Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.313exploits catalogados
34.834CVEs com exploração pública
24.695testados em laboratório
21.797 exploits
Referência
CVE-2017-9978
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response
23RISCO
abrir
Referência
CVE-2017-9978
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response
23RISCO
abrir
Referência
CVE-2016-1821
IOAudioFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a
23RISCO
abrir
ReferênciaVexDay Proof
Omegaboard 1.0beta4 - 'functions.php' Remote File Inclusion
CVE-2007-0683webappsphp
PHP remote file inclusion vulnerability in includes/functions.php in Omegaboard 1.0beta4 and earlier allows remote attac
23RISCO
abrir
ReferênciaVexDay Proof
Htaccess Passwort Generator 1.1 - 'ht_pfad' Remote File Inclusion
CVE-2007-1013webappsphp
PHP remote file inclusion vulnerability in generate.php in VirtualSystem Htaccess Passwort Generator 1.1 allows remote a
23RISCO
abrir
Referência
CVE-2009-3968
Multiple SQL injection vulnerabilities in ITechBids 8.0 allow remote attackers to execute arbitrary SQL commands via the
23RISCO
abrir
Referência
CVE-2009-3969
Stack-based buffer overflow in Faslo Player 7.0 allows remote attackers to cause a denial of service (application crash)
23RISCO
abrir
ReferênciaVexDay Proof
Nessus Vulnerability Scanner 3.0.6 - ActiveX Command Execution
CVE-2007-4061remotewindows
Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attac
28RISCO
abrir
Referência
CVE-2017-2473
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RISCO
abrir
Referência
CVE-2020-26829
SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary conne
48RISCO
abrir
Referência
CVE-2013-1937
Multiple cross-site scripting (XSS) vulnerabilities in tbl_gis_visualization.php in phpMyAdmin 3.5.x before 3.5.8 might
23RISCO
abrir
Referência
CVE-2019-10226
HTML Injection has been discovered in the v0.19.0 version of the Fat Free CRM product via an authenticated request to th
23RISCO
abrir
Referência
CVE-2019-10226
HTML Injection has been discovered in the v0.19.0 version of the Fat Free CRM product via an authenticated request to th
23RISCO
abrir
Referência
CVE-2011-4024
Cross-site scripting (XSS) vulnerability in ocsinventory in OCS Inventory NG 2.0.1 and earlier allows remote attackers t
23RISCO
abrir
Referência
CVE-2026-15260
Geo My WP < 4.5.5.3 - Subscriber+ Arbitrary Geolocation Record Modification and Deletion via IDOR
33RISCO
abrir
Referência
CVE-2018-6671
SB10240 - ePolicy Orchestrator (ePO) - Application Protection Bypass vulnerability
33RISCO
abrir
Referência
CVE-2014-3220
F5 BIG-IQ Cloud and Security 4.0.0 through 4.1.0 allows remote authenticated users to change the password of arbitrary u
28RISCO
abrir
Referência
CVE-2021-24405
Easy Cookie Policy <= 1.6.2 - Broken Access Control to Stored Cross-Site Scripting
28RISCO
abrir
ReferênciaVexDay Proof
Web Content System 2.7.1 - Remote File Inclusion
CVE-2007-1771webappsphp
PHP remote file inclusion vulnerability in manage/javascript/formjavascript.php in Ay System Solutions Web Content Syste
23RISCO
abrir
Referência
CVE-2014-125117
D-Link info.cgi POST Request Stack-Based Buffer Overflow RCE
63RISCO
abrir
Referência
CVE-2014-125117
D-Link info.cgi POST Request Stack-Based Buffer Overflow RCE
63RISCO
abrir
Referência
CVE-2014-125117
D-Link info.cgi POST Request Stack-Based Buffer Overflow RCE
63RISCO
abrir
Referência
CVE-2025-7097
Comodo Internet Security Premium Manifest File cis_update_x64.xml os command injection
48RISCO
abrir
Referência
CVE-2025-7097
Comodo Internet Security Premium Manifest File cis_update_x64.xml os command injection
48RISCO
abrir
Referência
CVE-2026-15231
TaxoPress < 3.51.0 - Contributor+ Private Post Disclosure via IDOR
28RISCO
abrir
Referência
CVE-2018-12052
SQL Injection exists in PHP Scripts Mall Schools Alert Management Script via the q Parameter in get_sec.php.
23RISCO
abrir
Referência
CVE-2026-14557
SoftMarket <= 1.0.0 - Unauthenticated Account Takeover via Email Verification Bypass
48RISCO
abrir
ReferênciaVexDay Proof
Adobe JRun 4 - 'logfile' (Authenticated) Directory Traversal
CVE-2009-1873remotewindows
Directory traversal vulnerability in logging/logviewer.jsp in the Management Console in Adobe JRun Application Server 4
23RISCO
abrir
Referência
CVE-2024-23749
KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insuffic
41RISCO
abrir
ReferênciaVexDay Proof
eFront 3.5.1 / build 2710 - Arbitrary File Upload
CVE-2008-7026webappsphp
Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote att
23RISCO
abrir
anteriorpágina 323 / 727próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.