Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.057exploits catalogados
36.288CVEs com exploração pública
24.695testados em laboratório
22.910 exploits
Referência
CVE-2018-14728
upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.
60RISCO
abrir
Referência
CVE-2021-22145
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the abil
60RISCO
abrir
Referência
CVE-2023-32243
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISCO
abrir
ReferênciaVexDay Proof
ABG Blocking Script 1.0a - 'abg_path' Remote File Inclusion
CVE-2008-3570webappsphp
PHP remote file inclusion vulnerability in index.php in Africa Be Gone (ABG) 1.0a allows remote attackers to execute arb
23RISCO
abrir
Referência
CVE-2021-44596
Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an
28RISCO
abrir
ReferênciaVexDay Proof
Forest Blog 1.3.2 - Remote Database Disclosure
CVE-2008-5780webappsasp
Forest Blog 1.3.2 stores sensitive information under the web root with insufficient access control, which allows remote
23RISCO
abrir
Referência
CVE-2019-1003030
CVE-2019-1003030CRITICALsob ataque
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/
100RISCO
abrir
Referência
CVE-2015-0016
CVE-2015-0016HIGHsob ataque
Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7
100RISCO
abrir
Referência
Online Magazine Management System 1.0 - SQLi Authentication Bypass
CVE-2021-44653webappsphp
Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability. The Admin panel auth
23RISCO
abrir
ReferênciaVexDay Proof
Kipper 2.01 - Cross-Site Scripting / Local File Inclusion / File Disclosure
CVE-2009-0767webappsphp
Kipper 2.01 stores sensitive information under the web root with insufficient access control, which allows remote attack
23RISCO
abrir
Referência
CVE-2012-4792
CVE-2012-4792HIGHsob ataque
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary cod
100RISCO
abrir
Referência
CVE-2017-16921
In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.2
28RISCO
abrir
Referência
Online Pre-owned/Used Car Showroom Management System 1.0 - SQLi Authentication Bypass
CVE-2021-44655webappsphp
Online Pre-owned/Used Car Showroom Management System 1.0 contains a SQL injection authentication bypass vulnerability. A
23RISCO
abrir
Referência
CVE-2013-5486
Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Network Manager
60RISCO
abrir
Referência
CVE-2015-0016
CVE-2015-0016HIGHsob ataque
Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7
100RISCO
abrir
Referência
CVE-2019-1937
Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data Authentication Bypass Vulnerability
85RISCO
abrir
Referência
CVE-2016-6433
The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users
60RISCO
abrir
Referência
CVE-2019-10267
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to
60RISCO
abrir
Referência
CVE-2019-1937
Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data Authentication Bypass Vulnerability
85RISCO
abrir
Referência
CVE-2021-44790
Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier
45RISCO
abrir
Referência
CVE-2022-2884
A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3
70RISCO
abrir
Referência
CVE-2009-2591
SQL injection vulnerability in the MyAnnonces module for E-Xoopport 3.1 allows remote attackers to execute arbitrary SQL
23RISCO
abrir
Referência
CVE-2017-1092
IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system a
60RISCO
abrir
Referência
CVE-2017-1092
IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system a
60RISCO
abrir
ReferênciaVexDay Proof
PNPHPBB2 < 1.2 - 'index.php' SQL Injection
CVE-2007-3052webappsphp
SQL injection vulnerability in index.php in the PNphpBB2 1.2i and earlier module for PostNuke allows remote attackers to
23RISCO
abrir
Referência
CVE-2019-1937
Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data Authentication Bypass Vulnerability
85RISCO
abrir
ReferênciaVexDay Proof
XOOPS Module icontent 1.0/4.5 - Remote File Inclusion
CVE-2007-3057webappsphp
PHP remote file inclusion vulnerability in include/wysiwyg/spaw_control.class.php in the icontent 4.5 module for XOOPS a
35RISCO
abrir
Referência
CVE-2019-10267
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to
60RISCO
abrir
Referência
CVE-2016-1561
ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, whic
60RISCO
abrir
Referência
CVE-2020-11854
Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) products.
85RISCO
abrir
anteriorpágina 40 / 764próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.