Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.772exploits catalogados
35.760CVEs com exploração pública
24.695testados em laboratório
22.523 exploits
Referência
CVE-2010-1727
SQL injection vulnerability in type.asp in JobPost 1.0 allows remote attackers to execute arbitrary SQL commands via the
23RISCO
abrir
Referência
CVE-2019-19774
An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetai
28RISCO
abrir
Referência
CVE-2010-1739
SQL injection vulnerability in the Newsfeeds (com_newsfeeds) component for Joomla! allows remote attackers to execute ar
23RISCO
abrir
Referência
CVE-2017-5630
PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenam
28RISCO
abrir
Referência
CVE-2016-2056
xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via
50RISCO
abrir
Referência
CVE-2010-1744
SQL injection vulnerability in product.html in B2B Gold Script allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Referência
CVE-2019-7385
An authenticated shell command injection issue has been discovered in Raisecom ISCOM HT803G-U, HT803G-W, HT803G-1GE, and
28RISCO
abrir
Referência
CVE-2024-8956
CVE-2024-8956CRITICALsob ataque
PTZOptics NDI and SDI Cameras /cgi-bin/param.cgi Insufficient Authentication
90RISCO
abrir
Referência
CVE-2016-1741
The NVIDIA driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary c
28RISCO
abrir
Referência
CVE-2017-5358
Stack-based buffer overflows in php_Easycom5_3_0.dll in EasyCom for PHP 4.0.0.29 allows remote attackers to execute arbi
28RISCO
abrir
Referência
CVE-2017-5358
Stack-based buffer overflows in php_Easycom5_3_0.dll in EasyCom for PHP 4.0.0.29 allows remote attackers to execute arbi
28RISCO
abrir
Referência
CVE-2022-28213
When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does n
28RISCO
abrir
Referência
CVE-2012-5306
Stack-based buffer overflow in the SelectDirectory method in DcsCliCtrl.dll in Camera Stream Client ActiveX Control, as
28RISCO
abrir
Referência
CVE-2021-36356
KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePa
50RISCO
abrir
Referência
CVE-2025-15471
TRENDnet TEW-713RE formFSrvX os command injection
53RISCO
abrir
Referência
CVE-2013-10048
D-Link Devices command.php Unauthenticated RCE
68RISCO
abrir
Referência
CVE-2013-10048
D-Link Devices command.php Unauthenticated RCE
68RISCO
abrir
Referência
CVE-2013-10048
D-Link Devices command.php Unauthenticated RCE
68RISCO
abrir
Referência
CVE-2013-10048
D-Link Devices command.php Unauthenticated RCE
68RISCO
abrir
Referência
CVE-2017-9675
On D-Link DIR-605L devices, firmware before 2.08UIBetaB01.bin allows an unauthenticated GET request to trigger a reboot.
28RISCO
abrir
Referência
CVE-2012-4399
The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via X
28RISCO
abrir
ReferênciaVexDay Proof
WordPress Plugin User Photo Component - Arbitrary File Upload
CVE-2013-1916webappsphp
In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upl
28RISCO
abrir
Referência
CVE-2021-36711
WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled.
28RISCO
abrir
Referência
CVE-2018-5724
MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Download and Upload, as demonstrated by restore
28RISCO
abrir
Referência
CVE-2018-5724
MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Download and Upload, as demonstrated by restore
28RISCO
abrir
Referência
CVE-2012-3574
Unrestricted file upload vulnerability in includes/doajaxfileupload.php in the MM Forms Community plugin 2.2.5 and 2.2.6
28RISCO
abrir
Referência
CVE-2019-6273
download_file in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to download arbitrary files.
28RISCO
abrir
Referência
CVE-2019-6273
download_file in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to download arbitrary files.
28RISCO
abrir
Referência
CVE-2014-7279
The Konke Smart Plug K does not require authentication for TELNET sessions, which allows remote attackers to obtain "equ
28RISCO
abrir
Referência
CVE-2009-4779
Multiple PHP remote file inclusion vulnerabilities in NukeHall 0.3 and earlier allow remote attackers to execute arbitra
23RISCO
abrir
anteriorpágina 554 / 751próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.