Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.101exploits catalogados
35.950CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.657GitHub PoC 14.406VulnCheck XDB 8.755Nuclei 4.340Metasploit 3.485✓ só verificadosrecentespopularesrisco
22.640 exploits
Referência
CVE-2018-0492
Johnathan Nightingale beep through 1.3.4, if setuid, has a race condition that allows local privilege escalation.
23RISCO
abrir ↗Referência
CVE-2012-5917
SnackAmp 3.1.3 allows remote attackers to cause a denial of service (application crash) via a long string in an aiff fil
23RISCO
abrir ↗Referência✓ VexDay Proof
BigACE 2.4 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in BigACE 2.4, when register_globals is enabled, allow remote attacke
23RISCO
abrir ↗Referência
CVE-2010-4145
Kisisel Radyo Script stores sensitive information under the web root with insufficient access control, which allows remo
23RISCO
abrir ↗Referência
CVE-2010-4145
Kisisel Radyo Script stores sensitive information under the web root with insufficient access control, which allows remo
23RISCO
abrir ↗Referência✓ VexDay Proof
Family Connections CMS 1.4 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 1.4 allow remote authenticated user
23RISCO
abrir ↗Referência
CVE-2009-4626
Directory traversal vulnerability in menu.php in phpNagios 1.2.0 allows remote attackers to include and execute arbitrar
23RISCO
abrir ↗Referência
CVE-2021-3186
A Stored Cross-site scripting (XSS) vulnerability in /main.html Wifi Settings in Tenda AC5 AC1200 version V15.03.06.47_m
23RISCO
abrir ↗Referência
CVE-2017-17649
Readymade Video Sharing Script 3.2 has HTML Injection via the single-video-detail.php comment parameter.
23RISCO
abrir ↗Referência
CVE-2018-15884
RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
23RISCO
abrir ↗Referência
CVE-2018-15884
RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
23RISCO
abrir ↗Referência
CVE-2009-4118
The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0
23RISCO
abrir ↗Referência
CVE-2018-16252
FsPro Labs Event Log Explorer 4.6.1.2115 has ".elx" FileType XML External Entity Injection.
23RISCO
abrir ↗Referência
CVE-2019-13657
CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that
48RISCO
abrir ↗Referência
CVE-2019-13657
CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that
48RISCO
abrir ↗Referência
CVE-2013-7193
Multiple SQL injection vulnerabilities in C2C Forward Auction Creator 2.0 allow remote attackers to execute arbitrary SQ
23RISCO
abrir ↗Referência✓ VexDay Proof
ASP.NET w3wp - COM Components Remote Crash
Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM com
35RISCO
abrir ↗Referência✓ VexDay Proof
Mini Blog 1.0.1 - 'index.php' Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in index.php in Mini Blog 1.0.1 allow remote attackers to include and execu
23RISCO
abrir ↗Referência✓ VexDay Proof
AJ Auction - Authentication Bypass
AJ Square AJ Auction Pro Platinum Skin #1 sends a redirect but does not exit when it is called directly, which allows re
23RISCO
abrir ↗Referência
CVE-2026-40521
FrontAccounting < 2.4.20 Path Traversal RCE via attachment upload
41RISCO
abrir ↗Referência✓ VexDay Proof
Enthrallweb eClassifieds 1.0 - Remote User Pass Change
myprofile.asp in Enthrallweb eClassifieds does not properly validate the MM_recordId parameter during profile updates, w
23RISCO
abrir ↗Referência✓ VexDay Proof
Tuned Studios Templates - Local File Inclusion
Multiple directory traversal vulnerabilities in index.php in Tuned Studios (1) Subwoofer, (2) Freeze Theme, (3) Orange C
23RISCO
abrir ↗Referência
CVE-2012-6044
M-Player 0.4 allows remote attackers to cause a denial of service (crash) via a crafted MP3 file.
23RISCO
abrir ↗Referência
CVE-2018-7176
FrontAccounting 2.4.3 suffers from a CSRF flaw, which leads to adding a user account via admin/users.php (aka the "add u
23RISCO
abrir ↗Referência
CVE-2013-6936
Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletin
23RISCO
abrir ↗Referência
CVE-2013-6936
Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletin
23RISCO
abrir ↗Referência
CVE-2017-9415
Cross-site request forgery (CSRF) vulnerability in subsonic 6.1.1 allows remote attackers with knowledge of the target u
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.