Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.101exploits catalogados
35.950CVEs com exploração pública
24.695testados em laboratório
22.640 exploits
Referência
CVE-2018-0492
Johnathan Nightingale beep through 1.3.4, if setuid, has a race condition that allows local privilege escalation.
23RISCO
abrir
Referência
CVE-2012-5917
SnackAmp 3.1.3 allows remote attackers to cause a denial of service (application crash) via a long string in an aiff fil
23RISCO
abrir
ReferênciaVexDay Proof
BigACE 2.4 - Multiple Remote File Inclusions
CVE-2008-2520webappsphp
Multiple PHP remote file inclusion vulnerabilities in BigACE 2.4, when register_globals is enabled, allow remote attacke
23RISCO
abrir
Referência
CVE-2010-4145
Kisisel Radyo Script stores sensitive information under the web root with insufficient access control, which allows remo
23RISCO
abrir
Referência
CVE-2010-4145
Kisisel Radyo Script stores sensitive information under the web root with insufficient access control, which allows remo
23RISCO
abrir
ReferênciaVexDay Proof
Family Connections CMS 1.4 - Multiple SQL Injections
CVE-2008-2901webappsphp
Multiple SQL injection vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 1.4 allow remote authenticated user
23RISCO
abrir
Referência
CVE-2009-4626
Directory traversal vulnerability in menu.php in phpNagios 1.2.0 allows remote attackers to include and execute arbitrar
23RISCO
abrir
Referência
CVE-2021-3186
A Stored Cross-site scripting (XSS) vulnerability in /main.html Wifi Settings in Tenda AC5 AC1200 version V15.03.06.47_m
23RISCO
abrir
Referência
CVE-2017-17649
Readymade Video Sharing Script 3.2 has HTML Injection via the single-video-detail.php comment parameter.
23RISCO
abrir
Referência
CVE-2018-15884
RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
23RISCO
abrir
Referência
CVE-2018-15884
RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
23RISCO
abrir
Referência
CVE-2009-4118
The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0
23RISCO
abrir
Referência
CVE-2026-19036
Shibby Tomato wanoptions sub_40F88C os command injection
41RISCO
abrir
Referência
CVE-2018-16252
FsPro Labs Event Log Explorer 4.6.1.2115 has ".elx" FileType XML External Entity Injection.
23RISCO
abrir
Referência
CVE-2019-13657
CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that
48RISCO
abrir
Referência
CVE-2019-13657
CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that
48RISCO
abrir
Referência
CVE-2013-7193
Multiple SQL injection vulnerabilities in C2C Forward Auction Creator 2.0 allow remote attackers to execute arbitrary SQ
23RISCO
abrir
ReferênciaVexDay Proof
ASP.NET w3wp - COM Components Remote Crash
CVE-2006-1364doswindows
Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM com
35RISCO
abrir
ReferênciaVexDay Proof
Mini Blog 1.0.1 - 'index.php' Multiple Local File Inclusions
CVE-2008-5594webappsphp
Multiple directory traversal vulnerabilities in index.php in Mini Blog 1.0.1 allow remote attackers to include and execu
23RISCO
abrir
ReferênciaVexDay Proof
AJ Auction - Authentication Bypass
CVE-2008-6966webappsphp
AJ Square AJ Auction Pro Platinum Skin #1 sends a redirect but does not exit when it is called directly, which allows re
23RISCO
abrir
Referência
CVE-2026-40521
FrontAccounting < 2.4.20 Path Traversal RCE via attachment upload
41RISCO
abrir
ReferênciaVexDay Proof
Enthrallweb eClassifieds 1.0 - Remote User Pass Change
CVE-2006-6822webappsasp
myprofile.asp in Enthrallweb eClassifieds does not properly validate the MM_recordId parameter during profile updates, w
23RISCO
abrir
ReferênciaVexDay Proof
Tuned Studios Templates - Local File Inclusion
CVE-2008-0231webappsphp
Multiple directory traversal vulnerabilities in index.php in Tuned Studios (1) Subwoofer, (2) Freeze Theme, (3) Orange C
23RISCO
abrir
Referência
CVE-2012-6044
M-Player 0.4 allows remote attackers to cause a denial of service (crash) via a crafted MP3 file.
23RISCO
abrir
Referência
CVE-2018-7176
FrontAccounting 2.4.3 suffers from a CSRF flaw, which leads to adding a user account via admin/users.php (aka the "add u
23RISCO
abrir
Referência
CVE-2013-6936
Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletin
23RISCO
abrir
Referência
CVE-2013-6936
Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletin
23RISCO
abrir
Referência
CVE-2017-9415
Cross-site request forgery (CSRF) vulnerability in subsonic 6.1.1 allows remote attackers with knowledge of the target u
23RISCO
abrir
Referência
CVE-2012-10040
Openfiler v2.x NetworkCard Command Execution
63RISCO
abrir
Referência
CVE-2012-10040
Openfiler v2.x NetworkCard Command Execution
63RISCO
abrir
anteriorpágina 626 / 755próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.