Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
24.460 exploits
Exploit-DB
ThingsBoard 3.3.1 'description' - Stored Cross-Site Scripting (XSS)
CVE-2021-42751webappsmultiple09 ago 2022
A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrat
23RISCO
abrir
Exploit-DB
ThingsBoard 3.3.1 'name' - Stored Cross-Site Scripting (XSS)
CVE-2021-42750webappsmultiple09 ago 2022
A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrat
23RISCO
abrir
Exploit-DB
Prestashop blockwishlist module 2.1.0 - SQLi
CVE-2022-31101HIGHwebappsphp09 ago 2022
SQL Injection in prestashop/blockwishlist
61RISCO
abrir
Exploit-DB
uftpd 2.10 - Directory Traversal (Authenticated)
CVE-2020-20277remotelinux02 ago 2022
There are multiple unauthenticated directory traversal vulnerabilities in different FTP commands in uftpd FTP server ver
28RISCO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Duplicator 1.4.7 - Information Disclosure
CVE-2022-2552webappsphp01 ago 2022
Duplicator < 1.4.7.1 - Unauthenticated System Information Disclosure
43RISCO
abrir
Exploit-DB
WordPress Plugin Duplicator 1.4.6 - Unauthenticated Backup Download
CVE-2022-2551webappsphp01 ago 2022
Duplicator < 1.4.7 - Unauthenticated Backup Download
43RISCO
abrir
Exploit-DB
Wavlink WN533A8 - Cross-Site Scripting (XSS)
CVE-2022-34048webappshardware01 ago 2022
Wavlink WN533A8 M33A8.V5030.190716 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via th
38RISCO
abrir
Exploit-DB
Wavlink WN530HG4 - Password Disclosure
CVE-2022-34047webappshardware01 ago 2022
An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows attackers to obtain usernames and passwords via v
43RISCO
abrir
Exploit-DB
Easy Chat Server 3.1 - Remote Stack Buffer Overflow (SEH)
CVE-2004-2466remotewindows01 ago 2022
chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username
60RISCO
abrir
Exploit-DB
Wavlink WN533A8 - Password Disclosure
CVE-2022-34046webappshardware01 ago 2022
An access control issue in Wavlink WN533A8 M33A8.V5030.190716 allows attackers to obtain usernames and passwords via vie
43RISCO
abrir
Exploit-DB
rpc.py 0.6.0 - Remote Code Execution (RCE)
CVE-2022-35411remotepython29 jul 2022
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header i
35RISCO
abrir
Exploit-DB
Dingtian-DT-R002 3.1.276A - Authentication Bypass
CVE-2022-29593MEDIUMwebappshardware29 jul 2022
relay_cgi.cgi on Dingtian DT-R002 2CH relay devices with firmware 3.1.276A allows an attacker to replay HTTP post reques
38RISCO
abrir
Exploit-DB
Magnolia CMS 6.2.19 - Stored Cross-Site Scripting (XSS)
CVE-2022-33098webappsphp21 jul 2022
Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function.
35RISCO
abrir
Exploit-DB
IOTransfer 4.0 - Remote Code Execution (RCE)
CVE-2022-24562remotewindows21 jul 2022
In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary
35RISCO
abrir
Exploit-DB
OctoBot WebInterface 0.4.3 - Remote Code Execution (RCE)
CVE-2021-36711webappsmultiple21 jul 2022
WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled.
28RISCO
abrir
Exploit-DB
CodoForum v5.1 - Remote Code Execution (RCE)
CVE-2022-31854webappsphp21 jul 2022
Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin
50RISCO
abrir
Exploit-DB
Nginx 1.20.0 - Denial of Service (DOS)
CVE-2021-23017remotemultiple11 jul 2022
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t
35RISCO
abrir
Exploit-DB
WSO2 Management Console (Multiple Products) - Unauthenticated Reflected Cross-Site Scripting (XSS)
CVE-2022-29548MEDIUMwebappsphp27 jun 2022
A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0,
60RISCO
abrir
Exploit-DB
Marval MSM v14.19.0.12476 - Remote Code Execution (RCE) (Authenticated)
CVE-2022-31885remotewindows14 jun 2022
Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts.
35RISCO
abrir
Exploit-DB
Virtua Software Cobranca 12S - SQLi
CVE-2021-37589remotewindows14 jun 2022
Virtua Cobranca before 12R allows SQL Injection on the login page.
50RISCO
abrir
Exploit-DB
Pandora FMS v7.0NG.742 - Remote Code Execution (RCE) (Authenticated)
CVE-2020-5844webappsphp14 jun 2022
index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators t
35RISCO
abrir
Exploit-DB
SolarView Compact 6.00 - 'time_begin' Cross-Site Scripting (XSS)
CVE-2022-29299webappshardware14 jun 2022
20RISCO
abrir
Exploit-DB
Avantune Genialcloud ProJ 10 - Cross-Site Scripting (XSS)
CVE-2022-29296webappsmultiple14 jun 2022
A reflected cross-site scripting (XSS) vulnerability in the login portal of Avantune Genialcloud ProJ - 10 allows attack
23RISCO
abrir
Exploit-DB
SolarView Compact 6.00 - 'pow' Cross-Site Scripting (XSS)
CVE-2022-29301webappshardware14 jun 2022
20RISCO
abrir
Exploit-DB
Sourcegraph Gitserver 3.36.3 - Remote Code Execution (RCE)
CVE-2022-23642HIGHremotemultiple14 jun 2022
Code Injection in Sourcegraph
78RISCO
abrir
Exploit-DB
ChurchCRM 4.4.5 - SQLi
CVE-2022-31325webappsphp14 jun 2022
There is a SQL Injection vulnerability in ChurchCRM 4.4.5 via the 'PersonID' field in /churchcrm/WhyCameEditor.php.
23RISCO
abrir
Exploit-DB
Marval MSM v14.19.0.12476 - Cross-Site Request Forgery (CSRF)
CVE-2022-31886remotewindows14 jun 2022
Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF). An attacker can disable the 2FA by sending
23RISCO
abrir
Exploit-DB
Confluence Data Center 7.18.0 - Remote Code Execution (RCE)
CVE-2022-26134CRITICALsob ataqueransomwarewebappsjava10 jun 2022
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
Exploit-DB
Microweber CMS 1.2.15 - Account Takeover
CVE-2022-1631MEDIUMwebappsphp03 jun 2022
Users Account Pre-Takeover or Users Account Takeover. in microweber/microweber
33RISCO
abrir
Exploit-DB
SolarView Compact 6.00 - Directory Traversal
CVE-2022-29298remotehardware03 jun 2022
SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.
50RISCO
abrir
anteriorpágina 28 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.