Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.902exploits catalogados
34.597CVEs com exploração pública
24.695testados em laboratório
21.624 exploits
Referência
CVE-2010-1475
Directory traversal vulnerability in the Preventive & Reservation (com_preventive) component 1.0.5 for Joomla! allows re
38RISCO
abrir
Referência
CVE-2010-1475
Directory traversal vulnerability in the Preventive & Reservation (com_preventive) component 1.0.5 for Joomla! allows re
38RISCO
abrir
Referência
CVE-2010-1477
SQL injection vulnerability in the SermonSpeaker (com_sermonspeaker) component before 3.2.1 for Joomla! allows remote at
23RISCO
abrir
Referência
CVE-2000-1196
PSCOErrPage.htm in Netscape PublishingXpert 2.5 before SP2 allows remote attackers to read arbitrary files by specifying
23RISCO
abrir
Referência
CVE-2021-27885
usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.
23RISCO
abrir
Referência
CVE-2018-0749
The Microsoft Server Message Block (SMB) Server in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2
23RISCO
abrir
Referência
CVE-2010-1478
Directory traversal vulnerability in the Ternaria Informatica Jfeedback! (com_jfeedback) component 1.2 for Joomla! allow
38RISCO
abrir
Referência
CVE-2013-10060
Netgear Routers pppoe.cgi RCE
63RISCO
abrir
Referência
CVE-2013-10060
Netgear Routers pppoe.cgi RCE
63RISCO
abrir
Referência
CVE-2013-10060
Netgear Routers pppoe.cgi RCE
63RISCO
abrir
Referência
CVE-2013-10060
Netgear Routers pppoe.cgi RCE
63RISCO
abrir
Referência
CVE-2013-1409
Cross-site scripting (XSS) vulnerability in the CommentLuv plugin before 2.92.4 for WordPress allows remote attackers to
23RISCO
abrir
Referência
CVE-2020-8819
An issue was discovered in the CardGate Payments plugin through 3.1.15 for WooCommerce. Lack of origin authentication in
23RISCO
abrir
Referência
CVE-2015-4084
Cross-site scripting (XSS) vulnerability in the Free Counter plugin 1.1 for WordPress allows remote attackers to inject
23RISCO
abrir
Referência
CVE-2015-4084
Cross-site scripting (XSS) vulnerability in the Free Counter plugin 1.1 for WordPress allows remote attackers to inject
23RISCO
abrir
Referência
CVE-2023-24217
AgileBio Electronic Lab Notebook v4.234 was discovered to contain a local file inclusion vulnerability.
41RISCO
abrir
ReferênciaVexDay Proof
TR Forum 2.0 - SQL Injection / Bypass Security Restriction
CVE-2006-4584webappsphp
Tr Forum 2.0 allows remote attackers to bypass authentication and add an administrative account via the login and passwo
23RISCO
abrir
ReferênciaVexDay Proof
Alstrasoft Live Support 1.21 - Admin Credential Retrieve
CVE-2007-2775webappsphp
AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are m
23RISCO
abrir
ReferênciaVexDay Proof
WikkiTikkiTavi 1.11 - Arbitrary '.PHP' File Upload
CVE-2009-0602webappsphp
Unrestricted file upload vulnerability in upload.php in WikkiTikkiTavi 1.11 allows remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
Gigaset SE461 WiMAX Router - Remote Denial of Service
CVE-2009-1152doshardware
Siemens Gigaset SE461 WiMAX router 1.5-BL024.9.6401, and possibly other versions, allows remote attackers to cause a den
23RISCO
abrir
Referência
CVE-2020-15238
Local privilege escalation Blueman
41RISCO
abrir
Referência
CVE-2013-5218
Cross-site scripting (XSS) vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to inject
23RISCO
abrir
Referência
CVE-2012-3755
Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of s
28RISCO
abrir
Referência
CVE-2015-5784
runner in Install.framework in the Install Framework Legacy component in Apple OS X before 10.10.5 does not properly dro
23RISCO
abrir
Referência
CVE-2017-15223
Denial-of-service vulnerability in ArGoSoft Mini Mail Server 1.0.0.2 and earlier allows remote attackers to waste CPU re
23RISCO
abrir
Referência
CVE-2017-3630
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions t
38RISCO
abrir
Referência
CVE-2017-3630
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions t
38RISCO
abrir
Referência
CVE-2011-2938
Multiple cross-site scripting (XSS) vulnerabilities in filter_api.php in MantisBT before 1.2.7 allow remote attackers to
23RISCO
abrir
Referência
CVE-2014-3842
Multiple cross-site scripting (XSS) vulnerabilities in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allow
23RISCO
abrir
Referência
CVE-2014-3842
Multiple cross-site scripting (XSS) vulnerabilities in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allow
23RISCO
abrir
anteriorpágina 254 / 721próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.