Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.137exploits catalogados
35.961CVEs com exploração pública
24.695testados em laboratório
22.657 exploits
Referência
CVE-2018-18308
In the 4.2.23 version of BigTree, a Stored XSS vulnerability has been discovered in /admin/ajax/file-browser/upload/ (ak
23RISCO
abrir
Referência
CVE-2018-18308
In the 4.2.23 version of BigTree, a Stored XSS vulnerability has been discovered in /admin/ajax/file-browser/upload/ (ak
23RISCO
abrir
Referência
CVE-2010-1307
Directory traversal vulnerability in the Magic Updater (com_joomlaupdater) component for Joomla! allows remote attackers
43RISCO
abrir
Referência
CVE-2023-33864
StreamReader::ReadFromExternal in RenderDoc before 1.27 allows an Integer Overflow with a resultant Buffer Overflow. It
48RISCO
abrir
Referência
CVE-2023-3843
mooSocial mooDating URL question cross site scripting
43RISCO
abrir
Referência
CVE-2010-1307
Directory traversal vulnerability in the Magic Updater (com_joomlaupdater) component for Joomla! allows remote attackers
43RISCO
abrir
Referência
CVE-2026-10212
AstrBotDevs AstrBot astr_main_agent.py astr_main_agent authorization
33RISCO
abrir
ReferênciaVexDay Proof
AuraCMS 2.1 - Remote File Attachment / Local File Inclusion
CVE-2007-4908webappsphp
Directory traversal vulnerability in index.php in AuraCMS 2.1 and earlier allows remote attackers to include and execute
23RISCO
abrir
Referência
CVE-2015-1701
CVE-2015-1701HIGHsob ataqueransomware
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local
98RISCO
abrir
Referência
CVE-2026-10188
Tenda W12 httpd cgistaKickOff stack-based overflow
41RISCO
abrir
ReferênciaVexDay Proof
Mercury/32 4.52 IMAPD - 'SEARCH' (Authenticated) Overflow
CVE-2007-5018remotewindows
Stack-based buffer overflow in IMAPD in Mercury/32 4.52 allows remote authenticated users to execute arbitrary code via
23RISCO
abrir
Referência
CVE-2015-5520
Cross-site scripting (XSS) vulnerability in the Users module in Orchard 1.7.3 through 1.8.2 and 1.9.x before 1.9.1 allow
23RISCO
abrir
Referência
CVE-2009-4563
Cross-site request forgery (CSRF) vulnerability in zp-core/admin-options.php in Zenphoto 1.2.5 allows remote attackers t
23RISCO
abrir
Referência
CVE-2026-10172
Bdtask Multi-Store Inventory Management System Component Module.php upload unrestricted upload
33RISCO
abrir
Referência
CVE-2017-6979
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
23RISCO
abrir
Referência
CVE-2026-10162
TRENDnet TEW-432BRP formSetPassword stack-based overflow
41RISCO
abrir
Referência
CVE-2026-10157
Open5GS NGAP PathSwitchRequest Message ngap-handler.c improper authentication
33RISCO
abrir
Referência
CVE-2009-4729
Multiple cross-site scripting (XSS) vulnerabilities in x10 Adult Media Script 1.7 allow remote attackers to inject arbit
23RISCO
abrir
Referência
CVE-2017-11176
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr
23RISCO
abrir
Referência
CVE-2016-4315
Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authenticatio
23RISCO
abrir
Referência
CVE-2008-6888
Cross-site scripting (XSS) vulnerability in signup.asp in Pre Classified Listings 1.0 allows remote attackers to inject
23RISCO
abrir
Referência
CVE-2016-1000123
Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla
23RISCO
abrir
Referência
CVE-2010-1312
Directory traversal vulnerability in the iJoomla News Portal (com_news_portal) component 1.5.x for Joomla! allows remote
43RISCO
abrir
Referência
CVE-2010-1313
Directory traversal vulnerability in the Seber Cart (com_sebercart) component 1.0.0.12 and 1.0.0.13 for Joomla!, when ma
38RISCO
abrir
ReferênciaVexDay Proof
LunarPoll 1.0 - 'show.php?PollDir' Remote File Inclusion
CVE-2007-0298webappsphp
PHP remote file inclusion vulnerability in show.php in LunarPoll, when register_globals is enabled, allows remote attack
23RISCO
abrir
ReferênciaVexDay Proof
Sciurus Hosting Panel - Remote Code Injection
CVE-2007-6082webappsphp
Direct static code injection vulnerability in acp/savenews.php in Sciurus Hosting Panel, possibly 2.0.3, allows remote a
23RISCO
abrir
ReferênciaVexDay Proof
Gradman 0.1.3 - 'agregar_info.php' Local File Inclusion
CVE-2008-0361webappsphp
Directory traversal vulnerability in agregar_info.php in GradMan 0.1.3 and earlier allows remote attackers to include an
23RISCO
abrir
Referência
CVE-2022-3634
Contact Form 7 Database Addon < 1.2.6.5 - CSV Injection
48RISCO
abrir
Referência
CVE-2018-6941
A /shell?cmd= CSRF issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remot
23RISCO
abrir
Referência
CVE-2026-10061
TRENDnet TEW-432BRP formWPS command injection
33RISCO
abrir
anteriorpágina 638 / 756próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.