Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.813exploits catalogados
35.788CVEs com exploração pública
24.695testados em laboratório
22.549 exploits
Referência
CVE-2013-6232
Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web
23RISCO
abrir
Referência
CVE-2022-41040
CVE-2022-41040HIGHsob ataqueransomware
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISCO
abrir
ReferênciaVexDay Proof
DB Top Sites 1.0 - 'index.php?u' Local File Inclusion
CVE-2009-2110webappsphp
Multiple directory traversal vulnerabilities in DB Top Sites 1.0, when magic_quotes_gpc is disabled, allow remote attack
23RISCO
abrir
Referência
CVE-2015-1479
SQL injection vulnerability in reports/CreateReportTable.jsp in ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 buil
23RISCO
abrir
Referência
CVE-2009-2123
Multiple SQL injection vulnerabilities in Elvin 1.2.0 allow remote attackers to execute arbitrary SQL commands via the (
23RISCO
abrir
Referência
CVE-2026-9434
Totolink A8000RU Web Management cstecgi.cgi setWiFiWpsCfg os command injection
48RISCO
abrir
Referência
CVE-2026-9431
Tenda F1202 PptpUserAdd fromPptpUserAdd stack-based overflow
41RISCO
abrir
Referência
CVE-2013-6987
Multiple directory traversal vulnerabilities in the FileBrowser components in Synology DiskStation Manager (DSM) before
28RISCO
abrir
Referência
CVE-2013-7025
Multiple cross-site scripting (XSS) vulnerabilities in ematStaticAlertTypes.jsp in the Alert Settings section in Dell So
23RISCO
abrir
Referência
CVE-2013-7186
Buffer overflow in Steinberg MyMp3PRO 5.0 (Build 5.1.0.21) allows remote attackers to execute arbitrary code via a long
28RISCO
abrir
Referência
CVE-2013-7186
Buffer overflow in Steinberg MyMp3PRO 5.0 (Build 5.1.0.21) allows remote attackers to execute arbitrary code via a long
28RISCO
abrir
Referência
CVE-2013-7186
Buffer overflow in Steinberg MyMp3PRO 5.0 (Build 5.1.0.21) allows remote attackers to execute arbitrary code via a long
28RISCO
abrir
ReferênciaVexDay Proof
OCS Inventory NG 1.02 - Remote File Disclosure
CVE-2009-2166webappsphp
Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to re
23RISCO
abrir
Referência
CVE-2021-3129
CVE-2021-3129CRITICALsob ataqueransomware
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
Referência
CVE-2021-3129
CVE-2021-3129CRITICALsob ataqueransomware
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir
Referência
CVE-2015-1489
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticat
43RISCO
abrir
ReferênciaVexDay Proof
vBulletin Radio and TV Player AddOn - HTML Injection
CVE-2009-2172webappsphp
Cross-site scripting (XSS) vulnerability in forum/radioandtv.php in the Radio and TV Player addon for vBulletin allows r
23RISCO
abrir
ReferênciaVexDay Proof
phpDatingClub 3.7 - SQL Injection / Cross-Site Scripting Injection
CVE-2009-2179webappsphp
SQL injection vulnerability in search.php in phpDatingClub 3.7 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Referência
CVE-2013-7409
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RISCO
abrir
Referência
CVE-2013-7409
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RISCO
abrir
Referência
CVE-2013-7409
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RISCO
abrir
Referência
CVE-2020-10189
CVE-2020-10189CRITICALsob ataque
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted d
100RISCO
abrir
Referência
CVE-2009-2309
SQL injection vulnerability in index.php in Codice CMS 2 allows remote attackers to execute arbitrary SQL commands via t
23RISCO
abrir
Referência
CVE-2009-2341
SQL injection vulnerability in albumdetail.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands vi
23RISCO
abrir
Referência
CVE-2026-7292
o2oa NodeAgent NodeAgent.java syncFile improper authorization
33RISCO
abrir
Referência
CVE-2026-7290
JeecgBoot loadDict Endpoint SqlInjectionUtil.java SqlInjectionUtil sql injection
33RISCO
abrir
Referência
CVE-2026-7289
D-Link DIR-825M formWanConfigSetup sub_414BA8 buffer overflow
41RISCO
abrir
Referência
CVE-2022-35405
CVE-2022-35405CRITICALsob ataque
Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code
100RISCO
abrir
Referência
CVE-2009-4785
SQL injection vulnerability in the Quick News (com_quicknews) component for Joomla! allows remote attackers to execute a
23RISCO
abrir
Referência
CVE-2026-7288
D-Link DIR-825M formVpnConfigSetup sub_4151FC buffer overflow
41RISCO
abrir
anteriorpágina 602 / 752próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.