Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.496exploits catalogados
34.964CVEs com exploração pública
24.695testados em laboratório
21.899 exploits
ReferênciaVexDay Proof
LBlog 1.05 - 'comments.asp' SQL Injection
CVE-2006-4284webappsasp
SQL injection vulnerability in comments.asp in LBlog 1.05 and earlier allows remote attackers to execute arbitrary SQL c
23RISCO
abrir
ReferênciaVexDay Proof
Fantastic News 2.1.3 - 'script_path' Remote File Inclusion
CVE-2006-4285webappsphp
PHP remote file inclusion vulnerability in news.php in Fantastic News 2.1.3 and earlier allows remote attackers to execu
23RISCO
abrir
Referência
CVE-2009-4560
SQL injection vulnerability in profile.php in WebLeague 2.2.0 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
ReferênciaVexDay Proof
NES Game and NES System c108122 - Remote File Inclusion
CVE-2006-4287webappsphp
Multiple PHP remote file inclusion vulnerabilities in NES Game and NES System c108122 and earlier allow remote attackers
28RISCO
abrir
ReferênciaVexDay Proof
SimpleBlog 2.0 - 'comments.asp' SQL Injection (2)
CVE-2006-4300webappsphp
SQL injection vulnerability in comments.asp in SimpleBlog 2.0 and earlier allows remote attackers to execute arbitrary S
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Internet Explorer 6 - DirectX Media Remote Overflow Denial of Service
CVE-2006-4301doswindows
Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) via a long Color attrib
35RISCO
abrir
ReferênciaVexDay Proof
OpenSSL < 0.9.7l/0.9.8d - SSLv2 Client Crash
CVE-2006-4343dosmultiple
The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier
28RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component Kochsuite 0.9.4 - Remote File Inclusion
CVE-2006-4348webappsphp
PHP remote file inclusion vulnerability in config.kochsuite.php in the Kochsuite (com_kochsuite) 0.9.4 component for Mam
23RISCO
abrir
Referência
CVE-2009-4561
Multiple SQL injection vulnerabilities in Admin/index.php in WebLeague 2.2.0, when magic_quotes_gpc is disabled, allow r
23RISCO
abrir
ReferênciaVexDay Proof
Empire CMS 3.7 - 'checklevel.php' Remote File Inclusion
CVE-2006-4354webappsphp
PHP remote file inclusion vulnerability in e/class/CheckLevel.php in Phome Empire CMS 3.7 and earlier allows remote atta
23RISCO
abrir
ReferênciaVexDay Proof
Integramod Portal 2.x - 'functions_portal.php' Remote File Inclusion
CVE-2006-4368webappsphp
PHP remote file inclusion vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier allows rem
23RISCO
abrir
ReferênciaVexDay Proof
Integramod Portal 2.x - 'functions_portal.php' Remote File Inclusion
CVE-2006-4369webappsphp
Absolute path traversal vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier, when magic_
23RISCO
abrir
ReferênciaVexDay Proof
pSlash 0.7 - 'lvc_include_dir' Remote File Inclusion
CVE-2006-4373webappsphp
PHP remote file inclusion vulnerability in modules/visitors2/include/config.inc.php in pSlash 0.70 allows remote attacke
23RISCO
abrir
ReferênciaVexDay Proof
PHPCOIN 1.2.3 - 'session_set.php' Remote File Inclusion
CVE-2006-4424webappsphp
PHP remote file inclusion vulnerability in coin_includes/constants.php in phpCOIN 1.2.3 allows remote attackers to execu
23RISCO
abrir
ReferênciaVexDay Proof
eFiction < 2.0.7 - Remote Admin Authentication Bypass
CVE-2006-4427webappsphp
index.php in eFiction before 2.0.7 allows remote attackers to bypass authentication and gain privileges by setting the (
23RISCO
abrir
ReferênciaVexDay Proof
Ay System CMS 2.6 - 'main.php' Remote File Inclusion
CVE-2006-4440webappsphp
PHP remote file inclusion vulnerability in main.php in Ay System Solutions CMS 2.6 and earlier allows remote attackers t
23RISCO
abrir
ReferênciaVexDay Proof
Interact 2.2 - 'CONFIG[base_path]' Remote File Inclusion
CVE-2006-4448webappsphp
Multiple PHP remote file inclusion vulnerabilities in interact 2.2, when register_globals is enabled, allow remote attac
23RISCO
abrir
ReferênciaVexDay Proof
XChat 2.6.7 (Windows) - Remote Denial of Service
CVE-2006-4455doswindows
Unspecified vulnerability in Xchat 2.6.7 and earlier allows remote attackers to cause a denial of service (crash) via un
23RISCO
abrir
Referência
CVE-2021-43798
CVE-2021-43798HIGHsob ataque
Grafana path traversal
100RISCO
abrir
Referência
CVE-2026-25559
OpenBullet2 0.3.2 Path Traversal via Wordlist Endpoint
41RISCO
abrir
Referência
CVE-2026-25855
OpenBullet2 0.3.2 Authenticated RCE via FileProxySource Script Upload
41RISCO
abrir
Referência
CVE-2026-11534
imvks786 student_management_system add.php cross site scripting
33RISCO
abrir
Referência
CVE-2026-11530
imvks786 student_management_system Login index.ph sql injection
33RISCO
abrir
Referência14
HTTP/2 Bomb
Apache HTTP Server: mod_http2 denial of service
46RISCO
abrir
Referência
CVE-2026-11333
tittuvarghese CollegeManagementSystem Student Data Upload Endpoint upload_student_data.php unrestricted upload
33RISCO
abrir
Referência
CVE-2026-50232
Lyrion Music Server 9.2.0 Stored XSS via Metadata Tags
33RISCO
abrir
Referência
CVE-2024-0723
freeSSHd denial of service
33RISCO
abrir
Referência
CVE-2021-22005
CVE-2021-22005CRITICALsob ataqueransomware
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISCO
abrir
Referência
CVE-2017-8484
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2,
23RISCO
abrir
Referência
CVE-2020-5902
CVE-2020-5902CRITICALsob ataqueransomware
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
anteriorpágina 337 / 730próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.