Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.714exploits catalogados
35.724CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.455Referência 22.492GitHub PoC 14.286VulnCheck XDB 8.693Nuclei 4.314Metasploit 3.474✓ só verificadosrecentespopularesrisco
22.429 exploits
Referência
CVE-2015-7857
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.p
60RISCO
abrir ↗Referência
CVE-2015-7857
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.p
60RISCO
abrir ↗Referência
CVE-2019-16172
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, Su
23RISCO
abrir ↗Referência
CVE-2017-5753
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RISCO
abrir ↗Referência
CVE-2008-6392
SQL injection vulnerability in showads.php in Z1Exchange allows remote attackers to execute arbitrary SQL commands via t
23RISCO
abrir ↗Referência
CVE-2018-14933
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir par
100RISCO
abrir ↗Referência
CyberArk Viewfinity 5.5.10.95 - Local Privilege Escalation
In CyberArk Viewfinity 5.5.10.95 and 6.x before 6.1.1.220, a low privilege user can escalate to an administrative user v
41RISCO
abrir ↗Referência
CVE-2015-5122
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player
100RISCO
abrir ↗Referência
CVE-2017-1129
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it coul
50RISCO
abrir ↗Referência✓ VexDay Proof
EasyMail - ActiveX 'emmailstore.dll 6.5.0.3' Remote Buffer Overflow
Buffer overflow in emmailstore.dll 6.5.0.3 in the QuikSoft EasyMail MailStore ActiveX control allows remote attackers to
23RISCO
abrir ↗Referência
CVE-2020-1350
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISCO
abrir ↗Referência✓ VexDay Proof
jPORTAL 2 - 'humor.php' SQL Injection
SQL injection vulnerability in humor.php in jPORTAL 2 allows remote attackers to execute arbitrary SQL commands via the
23RISCO
abrir ↗Referência
TSplus 16.0.2.14 - Remote Access Insecure Files and Folders Permissions
An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on so
23RISCO
abrir ↗Referência✓ VexDay Proof
Oceandir 2.9 - 'show_vote.php' SQL Injection
SQL injection vulnerability in show_vote.php in Oceandir 2.9 and earlier allows remote attackers to execute arbitrary SQ
23RISCO
abrir ↗Referência✓ VexDay Proof
Diesel Pay Script - 'area' SQL Injection
SQL injection vulnerability in index.php in Diesel Pay allows remote attackers to execute arbitrary SQL commands via the
23RISCO
abrir ↗Referência
TSplus 16.0.0.0 - Remote Work Insecure Files and Folders
An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on so
23RISCO
abrir ↗Referência✓ VexDay Proof
Plaincart 1.1.2 - 'p' SQL Injection
SQL injection vulnerability in index.php in PlainCart 1.1.2 allows remote attackers to execute arbitrary SQL commands vi
23RISCO
abrir ↗Referência✓ VexDay Proof
easyLink 1.1.0 - 'detail.php' SQL Injection
SQL injection vulnerability in detail.php in MountainGrafix easyLink 1.1.0 allows remote attackers to execute arbitrary
23RISCO
abrir ↗Referência✓ VexDay Proof
Hunkaray Duyuru Scripti - 'tr' SQL Injection
SQL injection vulnerability in oku.asp in Hunkaray Duyuru Scripti allows remote attackers to execute arbitrary SQL comma
23RISCO
abrir ↗Referência✓ VexDay Proof
Blogator-script 0.95 - Change User Password
_blogadata/include/init_pass2.php in Blogator-script 0.95 allows remote attackers to change the password for arbitrary u
23RISCO
abrir ↗Referência
CVE-2019-1821
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
78RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component MyAlbum 1.0 - 'album' SQL Injection
SQL injection vulnerability in MyAlbum component (com_myalbum) 1.0 for Joomla! allows remote attackers to execute arbitr
23RISCO
abrir ↗Referência✓ VexDay Proof
FLABER 1.1 RC1 - Remote Command Execution
function/update_xml.php in FLABER 1.1 and earlier allows remote attackers to overwrite arbitrary files by specifying the
23RISCO
abrir ↗Referência
CVE-2022-26352
An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form req
100RISCO
abrir ↗Referência
CVE-2017-16806
The Process function in RemoteTaskServer/WebServer/HttpServer.cs in Ulterius before 1.9.5.0 allows HTTP server directory
60RISCO
abrir ↗Referência
CVE-2018-16509
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handlin
60RISCO
abrir ↗Referência
CVE-2018-3810
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unau
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.