Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.652exploits catalogados
34.545CVEs com exploração pública
24.695testados em laboratório
21.581 exploits
Referência
CVE-2023-4112
PHP Jabbers Shuttle Booking Software index.php cross site scripting
48RISCO
abrir
Referência
CVE-2018-12981
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerabilit
23RISCO
abrir
Referência
CVE-2014-9097
Multiple SQL injection vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly
23RISCO
abrir
Referência
CVE-2017-6098
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/camp
23RISCO
abrir
ReferênciaVexDay Proof
Crafty Syntax Image Gallery 3.1g - Remote Code Execution
CVE-2006-1667webappsphp
SQL injection vulnerability in slides.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gal
23RISCO
abrir
Referência
CVE-2009-2361
SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arb
23RISCO
abrir
Referência
CVE-2018-16517
asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a deni
23RISCO
abrir
Referência
CVE-2018-16517
asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a deni
23RISCO
abrir
ReferênciaVexDay Proof
VRNews 1.1.1 - 'admin.php' Remote Security Bypass
CVE-2007-3611webappsphp
admin.php in VRNews 1.1.1, and possibly other 1.x versions, does not require authentication, which allows remote attacke
23RISCO
abrir
Referência
CVE-2018-8817
Wampserver before 3.1.3 has CSRF in add_vhost.php.
23RISCO
abrir
Referência
CVE-2008-1247
The web interface on the Linksys WRT54g router with firmware 1.00.9 does not require credentials when invoking scripts,
23RISCO
abrir
ReferênciaVexDay Proof
Macrovision FlexNet - 'isusweb.dll' DownloadAndExecute Method
CVE-2008-4586remotewindows
Insecure method vulnerability in the MVSNCLientWebAgent61.WebAgent.1 ActiveX control (isusweb.dll 6.1.100.61372) in Macr
23RISCO
abrir
Referência
CVE-2010-1176
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash)
23RISCO
abrir
Referência
CVE-2018-4121
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud b
28RISCO
abrir
Referência
CVE-2019-19031
Easy XML Editor through v1.7.8 is affected by: XML External Entity Injection. The impact is: Arbitrary File Read and DoS
23RISCO
abrir
Referência
CVE-2019-7652
TheHive Project UnshortenLink analyzer before 1.1, included in Cortex-Analyzers before 1.15.2, has SSRF. To exploit the
23RISCO
abrir
Referência
CVE-2025-14709
Shiguangwu sgwbox N3 WIRELESSCFGGET http_eshell_server buffer overflow
48RISCO
abrir
Referência
CVE-2011-0961
Cross-site scripting (XSS) vulnerability in cwhp/device.center.do in the Help servlet in Cisco CiscoWorks Common Service
23RISCO
abrir
ReferênciaVexDay Proof
runawaysoft haber portal 1.0 - 'tr' Multiple Vulnerabilities
CVE-2007-2753webappsasp
RunawaySoft Haber portal 1.0 stores sensitive information under the web root with insufficient access control, which all
23RISCO
abrir
Referência
CVE-2015-1368
Multiple cross-site scripting (XSS) vulnerabilities in Ansible Tower (aka Ansible UI) before 2.0.5 allow remote attacker
23RISCO
abrir
Referência
CVE-2015-1368
Multiple cross-site scripting (XSS) vulnerabilities in Ansible Tower (aka Ansible UI) before 2.0.5 allow remote attacker
23RISCO
abrir
Referência
CVE-2024-3191
MailCleaner Email os command injection
48RISCO
abrir
Referência
CVE-2018-5759
jsparse.c in Artifex MuJS through 1.0.2 does not properly maintain the AST depth for binary expressions, which allows re
23RISCO
abrir
Referência
CVE-2016-4793
The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP head
23RISCO
abrir
Referência
CVE-2010-2549
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2 and Server 2008 Gold and
23RISCO
abrir
Referência
CVE-2016-1803
CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RISCO
abrir
Referência
CVE-2016-1803
CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RISCO
abrir
Referência
CVE-2019-15092
The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in
23RISCO
abrir
Referência
CVE-2019-25699
Newsbull Haber Script 1.0.0 Authenticated SQL Injection via search parameter
41RISCO
abrir
Referência
CVE-2026-21876 PoC: WAF charset bypass (Flask, ASP.NET and Spring Boot stands)
OWASP CRS has multipart bypass using multiple content-type parts
53RISCO
abrir
anteriorpágina 230 / 720próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.