Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.056exploits catalogados
35.925CVEs com exploração pública
24.695testados em laboratório
22.640 exploits
Referência
CVE-2026-33829
Windows Snipping Tool Spoofing Vulnerability
33RISCO
abrir
ReferênciaVexDay Proof
JShop 1.x < 2.x - 'xPage' Local File Inclusion
CVE-2008-1624webappsphp
Directory traversal vulnerability in v2demo/page.php in Jshop Server 1.x through 2.x allows remote attackers to include
23RISCO
abrir
Referência
CVE-2017-6331
Prior to SEP 14 RU1 Symantec Endpoint Protection product can encounter an issue of Tamper-Protection Bypass, which is a
23RISCO
abrir
Referência
CVE-2009-4748
SQL injection vulnerability in mycategoryorder.php in the My Category Order plugin 2.8 and earlier for WordPress allows
23RISCO
abrir
Referência
CVE-2009-4748
SQL injection vulnerability in mycategoryorder.php in the My Category Order plugin 2.8 and earlier for WordPress allows
23RISCO
abrir
ReferênciaVexDay Proof
UBBCentral UBB.Threads 6.4.x < 6.5.2 - 'thispath' Remote File Inclusion
CVE-2006-2568webappsphp
PHP remote file inclusion vulnerability in addpost_newpoll.php in UBB.threads 6.4 through 6.5.2 and 6.5.1.1 (trial) allo
23RISCO
abrir
ReferênciaVexDay Proof
VidShare Pro - Arbitrary File Upload
CVE-2009-1750webappsphp
Unrestricted file upload vulnerability in VidSharePro allows remote authenticated users to execute arbitrary code by upl
23RISCO
abrir
Referência
CVE-2015-1517
SQL injection vulnerability in Piwigo before 2.7.4, when all filters are activated, allows remote authenticated users to
23RISCO
abrir
Referência
CVE-2010-0967
Multiple directory traversal vulnerabilities in Geekhelps ADMP 1.01, when magic_quotes_gpc is disabled, allow remote att
23RISCO
abrir
Referência
CVE-2024-27620
An issue in Ladder v.0.0.1 thru v.0.0.21 allows a remote attacker to obtain sensitive information via a crafted request
41RISCO
abrir
Referência
CVE-2010-1475
Directory traversal vulnerability in the Preventive & Reservation (com_preventive) component 1.0.5 for Joomla! allows re
38RISCO
abrir
ReferênciaVexDay Proof
Sisfo Kampus 2006 - 'dwoprn.php?f' Arbitrary File Download
CVE-2007-4895webappsphp
Directory traversal vulnerability in dwoprn.php in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to read arbitr
23RISCO
abrir
Referência
CVE-2014-5140
The bindReplace function in the query factory in includes/classes/database.php in Loaded Commerce 7 does not properly ha
23RISCO
abrir
Referência
CVE-2014-5140
The bindReplace function in the query factory in includes/classes/database.php in Loaded Commerce 7 does not properly ha
23RISCO
abrir
Referência
CVE-2010-1478
Directory traversal vulnerability in the Ternaria Informatica Jfeedback! (com_jfeedback) component 1.2 for Joomla! allow
38RISCO
abrir
Referência
CVE-2026-19974
treefrogframework treefrog-framework Session Cookie tsessioncookiestore.cpp strncmp improper authentication
33RISCO
abrir
Referência
CVE-2009-20007
Talkative IRC v0.4.4.16 Response Buffer Overflow
63RISCO
abrir
Referência
CVE-2009-20007
Talkative IRC v0.4.4.16 Response Buffer Overflow
63RISCO
abrir
Referência
CVE-2026-19973
itsourcecode Hospital Management System viewpaymentreport.php sql injection
33RISCO
abrir
Referência
CVE-2009-2641
PHP remote file inclusion vulnerability in app_and_readme/navigator/index.php in School Data Navigator allows remote att
23RISCO
abrir
Referência
CVE-2010-4099
ess.pm in NitroSecurity NitroView ESM 8.4.0a, when ESSPMDebug is enabled, allows remote attackers to execute arbitrary c
23RISCO
abrir
Referência
CVE-2026-19972
itsourcecode Hospital Management System viewpatient.php sql injection
33RISCO
abrir
Referência
CVE-2018-12326
Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution
23RISCO
abrir
ReferênciaVexDay Proof
MycroCMS 0.5 - Blind SQL Injection
CVE-2008-2770webappsphp
SQL injection vulnerability in index.php in MycroCMS 0.5, when magic_quotes_gpc is disabled, allows remote attackers to
23RISCO
abrir
Referência
CVE-2020-35416
Multiple cross-site scripting (XSS) vulnerabilities exist in PHPJabbers Appointment Scheduler 2.3, in the index.php admi
23RISCO
abrir
Referência
CVE-2020-35416
Multiple cross-site scripting (XSS) vulnerabilities exist in PHPJabbers Appointment Scheduler 2.3, in the index.php admi
23RISCO
abrir
Referência
CVE-2012-5293
Multiple PHP remote file inclusion vulnerabilities in SAPID CMS 1.2.3 Stable allow remote attackers to execute arbitrary
23RISCO
abrir
Referência
CVE-2020-8776
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via the URL property of a
23RISCO
abrir
ReferênciaVexDay Proof
eLineStudio Site Composer (ESC) 2.6 - Multiple Vulnerabilities
CVE-2008-2862webappsphp
Multiple SQL injection vulnerabilities in eLineStudio Site Composer (ESC) 2.6 and earlier allow remote attackers to exec
23RISCO
abrir
ReferênciaVexDay Proof
Ascended Guestbook 1.0.0 - 'embedded.php' File Inclusion
CVE-2006-5531webappsphp
PHP remote file inclusion vulnerability in embedded.php in Ascended Guestbook 1.0.0 and earlier allows remote attackers
23RISCO
abrir
anteriorpágina 622 / 755próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.