Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.559exploits catalogados
34.978CVEs com exploração pública
24.695testados em laboratório
21.899 exploits
Referência
CVE-2009-4935
SQL injection vulnerability in ogp_show.php in Online Guestbook Pro allows remote attackers to execute arbitrary SQL com
23RISCO
abrir
ReferênciaVexDay Proof
openMairie 1.10 - '/scr/soustab.php' Local File Inclusion
CVE-2007-2069webappsphp
Directory traversal vulnerability in scr/soustab.php in openMairie 1.11 and earlier allows remote attackers to include a
23RISCO
abrir
ReferênciaVexDay Proof
XAMPP for Windows 1.6.0a - 'mssql_connect()' Remote Buffer Overflow
CVE-2007-2080remotewindows
Multiple SQL injection vulnerabilities in XAMPP 1.6.0a for Windows allow remote attackers to execute arbitrary SQL comma
23RISCO
abrir
Referência
CVE-2021-31207
CVE-2021-31207MEDIUMsob ataqueransomware
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RISCO
abrir
Referência
CVE-2019-15107
CVE-2019-15107CRITICALsob ataqueransomware
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
Referência
CVE-2025-34103
WePresent WiPG-1000 Unauthenticated Command Injection in via rdfs.cgi
63RISCO
abrir
Referência
CVE-2026-6381
WP Maps < 4.9.3 - Subscriber+ Local File Inclusion
41RISCO
abrir
ReferênciaVexDay Proof
Joomla! / Mambo Component New Article 1.1 - Remote File Inclusion
CVE-2007-2089webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Jx Development Article 1.1 and earlier component for Mambo and
23RISCO
abrir
ReferênciaVexDay Proof
xoops module tsdisplay4xoops 0.1 - Remote File Inclusion
CVE-2007-2091webappsphp
PHP remote file inclusion vulnerability in blocks/tsdisplay4xoops_block2.php in tsdisplay4xoops (TSD4XOOPS, aka the Team
23RISCO
abrir
Referência
CVE-2026-6379
WP Photo Album Plus < 9.1.11.001 - Unauthenticated SQL Injection via 'wppa-supersearch' Parameter
41RISCO
abrir
Referência
Sophos XG115w Firewall 17.0.10 MR-10 - Authentication Bypass
CVE-2022-1040CRITICALsob ataquewebappshardware
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RISCO
abrir
Referência
CVE-2022-47966
CVE-2022-47966CRITICALsob ataqueransomware
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISCO
abrir
Referência
CVE-2022-47966
CVE-2022-47966CRITICALsob ataqueransomware
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISCO
abrir
Referência
CVE-2022-47966
CVE-2022-47966CRITICALsob ataqueransomware
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISCO
abrir
ReferênciaVexDay Proof
audioCMS arash 0.1.4 - 'arashlib_dir' Remote File Inclusion
CVE-2007-2301webappsphp
Multiple PHP remote file inclusion vulnerabilities in audioCMS arash 0.1.4 allow remote attackers to execute arbitrary P
23RISCO
abrir
Referência
CVE-2019-16759
CVE-2019-16759CRITICALsob ataque
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
Referência
CVE-2019-16759
CVE-2019-16759CRITICALsob ataque
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISCO
abrir
Referência
CVE-2026-8759
xiandafu beetl SpELFunction SpELFunction.java expression language injection
33RISCO
abrir
Referência
CVE-2026-8758
Metasoft 美特软件 MetaCRM upload3.jsp unrestricted upload
33RISCO
abrir
Referência
CVE-2021-38647
CVE-2021-38647CRITICALsob ataqueransomware
Open Management Infrastructure Remote Code Execution Vulnerability
100RISCO
abrir
Referência
CVE-2017-0147
CVE-2017-0147HIGHsob ataqueransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
Referência
CVE-2017-1000353
CVE-2017-1000353CRITICALsob ataque
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code exe
100RISCO
abrir
Referência
CVE-2020-10220
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php
60RISCO
abrir
Referência
CVE-2020-10220
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php
60RISCO
abrir
Referência
CVE-2020-10220
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php
60RISCO
abrir
Referência
CVE-2022-22965
CVE-2022-22965CRITICALsob ataque
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
Referência
CVE-2022-22965
CVE-2022-22965CRITICALsob ataque
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISCO
abrir
Referência
CVE-2017-8687
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RISCO
abrir
Referência
CVE-2020-37221
Atomic Alarm Clock 6.3 Stack Overflow via SEH Unicode
41RISCO
abrir
Referência
CVE-2020-37220
Huawei HG630 V2 Router Authentication Bypass via Serial Number
41RISCO
abrir
anteriorpágina 352 / 730próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.