Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.772exploits catalogados
35.760CVEs com exploração pública
24.695testados em laboratório
22.523 exploits
Referência
CVE-2017-12951
The gig::DimensionRegion::CreateVelocityTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a den
23RISCO
abrir
Referência
CVE-2015-3934
Multiple SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 allow remote attackers to execute arbitrary SQL commands vi
23RISCO
abrir
Referência
CVE-2024-53582
An issue found in the Copy and View functions in the File Manager component of OpenPanel v0.3.4 allows attackers to exec
41RISCO
abrir
Referência
CVE-2011-4671
SQL injection vulnerability in adrotate/adrotate-out.php in the AdRotate plugin 3.6.6, and other versions before 3.6.8,
23RISCO
abrir
Referência
CVE-2017-17110
Techno Portfolio Management Panel 1.0 allows an attacker to inject SQL commands via a single.php?id= request.
23RISCO
abrir
Referência
CVE-2023-27290
IBM Observability with Instana missing authentication
48RISCO
abrir
Referência
CVE-2015-7715
Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows
23RISCO
abrir
Referência
CVE-2015-7715
Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows
23RISCO
abrir
ReferênciaVexDay Proof
OWLLib 1.0 - 'OWLMemoryProperty.php' Remote File Inclusion
CVE-2006-6150webappsphp
PHP remote file inclusion vulnerability in memory/OWLMemoryProperty.php in OWLLib 1.0 allows remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
BrowseDialog Class - 'ccrpbds6.dll' Multiple Denial of Service Vulnerabilities
CVE-2007-1162doswindows
A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allo
23RISCO
abrir
Referência
CVE-2026-66007
Datasets Path Traversal via Unsanitized file_name Metadata
33RISCO
abrir
ReferênciaVexDay Proof
PHP-Nuke - 'iframe.php' Remote File Inclusion
CVE-2007-1626webappsphp
PHP remote file inclusion vulnerability in iframe.php in the iFrame Module for PHP-NUKE allows remote attackers to execu
23RISCO
abrir
ReferênciaVexDay Proof
Hot Links SQL-PHP 3 - 'report.php' Multiple Vulnerabilities
CVE-2008-4379webappsphp
Cross-site scripting (XSS) vulnerability in report.php in Mr. CGI Guy Hot Links SQL-PHP 3.0 and earlier allows remote at
23RISCO
abrir
Referência
CVE-2026-65917
CyberPanel IncBackups IDOR via Sequential Backup ID
41RISCO
abrir
Referência
CVE-2026-9577
Post Status Notifier Lite < 1.13.0 - Reflected XSS via mod Parameter
33RISCO
abrir
Referência
CVE-2012-0277
Heap-based buffer overflow in XnView before 1.99 allows remote attackers to cause a denial of service (application crash
23RISCO
abrir
Referência
CVE-2026-8986
Command Injection via Malicious OCPP Server
48RISCO
abrir
Referência
CVE-2026-8985
Unauthenticated Command Injection
48RISCO
abrir
Referência
CVE-2026-8984
Unauthenticated RCE
48RISCO
abrir
Referência
CVE-2026-8983
Backdoor Authentication Token
48RISCO
abrir
Referência
CVE-2026-16334
itsourcecode Hospital Management System prescriptionorder.php sql injection
33RISCO
abrir
Referência
CVE-2026-16332
D-Link DNS-320 multi_uploadify.php unrestricted upload
33RISCO
abrir
Referência
CVE-2026-13432
ThumbPress < 6.2.2 - Subscriber+ Plugin Deactivation
33RISCO
abrir
Referência
CVE-2026-13156
MailerSend - Official SMTP Integration < 1.0.8 - Settings Deletion and Plugin Deactivation via CSRF
33RISCO
abrir
Referência
CVE-2026-12972
PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Payment Metadata Tampering
33RISCO
abrir
Referência
CVE-2026-12898
All-in-One WP Migration and Backup < 7.106 - Unauthenticated Arbitrary-Location Log File Write via Path Traversal
33RISCO
abrir
Referência
CVE-2026-16220
code-projects Online Examination System account.php cross site scripting
33RISCO
abrir
Referência
CVE-2012-0393
The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which
35RISCO
abrir
Referência
CVE-2017-17595
Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter.
23RISCO
abrir
Referência
CVE-2012-0394
The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers
60RISCO
abrir
anteriorpágina 596 / 751próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.