Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.231exploits catalogados
35.420CVEs com exploração pública
24.695testados em laboratório
22.266 exploits
Referência
CVE-2016-7255
CVE-2016-7255HIGHsob ataque
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RISCO
abrir
Referência
CVE-2016-7255
CVE-2016-7255HIGHsob ataque
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RISCO
abrir
Referência
CVE-2016-8810
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RISCO
abrir
Referência
CVE-2021-44529
CVE-2021-44529CRITICALsob ataqueransomware
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execut
100RISCO
abrir
Referência
CVE-2021-44529
CVE-2021-44529CRITICALsob ataqueransomware
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execut
100RISCO
abrir
Referência
CVE-2021-44596
Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an
28RISCO
abrir
Referência
Online Magazine Management System 1.0 - SQLi Authentication Bypass
CVE-2021-44653webappsphp
Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability. The Admin panel auth
23RISCO
abrir
Referência
Online Pre-owned/Used Car Showroom Management System 1.0 - SQLi Authentication Bypass
CVE-2021-44655webappsphp
Online Pre-owned/Used Car Showroom Management System 1.0 contains a SQL injection authentication bypass vulnerability. A
23RISCO
abrir
Referência
CVE-2021-44848
In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication reques
43RISCO
abrir
Referência
CVE-2021-45092
Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection vi
50RISCO
abrir
Referência
CVE-2021-46379
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrust
43RISCO
abrir
Referência
CVE-2021-46398
A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor use
23RISCO
abrir
Referência
CVE-2022-23513
Pi-Hole/AdminLTE vulnerable due to improper access control in queryads endpoint
45RISCO
abrir
Referência
CVE-2022-23642
Code Injection in Sourcegraph
78RISCO
abrir
Referência
CVE-2022-23642
Code Injection in Sourcegraph
78RISCO
abrir
Referência
CVE-2022-24112
CVE-2022-24112CRITICALsob ataque
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RISCO
abrir
Referência
CVE-2022-24637
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RISCO
abrir
Referência
CVE-2022-24637
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RISCO
abrir
Referência
CVE-2022-26134
CVE-2022-26134CRITICALsob ataqueransomware
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
Referência
CVE-2017-15968
MyBuilder Clone 1.0 allows SQL Injection via the phpsqlsearch_genxml.php subcategory parameter.
23RISCO
abrir
Referência
CVE-2017-16542
Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name param
23RISCO
abrir
Referência
CVE-2017-16777
If HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.3 is installed but VMware Fusion is not, a loc
23RISCO
abrir
Referência
CVE-2017-16836
Arris TG1682G devices with Comcast TG1682_2.0s7_PRODse 10.0.59.SIP.PC20.CT software allow Unauthenticated Stored XSS via
23RISCO
abrir
Referência
CVE-2017-17571
FS Foodpanda Clone 1.0 has SQL Injection via the /food keywords parameter.
23RISCO
abrir
Referência
CVE-2022-30519
XSS in signing form in Reprise Software RLM License Administration v14.2BL4 allows remote attacker to inject arbitrary c
33RISCO
abrir
Referência
CVE-2022-30525
CVE-2022-30525CRITICALsob ataque
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RISCO
abrir
Referência
CVE-2022-30781
Gitea before 1.16.7 does not escape git fetch remote.
60RISCO
abrir
Referência
CVE-2022-30781
Gitea before 1.16.7 does not escape git fetch remote.
60RISCO
abrir
Referência
CVE-2022-31188
Server-Side Request Forgery Vulnerability in Computer Vision Annotation Tool (CVAT)
53RISCO
abrir
Referência
CVE-2022-32272
OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5
23RISCO
abrir
anteriorpágina 452 / 743próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.