Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.866exploits catalogados
35.812CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.573GitHub PoC 14.316VulnCheck XDB 8.722Nuclei 4.320Metasploit 3.477✓ só verificadosrecentespopularesrisco
22.573 exploits
Referência
CVE-2009-3506
Multiple cross-site scripting (XSS) vulnerabilities in CMSphp 0.21 allow remote attackers to inject arbitrary web script
23RISCO
abrir ↗Referência✓ VexDay Proof
Flatnux 2009-01-27 - Remote File Inclusion
PHP remote file inclusion vulnerability in include/flatnux.php in FlatnuX CMS (aka Flatnuke3) 2009-01-27 and 2009-02-04,
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Expose RC35 - Arbitrary File Upload
uploadimg.php in the Expose RC35 and earlier (com_expose) component for Joomla! sends an error message but does not exit
23RISCO
abrir ↗Referência
CVE-2010-5026
SQL injection vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to e
23RISCO
abrir ↗Referência
CVE-2017-0165
An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows 10 1511, Windows 8.
23RISCO
abrir ↗Referência
CVE-2018-14057
Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validati
23RISCO
abrir ↗Referência
CVE-2018-14057
Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validati
23RISCO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Filiale 1.0.4 - 'idFiliale' SQL Injection
SQL injection vulnerability in the Filiale 1.0.4 component for Joomla! allows remote attackers to execute arbitrary SQL
23RISCO
abrir ↗Referência
CVE-2020-6862
V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability. Unauthorized users could lo
23RISCO
abrir ↗Referência
CVE-2014-9448
Buffer overflow in Mini-stream RM-MP3 Converter 3.1.2.1.2010.03.30 allows remote attackers to execute arbitrary code or
23RISCO
abrir ↗Referência
CVE-2014-9448
Buffer overflow in Mini-stream RM-MP3 Converter 3.1.2.1.2010.03.30 allows remote attackers to execute arbitrary code or
23RISCO
abrir ↗Referência
CVE-2018-5985
SQL Injection exists in the LiveCRM SaaS Cloud 1.0 component for Joomla! via an r=site/login&company_id= request.
28RISCO
abrir ↗Referência
CVE-2017-5344
An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessib
23RISCO
abrir ↗Referência
CVE-2013-6796
The SMTP server in DeepOfix 3.3 and earlier allows remote attackers to bypass authentication via an empty password, whic
23RISCO
abrir ↗Referência
CVE-2013-6796
The SMTP server in DeepOfix 3.3 and earlier allows remote attackers to bypass authentication via an empty password, whic
23RISCO
abrir ↗Referência
CVE-2019-15083
Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workst
23RISCO
abrir ↗Referência
CVE-2018-5988
SQL Injection exists in Flexible Poll 1.2 via the id parameter to mobile_preview.php or index.php.
28RISCO
abrir ↗Referência
CVE-2020-37125
Edimax Technology EW-7438RPn-v3 Mini 1.27 - Remote Code Execution
48RISCO
abrir ↗Referência
CVE-2014-4018
The ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK has a default password of admin for the admin account, which
23RISCO
abrir ↗Referência
CVE-2014-4018
The ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK has a default password of admin for the admin account, which
23RISCO
abrir ↗Referência
CVE-2017-2457
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issu
23RISCO
abrir ↗Referência
ManageEngine Service Desk 10.0 - Cross-Site Scripting
Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workst
23RISCO
abrir ↗Referência
CVE-2015-1674
The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not pr
23RISCO
abrir ↗Referência
CVE-2017-15359
In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory t
23RISCO
abrir ↗Referência
CVE-2017-2367
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISCO
abrir ↗Referência
Webrun 3.6.0.42 - 'P_0' SQL Injection
WebRun 3.6.0.42 is vulnerable to SQL Injection via the P_0 parameter used to set the username during the login process.
23RISCO
abrir ↗Referência✓ VexDay Proof
moziloCMS 1.11 - Local File Inclusion / Full Path Disclosure / Cross-Site Scripting
Directory traversal vulnerability in index.php in moziloCMS 1.11 allows remote attackers to read arbitrary files via a .
23RISCO
abrir ↗Referência
CVE-2022-4047
Return Refund and Exchange For WooCommerce < 4.0.9 - Unauthenticated Arbitrary File Upload
48RISCO
abrir ↗Referência
CVE-2017-9259
The TDStretch::acceptNewOverlapLength function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote atta
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.