Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.302exploits catalogados
35.469CVEs com exploração pública
24.695testados em laboratório
22.301 exploits
Referência
CVE-2019-8928
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in /netflow/jspui/userMan
23RISCO
abrir
ReferênciaVexDay Proof
Cyberfolio 7.12.2 - 'theme' Local File Inclusion
CVE-2008-6265webappsphp
Directory traversal vulnerability in portfolio/css.php in Cyberfolio 7.12.2 and earlier allows remote attackers to inclu
23RISCO
abrir
ReferênciaVexDay Proof
Apoll 0.7b - Authentication Bypass
CVE-2008-6272webappsphp
SQL injection vulnerability in admin/index.php in Dragan Mitic Apoll 0.7 beta and 0.7.5 allows remote attackers to execu
23RISCO
abrir
ReferênciaVexDay Proof
Family Project 2.x - Authentication Bypass
CVE-2008-6274webappsphp
Multiple SQL injection vulnerabilities in index.php in FamilyProject 2.0 allow remote attackers to execute arbitrary SQL
23RISCO
abrir
ReferênciaVexDay Proof
Bluo CMS 1.2 - Blind SQL Injection
CVE-2008-6281webappsphp
SQL injection vulnerability in index.php in Bluo CMS 1.2 allows remote attackers to execute arbitrary SQL commands via t
23RISCO
abrir
ReferênciaVexDay Proof
z1exchange 1.0 - 'site' SQL Injection
CVE-2008-6284webappsphp
SQL injection vulnerability in edit.php in Z1Exchange 1.0 allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
ReferênciaVexDay Proof
Active Web Helpdesk 2 - 'categoryId' Blind SQL Injection
CVE-2008-6380webappsphp
SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL
23RISCO
abrir
Referência
CVE-2011-4825
Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinym
50RISCO
abrir
Referência
CVE-2014-9456
Buffer overflow in NotePad++ 6.6.9 allows remote attackers to have unspecified impact via a long Time attribute in an Ev
28RISCO
abrir
Referência
CVE-2026-9468
dazeb cline-mcp-memory-bank index.ts handleInitializeMemoryBank path traversal
33RISCO
abrir
ReferênciaVexDay Proof
Quick Tree View .NET 3.1 - Database Disclosure
CVE-2008-6387webappsphp
Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows
23RISCO
abrir
Referência
CVE-2019-9162
In the Linux kernel before 4.20.12, net/ipv4/netfilter/nf_nat_snmp_basic_main.c in the SNMP NAT module has insufficient
23RISCO
abrir
Referência
CVE-2014-9613
Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL co
23RISCO
abrir
Referência
CVE-2014-9641
The tmeext.sys driver before 2.0.0.1015 in Trend Micro Antivirus Plus, Internet Security, and Maximum Security allows lo
23RISCO
abrir
Referência
CVE-2011-4829
SQL injection vulnerability in the com_listing component in Barter Sites component 1.3 for Joomla! allows remote attacke
23RISCO
abrir
Referência
CVE-2018-25376
Socusoft 3GP Photo Slideshow 8.05 Buffer Overflow SEH
41RISCO
abrir
Referência
CVE-2019-9193
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISCO
abrir
Referência
CVE-2019-9193
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISCO
abrir
Referência
CVE-2019-9213
In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which make
38RISCO
abrir
Referência
CVE-2019-9213
In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which make
38RISCO
abrir
Referência
CVE-2019-9491
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to
28RISCO
abrir
Referência
Bolt CMS 3.6.4 - Cross-Site Scripting
CVE-2019-9553webappsphp
Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and
23RISCO
abrir
Referência
Craft CMS 3.1.12 Pro - Cross-Site Scripting
CVE-2019-9554webappsphp
In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at
23RISCO
abrir
Referência
CVE-2019-9581
phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitra
28RISCO
abrir
Referência
CVE-2015-1338
kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly ga
23RISCO
abrir
Referência
CVE-2026-9366
NousResearch hermes-agent prompt_builder.py _scan_context_content injection
33RISCO
abrir
Referência
CVE-2011-5044
SopCast 3.4.7.45585 uses weak permissions (Everyone:Full Control) for Diagnose.exe, which allows local users to execute
23RISCO
abrir
Referência
CVE-2020-0796
CVE-2020-0796CRITICALsob ataqueransomware
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
Referência
CVE-2020-0796
CVE-2020-0796CRITICALsob ataqueransomware
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
Referência
CVE-2020-0796
CVE-2020-0796CRITICALsob ataqueransomware
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
anteriorpágina 458 / 744próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.