Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.620exploits catalogados
35.647CVEs com exploração pública
24.695testados em laboratório
22.429 exploits
Referência
CVE-2017-11317
CVE-2017-11317CRITICALsob ataque
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload
100RISCO
abrir
Referência
CVE-2017-17587
FS Indiamart Clone 1.0 has SQL Injection via the catcompany.php token parameter, buyleads-details.php id parameter, or c
23RISCO
abrir
ReferênciaVexDay Proof
ITLPoll 2.7 Stable2 - Blind SQL Injection
CVE-2009-0295webappsphp
SQL injection vulnerability in index.php in Information Technology Light Poll Information (ITLPoll) 2.7 Stable 2, when m
23RISCO
abrir
Referência
CVE-2016-10174
CVE-2016-10174CRITICALsob ataque
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cg
100RISCO
abrir
Referência
CVE-2016-10174
CVE-2016-10174CRITICALsob ataque
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cg
100RISCO
abrir
Referência
CVE-2019-1935
Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data SCP User Default Credentials Vulnerability
85RISCO
abrir
Referência
CVE-2019-1935
Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data SCP User Default Credentials Vulnerability
85RISCO
abrir
Referência
CVE-2025-34026
CVE-2025-34026CRITICALsob ataque
Versa Concerto Actuator Authentication Bypass Information Leak
100RISCO
abrir
ReferênciaVexDay Proof
Groone's GLink ORGanizer 2.1 - 'cat' Blind SQL Injection
CVE-2009-0299webappsphp
SQL injection vulnerability in index.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Referência
CVE-2019-7214
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker co
60RISCO
abrir
Referência
CVE-2019-7214
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker co
60RISCO
abrir
ReferênciaVexDay Proof
FlexCell Grid Control 5.6.9 - Remote File Overwrite
CVE-2009-0301remotewindows
Multiple insecure method vulnerabilities in the FlexCell.Grid ActiveX control (FlexCell.ocx) in FlexCell Grid Control 5.
23RISCO
abrir
ReferênciaVexDay Proof
Amaya Web Editor 11.0 - XML / HTML Parser
CVE-2009-0323doswindows
Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0 and 11.0 allow remote attackers to execute arbitrary
50RISCO
abrir
Referência
CVE-2012-2952
SQL injection vulnerability in add_ons.php in Jaow 2.4.5 and earlier allows remote attackers to execute arbitrary SQL co
23RISCO
abrir
Referência
CVE-2020-7246
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISCO
abrir
Referência
CVE-2020-7246
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISCO
abrir
Referência
CVE-2020-7246
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISCO
abrir
ReferênciaVexDay Proof
BibCiter 1.4 - Multiple SQL Injections
CVE-2009-0324webappsphp
Multiple SQL injection vulnerabilities in BibCiter 1.4 allow remote attackers to execute arbitrary SQL commands via the
23RISCO
abrir
Referência
CVE-2017-5817
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
60RISCO
abrir
ReferênciaVexDay Proof
Pixaria Gallery 1.x - 'class.Smarty.php' Remote File Inclusion
CVE-2007-2458webappsphp
Multiple PHP remote file inclusion vulnerabilities in Pixaria Gallery before 1.4.3 allow remote attackers to execute arb
28RISCO
abrir
ReferênciaVexDay Proof
Free Bible Search PHP Script - SQL Injection
CVE-2009-0327webappsphp
SQL injection vulnerability in readbible.php in Free Bible Search PHP Script 1.0 allows remote attackers to execute arbi
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component com_pccookbook - 'recipe_id' Blind SQL Injection
CVE-2009-0329webappsphp
SQL injection vulnerability in the PcCookBook (com_pccookbook) component for Joomla! allows remote attackers to execute
23RISCO
abrir
Referência
CVE-2023-5702
Viessmann Vitogate 300 direct request
38RISCO
abrir
ReferênciaVexDay Proof
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
CVE-2009-0335webappsphp
Cross-site scripting (XSS) vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to inject arbitrar
23RISCO
abrir
Referência
CVE-2020-8163
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the
60RISCO
abrir
ReferênciaVexDay Proof
ProFTPd - 'mod_mysql' Authentication Bypass
CVE-2009-0542remotemultiple
SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL co
45RISCO
abrir
ReferênciaVexDay Proof
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
CVE-2009-0336webappsphp
Katy Whitton BlogIt! stores sensitive information under the web root with insufficient access control, which allows remo
23RISCO
abrir
Referência
CVE-2018-17254
The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.
60RISCO
abrir
ReferênciaVexDay Proof
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
CVE-2009-0337webappsphp
SQL injection vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to execute arbitrary SQL comman
23RISCO
abrir
Referência
CVE-2019-7194
CVE-2019-7194CRITICALsob ataqueransomware
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fi
100RISCO
abrir
anteriorpágina 497 / 748próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.