Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
22.936 exploits
Referência
CVE-2009-3446
SQL injection vulnerability in the MyRemote Video Gallery (com_mytube) component 1.0 Beta for Joomla! allows remote atta
23RISCO
abrir
Referência
CVE-2010-1622
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote at
35RISCO
abrir
Referência
CVE-2019-13068
public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the
35RISCO
abrir
ReferênciaVexDay Proof
e107 Plugin alternate_profiles - 'id' SQL Injection
CVE-2008-4785webappsphp
SQL injection vulnerability in newuser.php in the alternate_profiles plugin, possibly 0.2, for e107 allows remote attack
23RISCO
abrir
Referência
CVE-2011-4075
The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary
50RISCO
abrir
Referência
CVE-2025-40552
SolarWinds Web Help Desk Authentication Bypass Vulnerability
75RISCO
abrir
Referência
CVE-2011-0522
The StripTags function in (1) the USF decoder (modules/codec/subtitles/subsdec.c) and (2) the Text decoder (modules/code
35RISCO
abrir
Referência
CVE-2014-9308
Unrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka Wor
50RISCO
abrir
Referência
CVE-2014-9308
Unrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka Wor
50RISCO
abrir
Referência
CVE-2013-1408
Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin before 2.2.1 for WordPress allow remote authenti
23RISCO
abrir
Referência
CVE-2017-8731
Microsoft Edge in Microsoft Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the
35RISCO
abrir
Referência
CVE-2016-2388
CVE-2016-2388MEDIUMsob ataque
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user infor
75RISCO
abrir
Referência
CVE-2016-2388
CVE-2016-2388MEDIUMsob ataque
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user infor
75RISCO
abrir
Referência
CVE-2016-2388
CVE-2016-2388MEDIUMsob ataque
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user infor
75RISCO
abrir
Referência
CVE-2016-8740
The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2
45RISCO
abrir
ReferênciaVexDay Proof
e107 Plugin EasyShop - 'category_id' Blind SQL Injection
CVE-2008-4786webappsphp
SQL injection vulnerability in easyshop.php in the EasyShop plugin for e107 allows remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
RoomPHPlanning 1.5 - 'idresa' SQL Injection
CVE-2008-6633webappsphp
SQL injection vulnerability in RoomPHPlanning 1.5 allows remote attackers to execute arbitrary SQL commands via the idre
23RISCO
abrir
Referência
CVE-2009-2638
SQL injection vulnerability in the AkoBook (com_akobook) component 2.3 for Joomla! allows remote attackers to execute ar
23RISCO
abrir
Referência
CVE-2015-1833
XML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6, 2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.
35RISCO
abrir
Referência
CVE-2015-1833
XML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6, 2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.
35RISCO
abrir
Referência
CVE-2024-7314
anji-plus AJ-Report Authentication Bypass
75RISCO
abrir
Referência
CVE-2024-7314
anji-plus AJ-Report Authentication Bypass
75RISCO
abrir
Referência
CVE-2024-7314
anji-plus AJ-Report Authentication Bypass
75RISCO
abrir
Referência
CVE-2017-8496
Microsoft Edge in Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the context of
35RISCO
abrir
Referência
CVE-2024-53676
A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution
60RISCO
abrir
Referência
CVE-2010-4052
Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3,
35RISCO
abrir
Referência
CVE-2018-14933
CVE-2018-14933CRITICALsob ataque
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir par
100RISCO
abrir
Referência
CVE-2016-0015
DirectShow in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
35RISCO
abrir
Referência
CVE-2022-0557
OS Command Injection in microweber/microweber
53RISCO
abrir
ReferênciaVexDay Proof
Microsoft Windows Wordpad - '.doc' File Local Denial of Service (PoC)
CVE-2008-4841doswindows
The WordPad Text Converter for Word 97 files in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows r
35RISCO
abrir
anteriorpágina 71 / 765próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.