Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.836exploits catalogados
35.811CVEs com exploração pública
24.695testados em laboratório
22.572 exploits
ReferênciaVexDay Proof
e107 Plugin BLOG Engine 2.2 - 'rid' Blind SQL Injection
CVE-2008-2455webappsphp
SQL injection vulnerability in comment.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to exe
23RISCO
abrir
Referência
CVE-2015-1577
Directory traversal vulnerability in u5admin/deletefile.php in u5CMS before 3.9.4 allows remote attackers to write to ar
23RISCO
abrir
Referência
CVE-2010-5060
SQL injection vulnerability in Nus.php in NUs Newssystem 1.02 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Referência
CVE-2010-5060
SQL injection vulnerability in Nus.php in NUs Newssystem 1.02 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Referência
CVE-2010-5193
Stack-based buffer overflow in the TIFMergeMultiFiles function in the SCRIBBLE.ScribbleCtrl.1 ActiveX control (ImageView
50RISCO
abrir
Referência
CVE-2009-4932
Stack-based buffer overflow in 1by1 1.67 (aka 1.6.7.0) allows remote attackers to cause a denial of service (application
23RISCO
abrir
Referência
CVE-2016-3694
Multiple SQL injection vulnerabilities in modified eCommerce Shopsoftware 2.0.0.0 revision 9678, when the easybill-modul
23RISCO
abrir
Referência
CVE-2020-15364
The Nexos theme through 1.7 for WordPress allows top-map/?search_location= reflected XSS.
23RISCO
abrir
Referência
CVE-2010-2102
Buffer overflow in Webby Webserver 1.01 allows remote attackers to execute arbitrary code via a long HTTP GET request.
23RISCO
abrir
Referência
CVE-2009-2275
Directory traversal vulnerability in frontend/x3/stats/lastvisit.html in cPanel allows remote attackers to read arbitrar
23RISCO
abrir
Referência
CVE-2013-4862
MiCasaVerde VeraLite with firmware 1.5.408 does not properly restrict access, which allows remote authenticated users to
23RISCO
abrir
Referência
CVE-2013-4862
MiCasaVerde VeraLite with firmware 1.5.408 does not properly restrict access, which allows remote authenticated users to
23RISCO
abrir
Referência
CVE-2015-2365
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server
23RISCO
abrir
Referência
CVE-2009-2784
Multiple directory traversal vulnerabilities in dit.cms 1.3, when register_globals is enabled, allow remote attackers to
23RISCO
abrir
Referência
CVE-2008-6495
Cross-site scripting (XSS) vulnerability in index.php in Fritz Berger yet another php photo album - next generation (yap
23RISCO
abrir
ReferênciaVexDay Proof
MiniBill 20061010 - 'menu_builder.php' File Inclusion
CVE-2006-5620webappsphp
PHP remote file inclusion vulnerability in include/menu_builder.php in MiniBILL 2006-10-10 (1.2.3) and earlier, when reg
23RISCO
abrir
ReferênciaVexDay Proof
PHP Upload Center 2.0 - 'activate.php' File Inclusion
CVE-2006-6360webappsphp
PHP remote file inclusion vulnerability in activate.php in PHP Upload Center 2.0 allows remote attackers to execute arbi
23RISCO
abrir
ReferênciaVexDay Proof
CandyPress eCommerce suite 4.1.1.26 - Multiple Vulnerabilities
CVE-2008-0547webappsasp
Cross-site scripting (XSS) vulnerability in admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and probably ear
23RISCO
abrir
Referência
CVE-2018-25126
TVT NVMS-9000 Hard-coded API Credentials & Command Injection
48RISCO
abrir
Referência
CVE-2018-25126
TVT NVMS-9000 Hard-coded API Credentials & Command Injection
48RISCO
abrir
Referência
CVE-2017-15974
tPanel 2009 allows SQL injection for Authentication Bypass via 'or 1=1 or ''=' to login.php.
23RISCO
abrir
Referência
CVE-2017-15974
tPanel 2009 allows SQL injection for Authentication Bypass via 'or 1=1 or ''=' to login.php.
23RISCO
abrir
Referência
CVE-2019-17624
"" In X.Org X Server 1.20.4, there is a stack-based buffer overflow in the function XQueryKeymap. For example, by sendin
23RISCO
abrir
Referência
CVE-2018-0968
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISCO
abrir
Referência
Authenticated low-privileged RCE in Coolify via unsanitized shell commands in the Git Repository field.
Coolify Git Repository Field Command Injection in Project Deployment Workflow
48RISCO
abrir
ReferênciaVexDay Proof
Pixie CMS - Cross-Site Scripting / SQL Injection
CVE-2009-1067webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Pixie CMS 1.01a allows remote attackers to inject arbitrary web
23RISCO
abrir
Referência
CVE-2022-39285
Stored Cross-Site Scripting Vulnerability In File Parameter in zoneminder
41RISCO
abrir
Referência
CVE-2015-1028
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2730B router (rev C1) with firmware GE_1.01 allow remo
23RISCO
abrir
Referência
CVE-2026-4567
Tenda A15 UploadCfg stack-based overflow
48RISCO
abrir
Referência
CVE-2022-3481
WooCommerce Dropshipping < 4.4 - Unauthenticated SQLi
63RISCO
abrir
anteriorpágina 621 / 753próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.