Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.395exploits catalogados
34.906CVEs com exploração pública
24.695testados em laboratório
21.861 exploits
Referência
CVE-2021-27964
SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Con
50RISCO
abrir
Referência
CVE-2009-3597
Digitaldesign CMS 0.1 stores sensitive information under the web root with insufficient access control, which allows rem
23RISCO
abrir
Referência
CVE-2012-4362
hydra.exe in HP SAN/iQ before 9.5 on the HP Virtual SAN Appliance has a hardcoded password of L0CAlu53R for the global$a
23RISCO
abrir
Referência
CVE-2012-4362
hydra.exe in HP SAN/iQ before 9.5 on the HP Virtual SAN Appliance has a hardcoded password of L0CAlu53R for the global$a
23RISCO
abrir
ReferênciaVexDay Proof
TorrentTrader Classic 1.09 - Multiple Vulnerabilities
CVE-2009-2160webappsphp
TorrentTrader Classic 1.09 allows remote attackers to (1) obtain configuration information via a direct request to phpin
23RISCO
abrir
ReferênciaVexDay Proof
b1gbb 2.24.0 - SQL Injection / Cross-Site Scripting
CVE-2007-3590webappsphp
Cross-site scripting (XSS) vulnerability in visitenkarte.php in b1gBB 2.24.0 allows remote attackers to inject arbitrary
23RISCO
abrir
Referência
CVE-2023-38951
ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arb
48RISCO
abrir
Referência
CVE-2007-1524
Directory traversal vulnerability in themes/default/ in ZomPlog 3.7.6 and earlier allows remote attackers to include arb
23RISCO
abrir
Referência
CVE-2013-6233
Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web
23RISCO
abrir
Referência
CVE-2013-6233
Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web
23RISCO
abrir
Referência
CVE-2022-3982
Booking Calendar < 3.2.2 - Unauthenticated Arbitrary File Upload
63RISCO
abrir
Referência
CVE-2014-2045
Multiple cross-site scripting (XSS) vulnerabilities in the old and new interfaces in Viprinet Multichannel VPN Router 30
23RISCO
abrir
Referência
CVE-2014-2045
Multiple cross-site scripting (XSS) vulnerabilities in the old and new interfaces in Viprinet Multichannel VPN Router 30
23RISCO
abrir
Referência
CVE-2010-1528
PHP remote file inclusion vulnerability in include/template.php in Uiga Proxy, when register_globals is enabled, allows
23RISCO
abrir
Referência
CVE-2009-4823
Cross-site scripting (XSS) vulnerability in frontend/x3/files/fileop.html in cPanel 11.0 through 11.24.7 allows remote a
23RISCO
abrir
Referência
CVE-2019-10849
Computrols CBAS 18.0.0 allows unprotected Subversion (SVN) directory / source code disclosure.
23RISCO
abrir
Referência
CVE-2021-30149
Composr 10.0.36 allows upload and execution of PHP files.
28RISCO
abrir
Referência
CVE-2015-2291
CVE-2015-2291HIGHsob ataqueransomware
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows all
71RISCO
abrir
Referência
CVE-2017-5631
An issue was discovered in KMCIS CaseAware. Reflected cross site scripting is present in the user parameter (i.e., "usr"
38RISCO
abrir
Referência
CVE-2012-6534
Novell Sentinel Log Manager before 1.2.0.3 allows remote attackers to create data retention policies via a crafted text/
23RISCO
abrir
ReferênciaVexDay Proof
WMNews 0.2a - 'base_datapath' Remote File Inclusion
CVE-2006-3928webappsphp
PHP remote file inclusion vulnerability in index.php in WMNews 0.2a and earlier allows remote attackers to execute arbit
23RISCO
abrir
Referência
CVE-2020-1027
CVE-2020-1027HIGHsob ataque
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Window
71RISCO
abrir
ReferênciaVexDay Proof
Dyncms Release 6 - 'x_admindir' Remote File Inclusion
CVE-2006-4589webappsphp
PHP remote file inclusion vulnerability in 0_admin/modules/Wochenkarte/frontend/index.php in DynCMS 6 and earlier allows
23RISCO
abrir
Referência
CVE-2018-19799
Dolibarr ERP/CRM through 8.0.3 has /exports/export.php?datatoexport= XSS.
23RISCO
abrir
Referência
CVE-2018-19799
Dolibarr ERP/CRM through 8.0.3 has /exports/export.php?datatoexport= XSS.
23RISCO
abrir
Referência
CVE-2022-21723
Out-of-bounds read in multipart parsing in PJSIP
48RISCO
abrir
Referência
CVE-2019-7273
Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF).
23RISCO
abrir
Referência
CVE-2023-31703
Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allo
48RISCO
abrir
ReferênciaVexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6500webappsasp
Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to delete
23RISCO
abrir
Referência
CVE-2021-28417
A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php and t
23RISCO
abrir
anteriorpágina 325 / 729próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.