Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
22.936 exploits
ReferênciaVexDay Proof
Ajax File Browser 3b - 'settings.inc.php?approot' Remote File Inclusion
CVE-2007-4921webappsphp
PHP remote file inclusion vulnerability in _includes/settings.inc.php in Ajax File Browser 3 Beta allows remote attacker
35RISCO
abrir
ReferênciaVexDay Proof
KwsPHP Module jeuxflash 1.0 - 'id' SQL Injection
CVE-2007-4922webappsphp
SQL injection vulnerability in play.php in the jeuxflash 1.0 module for KwsPHP allows remote authenticated users to exec
23RISCO
abrir
ReferênciaVexDay Proof
Pilot Group eTraining - 'news_read.php' SQL Injection
CVE-2008-4709webappsphp
SQL injection vulnerability in news_read.php in Pilot Group (PG) eTraining allows remote attackers to execute arbitrary
23RISCO
abrir
Referência
CVE-2009-2400
SQL injection vulnerability in the PHP (com_php) component for Joomla! allows remote attackers to execute arbitrary SQL
23RISCO
abrir
Referência
CVE-2019-19609
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component Joomlaradio 5.0 - Remote File Inclusion
CVE-2007-4923webappsphp
PHP remote file inclusion vulnerability in admin.joomlaradiov5.php in the Joomla Radio 5 (com_joomlaradiov5) component f
35RISCO
abrir
ReferênciaVexDay Proof
Joovili 3.0 - Multiple SQL Injections
CVE-2008-4711webappsphp
SQL injection vulnerability in Joovili 3.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to ex
23RISCO
abrir
ReferênciaVexDay Proof
GO4I.NET ASP Forum 1.0 - SQL Injection
CVE-2008-6527webappsphp
SQL injection vulnerability in forum.asp in GO4I.NET ASP Forum 1.0 allows remote attackers to execute arbitrary SQL comm
23RISCO
abrir
Referência
CVE-2026-16083
Sipeed PicoClaw LINE Webhook line.go webhook.ParseRequest authentication replay
33RISCO
abrir
Referência
CVE-2026-16082
Sipeed PicoClaw pipeline_execute.go ExecTool.executeRun toctou
33RISCO
abrir
Referência
CVE-2026-16081
Sipeed PicoClaw auth.go cross-site request forgery
33RISCO
abrir
Referência
CVE-2026-16077
AstrBotDevs AstrBot Filesystem Computer-Use Tool fs.py _normalize_rw_path link following
33RISCO
abrir
Referência
CVE-2009-3361
SQL injection vulnerability in index.php in PHP-IPNMonitor allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
Referência
CVE-2009-3419
SQL injection vulnerability in index.php in the Publisher module 2.0 for Miniweb allows remote attackers to execute arbi
23RISCO
abrir
Referência
CVE-2016-3325
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted w
35RISCO
abrir
Referência
CVE-2017-11810
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Window
35RISCO
abrir
Referência
CVE-2018-8831
A Persistent XSS vulnerability exists in Kodi (formerly XBMC) through 17.6 that allows the execution of arbitrary HTML/s
35RISCO
abrir
Referência
CVE-2018-4233
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
68RISCO
abrir
Referência
CVE-2018-4233
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
68RISCO
abrir
Referência
CVE-2022-36267
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerabilit
35RISCO
abrir
ReferênciaVexDay Proof
212Cafe Board 0.07 - 'qID' SQL Injection
CVE-2008-4713webappsphp
SQL injection vulnerability in view.php in 212cafe Board 0.07 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Referência
CVE-2016-5312
Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote au
35RISCO
abrir
Referência
CVE-2024-9441
Linear eMerge e3-Series Forgot Password Command Injection
60RISCO
abrir
Referência
CVE-2013-0722
Stack-based buffer overflow in the scan_load_hosts function in ec_scan.c in Ettercap 0.7.5.1 and earlier might allow loc
23RISCO
abrir
Referência
CVE-2012-4329
The Samsung D6000 TV and possibly other products allow remote attackers to cause a denial of service (continuous restart
28RISCO
abrir
ReferênciaVexDay Proof
Microsoft Windows - '.chm' Denial of Service (HTML Compiled)
CVE-2009-0119doswindows
Buffer overflow in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (memory corruption and
35RISCO
abrir
ReferênciaVexDay Proof
MyioSoft Ajax Portal 3.0 - 'page' SQL Injection
CVE-2009-1509webappsphp
SQL injection vulnerability in ajaxp_backend.php in MyioSoft AjaxPortal 3.0 allows remote attackers to execute arbitrary
23RISCO
abrir
Referência
CVE-2019-6441
An issue was discovered on Shenzhen Coship RT3050 4.0.0.40, RT3052 4.0.0.48, RT7620 10.0.0.49, WM3300 5.0.0.54, and WM33
35RISCO
abrir
Referência
CVE-2019-6441
An issue was discovered on Shenzhen Coship RT3050 4.0.0.40, RT3052 4.0.0.48, RT7620 10.0.0.49, WM3300 5.0.0.54, and WM33
35RISCO
abrir
Referência
CVE-2011-4453
The PageListSort function in scripts/pagelist.php in PmWiki 2.x before 2.2.35 allows remote attackers to execute arbitra
50RISCO
abrir
anteriorpágina 68 / 765próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.