Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.284exploits catalogados
35.465CVEs com exploração pública
24.695testados em laboratório
22.266 exploits
Referência
CVE-2018-18923
AbiSoft Ticketly 1.0 is affected by multiple SQL Injection vulnerabilities through the parameters name, category_id and
23RISCO
abrir
Referência
CVE-2018-18924
The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file
23RISCO
abrir
ReferênciaVexDay Proof
FrontAccounting 1.12 build 31 - Remote File Inclusion
CVE-2007-4279webappsphp
PHP remote file inclusion vulnerability in config.php in FrontAccounting 1.12 Build 31 allows remote attackers to execut
45RISCO
abrir
Referência
CVE-2018-19913
DomainMOD through 4.11.01 has XSS via the assets/add/registrar-accounts.php UserName, Reseller ID, or notes field.
23RISCO
abrir
Referência
CVE-2018-20219
An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. After successful authentication, the de
28RISCO
abrir
Referência
CVE-2018-20250
CVE-2018-20250HIGHsob ataqueransomware
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
Referência
CVE-2018-20250
CVE-2018-20250HIGHsob ataqueransomware
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
Referência
CVE-2018-20250
CVE-2018-20250HIGHsob ataqueransomware
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISCO
abrir
Referência
CVE-2026-14647
onnx onnxruntime old.cc convPoolShapeInference_opset19 out-of-bounds
33RISCO
abrir
Referência
CVE-2026-14642
SourceCodester Class and Exam Timetabling System edit_class2.php sql injection
33RISCO
abrir
Referência
CVE-2012-5348
SQL injection vulnerability in MangosWeb Enhanced 3.0.3 allows remote attackers to execute arbitrary SQL commands via th
23RISCO
abrir
Referência
CVE-2012-5387
Cross-site request forgery (CSRF) vulnerability in wlcms-plugin.php in the White Label CMS plugin before 1.5.1 for WordP
23RISCO
abrir
Referência
CVE-2018-5701
In Iolo System Shield AntiVirus and AntiSpyware 5.0.0.136, the amp.sys driver file contains an Arbitrary Write vulnerabi
28RISCO
abrir
ReferênciaVexDay Proof
NuclearBB Alpha 2 - 'ROOT_PATH' Remote File Inclusion
CVE-2007-4906webappsphp
PHP remote file inclusion vulnerability in tasks/send_queued_emails.php in NuclearBB Alpha 2, when register_globals is e
35RISCO
abrir
Referência
CVE-2018-5701
In Iolo System Shield AntiVirus and AntiSpyware 5.0.0.136, the amp.sys driver file contains an Arbitrary Write vulnerabi
28RISCO
abrir
Referência
CVE-2022-50970
WordPress Plugin AAWP 3.16 Reflected XSS via tab Parameter
33RISCO
abrir
Referência
CVE-2026-14641
SourceCodester Class and Exam Timetabling System edit_course.php sql injection
33RISCO
abrir
Referência
CVE-2026-14640
CodeAstro Apartment Visitor Management System Login index.php sql injection
33RISCO
abrir
Referência
CVE-2026-14639
CodeAstro Ecommerce Website my_account.php sql injection
33RISCO
abrir
Referência
CVE-2026-14633
kirilkirkov Ecommerce-CodeIgniter-Bootstrap Hidden REST API Endpoint set cross site scripting
33RISCO
abrir
ReferênciaVexDay Proof
JetCast Server 2.0.0.4308 - Remote Denial of Service
CVE-2007-4911doswindows
JSMP3OGGWt.dll in JetCast Server 2.0.0.4308 allows remote attackers to cause a denial of service (daemon crash) via a lo
23RISCO
abrir
Referência
CVE-2018-5705
Reservo Image Hosting 1.6 is vulnerable to XSS attacks. The affected function is its search engine (the t parameter to t
23RISCO
abrir
Referência
CVE-2018-5705
Reservo Image Hosting 1.6 is vulnerable to XSS attacks. The affected function is its search engine (the t parameter to t
23RISCO
abrir
Referência
CVE-2018-5723
MASTER IPCAMERA01 3.3.4.2103 devices have a hardcoded password of cat1029 for the root account.
23RISCO
abrir
Referência
CVE-2018-5755
Absolute path traversal vulnerability in the readerengine component in Open-Xchange OX App Suite before 7.6.3-rev3, 7.8.
23RISCO
abrir
Referência
CVE-2012-5900
Multiple SQL injection vulnerabilities in SAMEDIA LandShop 0.9.2 allow remote attackers to execute arbitrary SQL command
23RISCO
abrir
ReferênciaVexDay Proof
Winamp 5.12 - '.pls' Remote Buffer Overflow (Perl) (2)
CVE-2006-0476remotewindows
Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with
60RISCO
abrir
Referência
CVE-2018-5989
SQL Injection exists in the ccNewsletter 2.x component for Joomla! via the id parameter in a task=removeSubscriber actio
23RISCO
abrir
Referência
CVE-2018-5990
SQL Injection exists in the AllVideos Reloaded 1.2.x component for Joomla! via the divid parameter.
23RISCO
abrir
Referência
CVE-2018-5991
SQL Injection exists in the Form Maker 3.6.12 component for Joomla! via the id, from, or to parameter in a view=stats re
23RISCO
abrir
anteriorpágina 440 / 743próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.