Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.313exploits catalogados
34.834CVEs com exploração pública
24.695testados em laboratório
21.797 exploits
Referência
CVE-2024-0204
Authentication Bypass in GoAnywhere MFT
85RISCO
abrir
Referência
CVE-2012-5875
Firefly Media Server 1.0.0.1359 allows remote attackers to cause a denial of service (NULL pointer dereference) via a (1
28RISCO
abrir
Referência
CVE-2019-12962
LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header.
38RISCO
abrir
ReferênciaVexDay Proof
WordPress MU < 2.7 - 'HOST' HTTP Header Cross-Site Scripting
CVE-2009-1030webappsphp
Cross-site scripting (XSS) vulnerability in the choose_primary_blog function in wp-includes/wpmu-functions.php in WordPr
23RISCO
abrir
Referência
CVE-2017-11661
The _WM_SetupMidiEvent function in internal_midi.c:2318 in WildMIDI 0.4.2 can cause a denial of service (invalid memory
28RISCO
abrir
Referência
CVE-2013-3075
Multiple buffer overflows in ActUWzd.dll 1.0.0.1 in Mitsubishi MX Component 3, as distributed in Citect CitectFacilities
28RISCO
abrir
Referência
CVE-2012-0781
The tidy_diagnose function in PHP 5.3.8 might allow remote attackers to cause a denial of service (NULL pointer derefere
28RISCO
abrir
ReferênciaVexDay Proof
WinRemotePC Full+Lite 2008 r.2server - Denial of Service
CVE-2008-3269doswindows
WRPCServer.exe in WinSoftMagic WinRemotePC (WRPC) Lite 2008 and Full 2008 allows remote attackers to cause a denial of s
28RISCO
abrir
Referência
CVE-2018-19125
PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to delete an image directory.
28RISCO
abrir
Referência
CVE-2019-1674
Cisco Webex Meetings Desktop App and Cisco Webex Productivity Tools Update Service Command Injection Vulnerability
46RISCO
abrir
Referência
CVE-2017-20216
FLIR Thermal Camera PT-Series firmware version 8.0.0.64 Unauthenticated Remote Command Injection
53RISCO
abrir
Referência
CVE-2014-9349
Multiple cross-site scripting (XSS) vulnerabilities in admin/robots.lib.php in RobotStats 1.0 allow remote attackers to
23RISCO
abrir
Referência
CVE-2014-9349
Multiple cross-site scripting (XSS) vulnerabilities in admin/robots.lib.php in RobotStats 1.0 allow remote attackers to
23RISCO
abrir
Referência
CVE-2026-16064
Event Booking Manager for WooCommerce < 5.3.7 - Contributor+ Arbitrary Post Modification via mpwem_quick_edit_event
33RISCO
abrir
Referência
CVE-2010-1341
SQL injection vulnerability in index.php in Systemsoftware Community Black Forum allows remote attackers to execute arbi
23RISCO
abrir
Referência
CVE-2018-12520
An issue was discovered in ntopng 3.4 before 3.4.180617. The PRNG involved in the generation of session IDs is not seede
28RISCO
abrir
Referência
CVE-2012-0407
Integer overflow in the DPA_Utilities library in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote att
23RISCO
abrir
Referência
CVE-2015-5999
Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DIR-816L Wireless Router with firmware before 2
23RISCO
abrir
Referência
CVE-2015-5999
Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DIR-816L Wireless Router with firmware before 2
23RISCO
abrir
Referência
CVE-2026-16063
Event Booking Manager for WooCommerce < 5.3.7 - Author+ Stored XSS via Event Timeline Content
33RISCO
abrir
Referência
CVE-2026-16062
Event Booking Manager for WooCommerce < 5.3.7 - Contributor+ PHP Object Injection via Event Timeline and FAQ Content
33RISCO
abrir
Referência
CVE-2026-16292
Frontend File Manager Plugin <= 23.6 - File Metadata Update via CSRF
33RISCO
abrir
Referência
CVE-2026-16291
ProfileGrid < 5.9.9.8 - Subscriber+ Arbitrary Notification Deletion via IDOR
33RISCO
abrir
Referência
CVE-2026-16285
WooCommerce Product Attachment < 2.3.3 - Unauthenticated Arbitrary Media Download
41RISCO
abrir
Referência
CVE-2019-1010124
WebAppick WooCommerce Product Feed 2.2.18 and earlier is affected by: Cross Site Scripting (XSS). The impact is: XSS to
23RISCO
abrir
Referência
CVE-2026-16273
Narrative Publisher <= 1.0.7 - Contributor+ Stored XSS via narrative_post_script Post Meta
33RISCO
abrir
Referência
CVE-2018-17376
SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter
23RISCO
abrir
Referência
CVE-2018-17376
SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter
23RISCO
abrir
Referência
CVE-2018-17377
SQL Injection exists in the Questions 1.4.3 component for Joomla! via the term, userid, users, or groups parameter.
23RISCO
abrir
ReferênciaVexDay Proof
Lms 1.8.9 - Vala Remote File Inclusion
CVE-2007-1643webappsphp
Multiple PHP remote file inclusion vulnerabilities in LAN Management System (LMS) 1.8.9 Vala and earlier allow remote at
28RISCO
abrir
anteriorpágina 321 / 727próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.