Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
24.460 exploits
Exploit-DB
Chamilo LMS 1.11.14 - Account Takeover
CVE-2021-37391webappsphp02 fev 2022
A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator
23RISCO
abrir
Exploit-DB
WordPress Plugin Product Slider for WooCommerce 1.13.21 - Cross Site Scripting (XSS)
CVE-2021-24300webappsphp02 fev 2022
PickPlugins Product Slider for WooCommerce < 1.13.22 - Reflected Cross-Site Scripting (XSS)
43RISCO
abrir
Exploit-DB
Mozilla Firefox 67 - Array.pop JIT Type Confusion
CVE-2019-11707HIGHsob ataquelocalwindows02 fev 2022
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow
83RISCO
abrir
Exploit-DB
PHP Unit 4.8.28 - Remote Code Execution (RCE) (Unauthenticated)
CVE-2017-9841CRITICALsob ataquewebappsphp02 fev 2022
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISCO
abrir
Exploit-DB
Moodle 3.11.4 - SQL Injection
CVE-2022-0332webappsphp02 fev 2022
A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web serv
35RISCO
abrir
Exploit-DB
Wordpress Plugin Download Monitor WordPress V 4.4.4 - SQL Injection (Authenticated)
CVE-2021-24786HIGHwebappsphp02 fev 2022
Download Monitor < 4.4.5 - Admin+ SQL Injection
61RISCO
abrir
Exploit-DB
Wordpress Plugin 404 to 301 2.0.2 - SQL-Injection (Authenticated)
CVE-2015-9323webappsphp02 fev 2022
The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection.
50RISCO
abrir
Exploit-DB
WordPress Plugin Learnpress 4.1.4.1 - Arbitrary Image Renaming
CVE-2022-0377webappsphp02 fev 2022
LearnPress < 4.1.5 - Arbitrary Image Renaming
23RISCO
abrir
Exploit-DB
WordPress Plugin Contact Form Check Tester 1.0.2 - Broken Access Control
CVE-2021-24247webappsphp02 fev 2022
Contact Form Check Tester <= 1.0.2 - Broken Access Control to Cross-Site Scripting (XSS)
23RISCO
abrir
Exploit-DB
WordPress Plugin Domain Check 1.0.16 - Reflected Cross-Site Scripting (XSS) (Authenticated)
CVE-2021-24926webappsphp02 fev 2022
Domain Check < 1.0.17 - Reflected Cross-Site Scripting
43RISCO
abrir
Exploit-DB
WordPress Plugin Post Grid 2.1.1 - Cross Site Scripting (XSS)
CVE-2021-24488webappsphp02 fev 2022
Post Grid < 2.1.8 - Reflected Cross-Site Scripting (XSS)
43RISCO
abrir
Exploit-DB
WordPress Plugin Modern Events Calendar V 6.1 - SQL Injection (Unauthenticated)
CVE-2021-24946webappsphp27 jan 2022
Modern Events Calendar < 6.1.5 - Unauthenticated Blind SQL Injection
60RISCO
abrir
Exploit-DB
PolicyKit-1 0.105-31 - Privilege Escalation
CVE-2021-4034HIGHsob ataqueransomwarelocallinux27 jan 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISCO
abrir
Exploit-DB
WordPress Plugin Mortgage Calculators WP 1.52 - Stored Cross-Site Scripting (XSS) (Authenticated)
CVE-2021-24904webappsphp27 jan 2022
Mortgage Calculators WP < 1.56 - Admin+ Stored Cross-Site Scripting
23RISCO
abrir
Exploit-DB
WordPress Plugin RegistrationMagic V 5.0.1.5 - SQL Injection (Authenticated)
CVE-2021-24862webappsphp27 jan 2022
RegistrationMagic < 5.0.1.6 - Admin+ SQL Injection
60RISCO
abrir
Exploit-DB
Oracle WebLogic Server 14.1.1.0.0 - Local File Inclusion
CVE-2022-21371HIGHremotewindows27 jan 2022
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported ve
78RISCO
abrir
Exploit-DB
PHPIPAM 1.4.4 - SQLi (Authenticated)
CVE-2022-23046webappsphp25 jan 2022
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a su
28RISCO
abrir
Exploit-DB
Creston Web Interface 1.0.0.2159 - Credential Disclosure
CVE-2022-23178webappshardware18 jan 2022
An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI
60RISCO
abrir
Exploit-DB
WordPress Plugin Frontend Uploader 1.3.2 - Stored Cross Site Scripting (XSS) (Unauthenticated)
CVE-2021-24563webappsphp12 jan 2022
Frontend Uploader <= 1.3.2 - Unauthenticated Stored Cross-Site Scripting
28RISCO
abrir
Exploit-DB
VUPlayer 2.49 - '.wax' Local Buffer Overflow (DEP Bypass)
CVE-2009-0182localwindows10 jan 2022
Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in
50RISCO
abrir
Exploit-DB
Open-AudIT Community 4.2.0 - Cross-Site Scripting (XSS) (Authenticated)
CVE-2021-44916webappsphp10 jan 2022
Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability. If a bad
23RISCO
abrir
Exploit-DB
CoreFTP Server build 725 - Directory Traversal (Authenticated)
CVE-2022-22836remotewindows10 jan 2022
CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP
23RISCO
abrir
Exploit-DB
Nettmp NNT 5.1 - SQLi Authentication Bypass
CVE-2021-45814webappsphp05 jan 2022
Nettmp NNT 5.1 is affected by a SQL injection vulnerability. An attacker can bypass authentication and access the panel
23RISCO
abrir
Exploit-DB
SAFARI Montage 8.5 - Reflected Cross Site Scripting (XSS)
CVE-2021-45425webappsphp05 jan 2022
Reflected Cross Site Scripting (XSS) in SAFARI Montage versions 8.3 and 8.5 allows remote attackers to execute JavaScrip
23RISCO
abrir
Exploit-DB
WordPress Plugin WP Visitor Statistics 4.7 - SQL Injection
CVE-2021-24750webappsphp05 jan 2022
WP Visitor Statistics (Real Time Traffic) < 4.8 - Subscriber+ SQL Injection
50RISCO
abrir
Exploit-DB
ConnectWise Control 19.2.24707 - Username Enumeration
CVE-2019-16516remotemultiple05 jan 2022
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a user enumer
28RISCO
abrir
Exploit-DB
WordPress Plugin The True Ranker 2.2.2 - Arbitrary File Read (Unauthenticated)
CVE-2021-39312HIGHwebappsphp05 jan 2022
True Ranker <= 2.2.2 Directory Traversal/Arbitrary File Read
78RISCO
abrir
Exploit-DB
Gerapy 0.9.7 - Remote Code Execution (RCE) (Authenticated)
CVE-2021-43857CRITICALremotepython05 jan 2022
Gerapy may contain remote code execution vulnerability
60RISCO
abrir
Exploit-DB
Automox Agent 32 - Local Privilege Escalation
CVE-2021-43326localwindows05 jan 2022
Automox Agent before 32 on Windows incorrectly sets permissions on a temporary directory.
23RISCO
abrir
Exploit-DB
WBCE CMS 1.5.1 - Admin Password Reset
CVE-2021-3817CRITICALwebappsphp20 dez 2021
SQL Injection in wbce/wbce_cms
60RISCO
abrir
anteriorpágina 32 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.