Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
22.936 exploits
Referência
CVE-2021-33353
Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows at
48RISCO
abrir
Referência
CVE-2007-6191
Multiple PHP remote file inclusion vulnerabilities in Armin Burger p.mapper 3.2.0 beta3 allow remote attackers to execut
23RISCO
abrir
Referência
CVE-2012-1613
Cross-site scripting (XSS) vulnerability in edit_one_pic.php in Coppermine Photo Gallery before 1.5.20 allows remote aut
23RISCO
abrir
Referência
CVE-2012-1613
Cross-site scripting (XSS) vulnerability in edit_one_pic.php in Coppermine Photo Gallery before 1.5.20 allows remote aut
23RISCO
abrir
Referência
CVE-2017-16962
The WebMail components (Crystal, pronto, and pronto4) in CommuniGate Pro before 6.2.1 have stored XSS vulnerabilities vi
23RISCO
abrir
Referência
CVE-2017-16962
The WebMail components (Crystal, pronto, and pronto4) in CommuniGate Pro before 6.2.1 have stored XSS vulnerabilities vi
23RISCO
abrir
ReferênciaVexDay Proof
TOWeLS 0.1 - 'scripture.php' Remote File Inclusion
CVE-2007-5628webappsphp
PHP remote file inclusion vulnerability in src/scripture.php in The Online Web Library Site (TOWels) 0.1 allows remote a
28RISCO
abrir
Referência
CVE-2011-4673
SQL injection vulnerability in modules/sharedaddy.php in the Jetpack plugin for WordPress allows remote attackers to exe
23RISCO
abrir
Referência
CVE-2026-10230
Assimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_animations heap-based overflow
33RISCO
abrir
Referência
CVE-2019-7004
Avaya IP Office XSS Vulnerability
33RISCO
abrir
ReferênciaVexDay Proof
CcMail 1.0.1 - Insecure Cookie Handling
CVE-2008-1904webappsphp
Cicoandcico CcMail 1.0.1 and earlier does not verify that the this_cookie cookie corresponds to an authenticated session
23RISCO
abrir
Referência
MyT Project Management 1.5.1 - User[username] Persistent Cross-Site Scripting
CVE-2019-13346webappsphp
In MyT 1.5.1, the User[username] parameter has XSS.
23RISCO
abrir
Referência
CVE-2010-0665
JAG (Just Another Guestbook) 1.14 stores sensitive information under the web root with insufficient access control, whic
23RISCO
abrir
Referência
CVE-2015-5287
CVE-2015-5287HIGHsob ataque
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain perm
86RISCO
abrir
ReferênciaVexDay Proof
Download Accelerator Plus DAP 8.x - '.m3u' File Buffer Overflow
CVE-2008-3182localwindows
Stack-based buffer overflow in DAP.exe in Download Accelerator Plus (DAP) 7.0.1.3, 8.6.6.3, and other 8.x versions allow
23RISCO
abrir
ReferênciaVexDay Proof
CCLeague Pro 1.2 - Insecure Cookie Authentication
CVE-2008-5125webappsphp
admin.php in CCleague Pro 1.2 allows remote attackers to bypass authentication by setting the type cookie value to admin
23RISCO
abrir
ReferênciaVexDay Proof
4Images 1.7.7 - Filter Bypass HTML Injection / Cross-Site Scripting
CVE-2009-2131webappsphp
Cross-site scripting (XSS) vulnerability in 4images 1.7.7 and earlier allows remote authenticated users to inject arbitr
23RISCO
abrir
Referência
CVE-2014-3857
Multiple SQL injection vulnerabilities in Kerio Control Statistics in Kerio Control (formerly WinRoute Firewall) before
23RISCO
abrir
Referência
CVE-2014-3857
Multiple SQL injection vulnerabilities in Kerio Control Statistics in Kerio Control (formerly WinRoute Firewall) before
23RISCO
abrir
Referência
CVE-2018-5976
Cross Site Request Forgery (CSRF) exists in RSVP Invitation Online 1.0 via function/account.php, as demonstrated by modi
23RISCO
abrir
Referência
CVE-2017-1000474
Soyket Chowdhury Vehicle Sales Management System version 2017-07-30 is vulnerable to multiple SQL Injecting in login/veh
23RISCO
abrir
Referência
CVE-2010-1498
Multiple SQL injection vulnerabilities in dl_stats before 2.0 allow remote attackers to execute arbitrary SQL commands v
23RISCO
abrir
Referência
CVE-2010-1498
Multiple SQL injection vulnerabilities in dl_stats before 2.0 allow remote attackers to execute arbitrary SQL commands v
23RISCO
abrir
ReferênciaVexDay Proof
Dokeos 1.6.5 - 'courseLog.php?scormcontopen' SQL Injection
CVE-2007-2889webappsphp
SQL injection vulnerability in tracking/courseLog.php in Dokeos 1.6.5 and earlier allows remote attackers to execute arb
23RISCO
abrir
ReferênciaVexDay Proof
PHPizabi 0.848b C1 HFP3 - Database Information Disclosure
CVE-2008-2018webappsphp
The AssignUser function in template.class.php in PHPizabi 0.848b C1 HFP3 performs unsafe macro expansions on strings del
23RISCO
abrir
Referência
CVE-2013-10054
LibrettoCMS File Manager Arbitrary File Upload
63RISCO
abrir
Referência
CVE-2013-10054
LibrettoCMS File Manager Arbitrary File Upload
63RISCO
abrir
Referência
CVE-2013-10054
LibrettoCMS File Manager Arbitrary File Upload
63RISCO
abrir
Referência
CVE-2012-4281
Multiple SQL injection vulnerabilities in Travelon Express 6.2.2 allow remote attackers to execute arbitrary SQL command
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component Pony Gallery 1.5 - SQL Injection
CVE-2007-4046webappsphp
SQL injection vulnerability in index.php in the Pony Gallery (com_ponygallery) 1.5 and earlier component for Joomla! all
23RISCO
abrir
anteriorpágina 65 / 765próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.