Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.533exploits catalogados
35.607CVEs com exploração pública
24.695testados em laboratório
22.407 exploits
Referência
CVE-2026-15230
YayPricing < 3.5.7 - Subscriber+ Pricing Configuration Modification and Coupon Code Disclosure
41RISCO
abrir
Referência
CVE-2026-14553
Zportals < 6.3.4 - Subscriber+ Arbitrary File Upload
41RISCO
abrir
Referência
CVE-2025-15677
GeoDirectory < 2.8.110 - Editor+ Stored XSS via Place Categories
28RISCO
abrir
Referência
CVE-2026-16993
DHL for WooCommerce < 4.0.1 - Unauthenticated Shipping Label Disclosure via Unprotected Uploads Directory
28RISCO
abrir
Referência
CVE-2026-16981
DHL for WooCommerce < 4.0.1 - Unauthenticated Shipping Label Download via IDOR
33RISCO
abrir
Referência
CVE-2026-16968
GeoDirectory < 2.8.168 - Contributor+ User Email Disclosure via geodir_json_search_users
33RISCO
abrir
Referência
CVE-2015-4027
The AcuWVSSchedulerv10 service in Acunetix Web Vulnerability Scanner (WVS) before 10 build 20151125 allows local users t
23RISCO
abrir
ReferênciaVexDay Proof
SNMPc 7.0.18 - Remote Denial of Service (Metasploit)
CVE-2007-3098doswindows
The SNMPc Server (crserv.exe) process in Castle Rock Computing SNMPc before 7.0.19 allows remote attackers to cause a de
23RISCO
abrir
ReferênciaVexDay Proof
X.Org xorg-x11-xfs 1.0.2-3.1 - Local Race Condition
CVE-2007-3103locallinux
The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local users to change the
23RISCO
abrir
ReferênciaVexDay Proof
Kravchuk letter script 1.0 - 'scdir' Remote File Inclusion
CVE-2007-3118webappsphp
Multiple PHP remote file inclusion vulnerabilities in Kravchuk letter (K-letter) 1.0 allow remote attackers to execute a
23RISCO
abrir
ReferênciaVexDay Proof
Kartli Alisveris Sistemi 1.0 - SQL Injection
CVE-2007-3119webappsasp
SQL injection vulnerability in news.asp in Kartli Alisveris Sistemi (aka Free-PayPal-Shopping-Cart) 1.0 allows remote at
23RISCO
abrir
ReferênciaVexDay Proof
Quick.Cart 2.2 - Local/Remote File Inclusion / Remote Code Execution
CVE-2007-3138webappsphp
Directory traversal vulnerability in index.php in Open Solution Quick.Cart 2.2 and earlier allows remote attackers to in
23RISCO
abrir
Referência
CVE-2017-17611
Doctor Search Script 1.0 has SQL Injection via the /list city parameter.
23RISCO
abrir
ReferênciaVexDay Proof
Quick.Cart 2.2 - Local/Remote File Inclusion / Remote Code Execution
CVE-2007-3139webappsphp
config/general.php in Quick.Cart 2.2 and earlier uses a default username and password, which allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
Yahoo! Messenger Webcam 8.1 - ActiveX Remote Buffer Overflow (2)
CVE-2007-3148remotewindows
Buffer overflow in the Yahoo! Webcam Viewer ActiveX control in ywcvwr.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows
28RISCO
abrir
ReferênciaVexDay Proof
XOOPS Module XT-Conteudo - 'spaw_root' Remote File Inclusion
CVE-2007-3221webappsphp
PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows
35RISCO
abrir
ReferênciaVexDay Proof
PHP::HTML 0.6.4 - 'PHPhtml.php' Remote File Inclusion
CVE-2007-3230webappsphp
PHP remote file inclusion vulnerability in phphtml.php in Idan Sofer PHP::HTML 0.6.4 allows remote attackers to execute
35RISCO
abrir
Referência
CVE-2017-17618
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
23RISCO
abrir
ReferênciaVexDay Proof
Fuzzylime Forum 1.0 - 'low.php?topic' SQL Injection
CVE-2007-3235webappsphp
Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum 1.0 allows remote attackers to inject arbitrary w
23RISCO
abrir
Referência
CVE-2017-17618
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
23RISCO
abrir
ReferênciaVexDay Proof
XOOPS Module horoscope 2.0 - Remote File Inclusion
CVE-2007-3236webappsphp
PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to e
45RISCO
abrir
ReferênciaVexDay Proof
xoops module tinycontent 1.5 - Remote File Inclusion
CVE-2007-3237webappsphp
PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the TinyContent 1.5 module for XOOPS all
35RISCO
abrir
Referência
CVE-2017-17619
Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.
23RISCO
abrir
ReferênciaVexDay Proof
PHPMyInventory 2.8 - 'global.inc.php' Remote File Inclusion
CVE-2007-3270webappsphp
PHP remote file inclusion vulnerability in Includes/global.inc.php in phpMyInventory 2.8 allows remote attackers to exec
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Office - MSODataSourceControl COM-object Buffer Overflow (PoC)
CVE-2007-3282doswindows
Buffer overflow in the Microsoft Office MSODataSourceControl ActiveX object allows remote attackers to cause a denial of
35RISCO
abrir
Referência
CVE-2017-17620
Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter.
23RISCO
abrir
ReferênciaVexDay Proof
XOOPS Module wiwimod 0.4 - Remote File Inclusion
CVE-2007-3289webappsphp
PHP remote file inclusion vulnerability in spaw/spaw_control.class.php in the WiwiMod 0.4 module for XOOPS allows remote
28RISCO
abrir
ReferênciaVexDay Proof
LiveCMS 3.4 - 'categoria.php?cid' SQL Injection
CVE-2007-3290webappsphp
categoria.php in LiveCMS 3.4 and earlier allows remote attackers to obtain sensitive information via a ' (quote) charact
23RISCO
abrir
ReferênciaVexDay Proof
LiveCMS 3.4 - 'categoria.php?cid' SQL Injection
CVE-2007-3292webappsphp
Unrestricted file upload vulnerability in LiveCMS 3.4 and earlier allows remote attackers to upload and execute arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
MiniBill 1.2.5 - 'run_billing.php' Remote File Inclusion
CVE-2007-3306webappsphp
PHP remote file inclusion vulnerability in crontab/run_billing.php in MiniBill 1.2.5 allows remote attackers to execute
35RISCO
abrir
anteriorpágina 532 / 747próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.