Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.589exploits catalogados
34.508CVEs com exploração pública
24.695testados em laboratório
21.554 exploits
Referência
CVE-2026-49491
Pixa Bank 2.0 SQL Injection via agence-ajax.php API
41RISCO
abrir
Referência
CVE-2018-18955
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RISCO
abrir
Referência
CVE-2026-5812
SourceCodester Pharmacy Product Management System POST Parameter add-sales.php logic error
33RISCO
abrir
ReferênciaVexDay Proof
Attachmax Dolphin 2.1.0 - Multiple Vulnerabilities
CVE-2008-4207webappsphp
Attachmax Dolphin 2.1.0 and earlier does not properly protect info.php in the main folder, which allows remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
webid 0.5.4 - Multiple Vulnerabilities
CVE-2008-7117webappsphp
eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) file
23RISCO
abrir
Referência
CVE-2013-1408
Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin before 2.2.1 for WordPress allow remote authenti
23RISCO
abrir
Referência
CVE-2019-2861
Vulnerability in the Oracle Hyperion Planning component of Oracle Hyperion (subcomponent: Security). The supported versi
23RISCO
abrir
Referência
CVE-2017-2480
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud b
23RISCO
abrir
Referência
CVE-2016-6663
Race condition in Oracle MySQL before 5.5.52, 5.6.x before 5.6.33, 5.7.x before 5.7.15, and 8.x before 8.0.1; MariaDB be
23RISCO
abrir
Referência
CVE-2023-31702
SQL injection in the View User Profile in MicroWorld eScan Management Console 14.0.1400.2281 allows remote attacker to d
41RISCO
abrir
ReferênciaVexDay Proof
Valdersoft Shopping Cart 3.0 - Remote Command Execution
CVE-2006-0099webappsphp
PHP remote file include vulnerability in (1) include/templates/categories/default.php and (2) certain other include/temp
23RISCO
abrir
Referência
CVE-2014-1204
SQL injection vulnerability in Tableau Server 8.0.x before 8.0.7 and 8.1.x before 8.1.2 allows remote authenticated user
23RISCO
abrir
Referência
CVE-2017-6978
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Accessibili
23RISCO
abrir
Referência
CVE-2018-11522
Yosoro 1.0.4 has stored XSS.
23RISCO
abrir
Referência
CVE-2018-11522
Yosoro 1.0.4 has stored XSS.
23RISCO
abrir
Referência
CVE-2018-14059
Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick,
23RISCO
abrir
Referência
CVE-2018-14059
Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick,
23RISCO
abrir
Referência
CVE-2009-4854
addons/import.php in TalkBack 2.3.14 allows remote attackers to execute arbitrary commands via the result parameter.
23RISCO
abrir
Referência
CVE-2009-4854
addons/import.php in TalkBack 2.3.14 allows remote attackers to execute arbitrary commands via the result parameter.
23RISCO
abrir
ReferênciaVexDay Proof
Achievo 1.1.0 - 'config_atkroot' Remote File Inclusion
CVE-2007-2736webappsphp
PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP c
23RISCO
abrir
ReferênciaVexDay Proof
Confixx Pro 3.3.1 - 'saveserver.php' Remote File Inclusion
CVE-2007-4009webappsphp
PHP remote file inclusion vulnerability in admin/business_inc/saveserver.php in SWSoft Confixx Pro 2.0.12 through 3.3.1
23RISCO
abrir
ReferênciaVexDay Proof
WebPortal CMS 0.6-beta - Remote Password Change
CVE-2008-0141webappsphp
actions.php in WebPortal CMS 0.6-beta generates predictable passwords containing only the time of day, which makes it ea
23RISCO
abrir
ReferênciaVexDay Proof
TurnkeyForms Web Hosting Directory - Multiple Vulnerabilities
CVE-2008-6939webappsphp
TurnkeyForms Web Hosting Directory allows remote attackers to bypass authentication and (1) gain administrative privileg
23RISCO
abrir
Referência
CVE-2012-2905
Artiphp CMS 5.5.0 Neo (r422) stores database backups with predictable names under the web root with insufficient access
23RISCO
abrir
Referência
CVE-2017-8912
CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code para
41RISCO
abrir
Referência
CVE-2018-6364
SQL Injection exists in Multilanguage Real Estate MLM Script through 3.0 via the /product-list.php srch parameter.
23RISCO
abrir
Referência
CVE-2018-6364
SQL Injection exists in Multilanguage Real Estate MLM Script through 3.0 via the /product-list.php srch parameter.
23RISCO
abrir
Referência
CVE-2009-4562
Cross-site scripting (XSS) vulnerability in zp-core/admin.php in Zenphoto 1.2.5 allows remote attackers to inject arbitr
23RISCO
abrir
Referência
CVE-2010-4901
Multiple cross-site scripting (XSS) vulnerabilities in char_map.php in MySource Matrix 3.28.3 allow remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
ExBB Italiano 0.2 - exbb[home_path] Remote File Inclusion
CVE-2006-4488webappsphp
PHP remote file inclusion vulnerability in modules/userstop/userstop.php in ExBB Italia 0.2 and earlier, when register_g
23RISCO
abrir
anteriorpágina 198 / 719próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.