpc is disabled, allo
23RISCO
abrir
Referência
CVE-2025-2621
D-Link DAP-1620 storage check_dws_cookie stack-based overflow
48RISCO
abrir
ReferênciaVexDay Proof
WR-Meeting 1.0 - 'msnum' Local File Disclosure
CVE-2008-2355webappsphp
Directory traversal vulnerability in index.php in WR-Meeting 1.0, when magic_quotes_gpc is disabled, allows remote attac
23RISCO
abrir
ReferênciaVexDay Proof
jsite 1.0 oe - SQL Injection / Local File Inclusion
CVE-2008-3192webappsphp
Directory traversal vulnerability in index.php in jSite 1.0 OE allows remote attackers to include and execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
TriO 2.1 - 'browse.php' SQL Injection
CVE-2008-3418webappsphp
SQL injection vulnerability in browse.php in TriO 2.1 and earlier allows remote attackers to execute arbitrary SQL comma
23RISCO
abrir
ReferênciaVexDay Proof
txtCMS 0.3 - 'index.php' Local File Inclusion
CVE-2008-5217webappsphp
Directory traversal vulnerability in index.php in txtCMS 0.3, when register_globals is enabled and magic_quotes_gpc is d
23RISCO
abrir
Referência
CVE-2021-30637
htmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php.
23RISCO
abrir
Referência
CVE-2017-16819
A stored cross-site scripting vulnerability in the Icon Time Systems RTC-1000 v2.5.7458 and earlier time clock allows re
23RISCO
abrir
Referência
CVE-2018-7355
All versions up to V1.0.0B05 of ZTE MF65 and all versions up to V1.0.0B02 of ZTE MF65M1 are impacted by cross-site scrip
23RISCO
abrir
Referência
CVE-2016-7391
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RISCO
abrir
anteriorpágina 407 / 740próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.