Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
19.066 exploits
Exploit-DBVexDay Proof
Auto Dealer Management System v1.0 - SQL Injection on manage_user.php
CVE-2023-0915MEDIUMwebappsphp06 abr 2023
SourceCodester Auto Dealer Management System sql injection
33RISCO
abrir
Exploit-DBVexDay Proof
Best pos Management System v1.0 - Remote Code Execution (RCE) on File Upload
CVE-2023-0943MEDIUMwebappsphp06 abr 2023
SourceCodester Best POS Management System Image save_settings unrestricted upload
33RISCO
abrir
Exploit-DBVexDay Proof
Simple Task Managing System v1.0 - SQL Injection (Unauthenticated)
CVE-2022-40032CRITICALwebappsphp06 abr 2023
SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' paramet
68RISCO
abrir
Exploit-DBVexDay Proof
Music Gallery Site v1.0 - SQL Injection on page Master.php
CVE-2023-0962MEDIUMwebappsphp06 abr 2023
SourceCodester Music Gallery Site GET Request Master.php sql injection
33RISCO
abrir
Exploit-DBVexDay Proof
Employee Task Management System v1.0 - SQL Injection on edit-task.php
CVE-2023-0902LOWwebappsphp06 abr 2023
SourceCodester Simple Food Ordering System process_order.php cross site scripting
28RISCO
abrir
Exploit-DBVexDay Proof
Employee Task Management System v1.0 - SQL Injection on (task-details.php?task_id=?)
CVE-2023-0904MEDIUMwebappsphp06 abr 2023
SourceCodester Employee Task Management System task-details.php sql injection
33RISCO
abrir
Exploit-DBVexDay Proof
Auto Dealer Management System v1.0 - SQL Injection in sell_vehicle.php
CVE-2023-0913MEDIUMwebappsphp06 abr 2023
SourceCodester Auto Dealer Management System sql injection
33RISCO
abrir
Exploit-DBVexDay Proof
Auto Dealer Management System v1.0 - SQL Injection
CVE-2023-0912MEDIUMwebappsphp06 abr 2023
SourceCodester Auto Dealer Management System sql injection
33RISCO
abrir
Exploit-DBVexDay Proof
Responsive FileManager 9.9.5 - Remote Code Execution (RCE)
CVE-2022-46604HIGHwebappsphp05 abr 2023
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanis
41RISCO
abrir
Exploit-DBVexDay Proof
Answerdev 1.0.3 - Account Takeover
CVE-2023-0744CRITICALwebappsgo05 abr 2023
Improper Access Control in answerdev/answer
48RISCO
abrir
Exploit-DBVexDay Proof
BTCPay Server v1.7.4 - HTML Injection
CVE-2023-0493MEDIUMwebappsmultiple05 abr 2023
Improper Neutralization of Equivalent Special Elements in btcpayserver/btcpayserver
33RISCO
abrir
Exploit-DBVexDay Proof
Roxy WI v6.1.0.0 - Improper Authentication Control
CVE-2022-31125CRITICALwebappspython03 abr 2023
Authentication Bypass in Roxy-wi
53RISCO
abrir
Exploit-DBVexDay Proof
Art Gallery Management System Project v1.0 - SQL Injection (cid) Unauthenticated
CVE-2023-23162webappsphp03 abr 2023
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter
23RISCO
abrir
Exploit-DBVexDay Proof
Art Gallery Management System Project v1.0 - Reflected Cross-Site Scripting (XSS)
CVE-2023-23161webappsphp03 abr 2023
A reflected cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to e
38RISCO
abrir
Exploit-DBVexDay Proof
Art Gallery Management System Project v1.0 - SQL Injection (editid) authenticated
CVE-2023-23163webappsphp03 abr 2023
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parame
23RISCO
abrir
Exploit-DBVexDay Proof
WP-file-manager v6.9 - Unauthenticated Arbitrary File Upload leading to RCE
CVE-2020-25213CRITICALsob ataquewebappsphp03 abr 2023
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISCO
abrir
Exploit-DBVexDay Proof
Roxy WI v6.1.0.0 - Unauthenticated Remote Code Execution (RCE)
CVE-2022-31126CRITICALwebappspython03 abr 2023
Unauthenticated Remote Code Execution in Roxy-wi
75RISCO
abrir
Exploit-DBVexDay Proof
Paid Memberships Pro v2.9.8 (WordPress Plugin) - Unauthenticated SQL Injection
CVE-2023-23488CRITICALwebappsphp03 abr 2023
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerabilit
85RISCO
abrir
Exploit-DBVexDay Proof
Yahoo User Interface library (YUI2) TreeView v2.8.2 - Multiple Reflected Cross Site Scripting (XSS)
CVE-2022-48197webappsphp01 abr 2023
Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, Tree
38RISCO
abrir
Exploit-DBVexDay Proof
Apache 2.4.x - Buffer Overflow
CVE-2021-44790webappsmultiple01 abr 2023
Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier
45RISCO
abrir
Exploit-DBVexDay Proof
GitLab v15.3 - Remote Code Execution (RCE) (Authenticated)
CVE-2022-2884CRITICALwebappsruby01 abr 2023
A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3
70RISCO
abrir
Exploit-DBVexDay Proof
WP All Import v3.6.7 - Remote Code Execution (RCE) (Authenticated)
CVE-2022-1565HIGHwebappsphp29 mar 2023
Import any XML or CSV File to WordPress <= 3.6.7 - Admin+ Malicious File Upload
46RISCO
abrir
Exploit-DBVexDay Proof
BoxBilling<=4.22.1.5 - Remote Code Execution (RCE)
CVE-2022-3552HIGHwebappsphp28 mar 2023
Unrestricted Upload of File with Dangerous Type in boxbilling/boxbilling
53RISCO
abrir
Exploit-DBVexDay Proof
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
CVE-2022-39285HIGHwebappsphp27 mar 2023
Stored Cross-Site Scripting Vulnerability In File Parameter in zoneminder
41RISCO
abrir
Exploit-DBVexDay Proof
Grafana <=6.2.4 - HTML Injection
CVE-2019-13068webappstypescript27 mar 2023
public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the
35RISCO
abrir
Exploit-DBVexDay Proof
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
CVE-2022-39291MEDIUMwebappsphp27 mar 2023
Denial of service through logs in zoneminder
33RISCO
abrir
Exploit-DBVexDay Proof
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
CVE-2022-39290HIGHwebappsphp27 mar 2023
CSRF key bypass using HTTP methods in zoneminder
41RISCO
abrir
Exploit-DBVexDay Proof
Abantecart v1.3.2 - Authenticated Remote Code Execution
CVE-2022-26521webappsphp25 mar 2023
Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable
23RISCO
abrir
Exploit-DBVexDay Proof
Translatepress Multilinugal WordPress plugin < 2.3.3 - Authenticated SQL Injection
CVE-2022-3141webappsphp25 mar 2023
Translatepress Multilinugal < 2.3.3 - Admin+ SQLi
23RISCO
abrir
Exploit-DBVexDay Proof
NEX-Forms WordPress plugin < 7.9.7 - Authenticated SQLi
CVE-2022-3142webappsphp25 mar 2023
NEX-Forms < 7.9.7 - Authenticated SQLi
43RISCO
abrir

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.