Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.057exploits catalogados
36.288CVEs com exploração pública
24.695testados em laboratório
22.910 exploits
Referência
CVE-2017-16666
Xplico before 1.2.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the name
60RISCO
abrir
Referência
CVE-2017-16666
Xplico before 1.2.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the name
60RISCO
abrir
Referência
CVE-2018-18809
CVE-2018-18809CRITICALsob ataque
TIBCO JasperReports Library Directory Traversal Vulnerability
100RISCO
abrir
ReferênciaVexDay Proof
linksnet newsfeed 1.0 - Remote File Inclusion
CVE-2007-2707webappsphp
PHP remote file inclusion vulnerability in linksnet_linkslog_rss.php in Linksnet Newsfeed 1.0 allows remote attackers to
35RISCO
abrir
ReferênciaVexDay Proof
SAP MaxDB 7.6.03.07 - Remote Command Execution
CVE-2008-0244remotemultiple
SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell me
60RISCO
abrir
ReferênciaVexDay Proof
WEBalbum 2.4b - 'id' Blind SQL Injection
CVE-2009-0446webappsphp
SQL injection vulnerability in photo.php in WEBalbum 2.4b allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
Referência
CVE-2014-4872
BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbit
60RISCO
abrir
Referência
CVE-2015-3043
CVE-2015-3043HIGHsob ataque
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457
100RISCO
abrir
Referência
CVE-2015-7387
ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions
60RISCO
abrir
Referência
CVE-2015-7387
ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions
60RISCO
abrir
Referência
CVE-2019-11600
A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbi
45RISCO
abrir
Referência
CVE-2016-2555
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbi
60RISCO
abrir
ReferênciaVexDay Proof
MojoAuto - Blind SQL Injection
CVE-2008-3383webappscgi
SQL injection vulnerability in mojoAuto.cgi in MojoAuto allows remote attackers to execute arbitrary SQL commands via th
23RISCO
abrir
Referência
CVE-2016-7201
CVE-2016-7201HIGHsob ataque
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
93RISCO
abrir
Referência
CVE-2016-7201
CVE-2016-7201HIGHsob ataque
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
93RISCO
abrir
Referência
CVE-2019-5736
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
Referência
CVE-2017-12615
CVE-2017-12615HIGHsob ataqueransomware
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISCO
abrir
Referência
CVE-2014-7866
Multiple directory traversal vulnerabilities in ZOHO ManageEngine OpManager 8 (build 88xx) through 11.4, IT360 10.3 and
45RISCO
abrir
Referência
CVE-2018-10662
An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.
60RISCO
abrir
Referência
CVE-2019-5736
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
Referência
CVE-2019-5736
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISCO
abrir
ReferênciaVexDay Proof
Alstrasoft Video Share Enterprise 4.5.1 - 'UID' SQL Injection
CVE-2008-3386webappsphp
SQL injection vulnerability in album.php in AlstraSoft Video Share Enterprise 4.51 allows remote attackers to execute ar
23RISCO
abrir
Referência
CVE-2012-0217
The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and
50RISCO
abrir
Referência
CVE-2016-7201
CVE-2016-7201HIGHsob ataque
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
93RISCO
abrir
Referência
CVE-2012-1495
install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user
60RISCO
abrir
Referência
CVE-2012-1495
install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user
60RISCO
abrir
ReferênciaVexDay Proof
XRms 1.99.2 - Remote File Inclusion / Cross-Site Scripting / Information Gathering
CVE-2008-3400webappsphp
XRMS CRM 1.99.2 allows remote attackers to obtain configuration information via a direct request to tests/info.php, whic
23RISCO
abrir
Referência
CVE-2024-10915
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISCO
abrir
Referência
CVE-2025-2777
SysAid On-Prem <= 23.3.40 lshw Proceessing XML External Entity Injection
85RISCO
abrir
Referência
CVE-2019-15954
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote
60RISCO
abrir
anteriorpágina 35 / 764próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.