Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.056exploits catalogados
35.925CVEs com exploração pública
24.695testados em laboratório
22.640 exploits
Referência
CVE-2011-2523
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
Referência64
FortiWeb CVE-2025-25257 exploit
CVE-2025-25257CRITICALsob ataque
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISCO
abrir
Referência
FortiWeb Fabric Connector 7.6.x - SQL Injection to Remote Code Execution
CVE-2025-25257CRITICALsob ataquewebappsmultiple
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISCO
abrir
ReferênciaVexDay Proof
plxAutoReminder 3.7 - 'id' SQL Injection
CVE-2009-0593webappsphp
SQL injection vulnerability in members.php in plx Auto Reminder 3.7 allows remote authenticated users to execute arbitra
23RISCO
abrir
ReferênciaVexDay Proof
phpskelsite 1.4 - Local File Inclusion / Remote File Inclusion / Cross-Site Scripting
CVE-2009-0594webappsphp
Cross-site scripting (XSS) vulnerability in index.php in phpSkelSite 1.4 allows remote attackers to inject arbitrary web
23RISCO
abrir
Referência
CVE-2018-11776
CVE-2018-11776HIGHsob ataque
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
Referência
CVE-2009-4624
SQL injection vulnerability in download.php in Nicecoder iDesk allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Referência
CVE-2020-8515
CVE-2020-8515CRITICALsob ataque
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow
100RISCO
abrir
Referência
CVE-2018-7600
CVE-2018-7600CRITICALsob ataqueransomware
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
Referência
CVE-2018-7600
CVE-2018-7600CRITICALsob ataqueransomware
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
Referência
CVE-2013-2143
The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update
50RISCO
abrir
ReferênciaVexDay Proof
Multiple Vendor - PF Null Pointer Dereference
CVE-2009-0687dosbsd
The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirO
23RISCO
abrir
ReferênciaVexDay Proof
OpenBSD 4.5 - IP datagrams Remote Denial of Service
CVE-2009-0687dosopenbsd
The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirO
23RISCO
abrir
Referência
CVE-2026-8214
Industrial Application Software IAS Canias ERP RMI doAction improper authentication
33RISCO
abrir
Referência
CVE-2013-2294
Multiple cross-site scripting (XSS) vulnerabilities in ViewGit before 0.0.7 allow remote repository users to inject arbi
23RISCO
abrir
Referência
CVE-2013-2423
CVE-2013-2423LOWsob ataque
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and
95RISCO
abrir
Referência
CVE-2014-7200
Cross-site scripting (XSS) vulnerability in pi1/class.tx_dmmjobcontrol_pi1.php in the JobControl (dmmjobcontrol) extensi
23RISCO
abrir
Referência
CVE-2014-8469
Cross-site scripting (XSS) vulnerability in Guests/Boots in AdminCP in Moxi9 PHPFox before 4 Beta allows remote attacker
23RISCO
abrir
Referência
CVE-2009-4688
Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP Shopping Cart Selling Website Script allow remot
23RISCO
abrir
Referência
Nagios Log Server 2024R1.3.1 - Stored XSS
CVE-2025-29471HIGHwebappsmultiple
Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code
41RISCO
abrir
Referência
CVE-2013-2567
An Authentication Bypass vulnerability exists in the web interface in Zavio IP Cameras through 1.6.03 due to a hardcoded
28RISCO
abrir
Referência
CVE-2013-2567
An Authentication Bypass vulnerability exists in the web interface in Zavio IP Cameras through 1.6.03 due to a hardcoded
28RISCO
abrir
Referência
CVE-2018-25403
The Open ISES Project 3.30A SQL Injection via city_graph.php
41RISCO
abrir
Referência
CVE-2018-25402
The Open ISES Project 3.30A SQL Injection via inc_types_graph.php
41RISCO
abrir
Referência
CVE-2018-25401
The Open ISES Project 3.30A SQL Injection via sever_graph.php
41RISCO
abrir
Referência
CVE-2024-27199
CVE-2024-27199HIGHsob ataqueransomware
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
100RISCO
abrir
Referência
CVE-2022-44877
CVE-2022-44877CRITICALsob ataque
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISCO
abrir
Referência
CVE-2022-44877
CVE-2022-44877CRITICALsob ataque
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISCO
abrir
Referência
CVE-2018-25400
The Open ISES Project 3.30A SQL Injection via form_post.php
41RISCO
abrir
Referência
CVE-2014-9258
SQL injection vulnerability in ajax/getDropdownValue.php in GLPI before 0.85.1 allows remote authenticated users to exec
23RISCO
abrir
anteriorpágina 618 / 755próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.