Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
22.721 exploits
Referência
CVE-2017-0146
CVE-2017-0146HIGHsob ataqueransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISCO
abrir
ReferênciaVexDay Proof
PHPRaider 1.0.7 - 'PHPbb3.functions.php' Remote File Inclusion
CVE-2008-2481webappsphp
PHP remote file inclusion vulnerability in authentication/phpbb3/phpbb3.functions.php in phpRaider 1.0.7 and 1.0.7a, whe
23RISCO
abrir
Referência
CVE-2022-44268
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISCO
abrir
ReferênciaVexDay Proof
Xomol CMS 1.2 - Authentication Bypass / Local File Inclusion
CVE-2008-2484webappsphp
SQL injection vulnerability in index.php in Xomol CMS 1.20071213, when magic_quotes_gpc is disabled, allows remote attac
23RISCO
abrir
Referência
Ericsson Network Location MPS GMPC21 - Remote Code Execution (RCE) (Metasploit)
CVE-2021-43339webappsmultiple
In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file
23RISCO
abrir
Referência
CVE-2024-13160
CVE-2024-13160CRITICALsob ataque
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
100RISCO
abrir
Referência
CVE-2025-37164
CVE-2025-37164CRITICALsob ataque
A remote code execution issue exists in HPE OneView.
100RISCO
abrir
Referência
CVE-2019-7195
CVE-2019-7195CRITICALsob ataqueransomware
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fi
100RISCO
abrir
Referência
CVE-2019-17621
CVE-2019-17621CRITICALsob ataque
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated rem
100RISCO
abrir
Referência
CVE-2018-4878
CVE-2018-4878HIGHsob ataqueransomware
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISCO
abrir
Referência
X.Org X Server 1.20.4 - Local Stack Overflow
CVE-2019-17624locallinux
"" In X.Org X Server 1.20.4, there is a stack-based buffer overflow in the function XQueryKeymap. For example, by sendin
23RISCO
abrir
ReferênciaVexDay Proof
CA Internet Security Suite 2008 - 'SaveToFile()' File Corruption (PoC)
CVE-2008-2511doswindows
Directory traversal vulnerability in the UmxEventCli.CachedAuditDataList.1 (aka UmxEventCliLib) ActiveX control in UmxEv
28RISCO
abrir
ReferênciaVexDay Proof
Mega File Hosting Script 1.2 - 'fid' SQL Injection
CVE-2008-2521webappsphp
SQL injection vulnerability in members.php in YABSoft Mega File Hosting Script (aka MFH or MFHS) 1.2 allows remote authe
23RISCO
abrir
ReferênciaVexDay Proof
Enrollment System Project v1.0 - SQL Injection Authentication Bypass (SQLI)
CVE-2023-33584CRITICALwebappsphp
Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to
53RISCO
abrir
Referência
CVE-2007-2821
SQL injection vulnerability in wp-admin/admin-ajax.php in WordPress before 2.2 allows remote attackers to execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
TutorialCMS 1.01 - Authentication Bypass
CVE-2007-2822webappsphp
TutorialCMS 1.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication via the
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Visual Basic 6.0 Project - Company Name Stack Overflow (PoC)
CVE-2007-2884doswindows
Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attackers to cause a denial
35RISCO
abrir
ReferênciaVexDay Proof
Microsoft Visual Basic 6.0 Project - Description Stack Overflow (PoC)
CVE-2007-2884doswindows
Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attackers to cause a denial
35RISCO
abrir
ReferênciaVexDay Proof
UltraISO 8.6.2.2011 - '.cue/'.bin' Local Buffer Overflow (PoC)
CVE-2007-2888doswindows
Stack-based buffer overflow in UltraISO 8.6.2.2011 and earlier allows user-assisted remote attackers to execute arbitrar
50RISCO
abrir
ReferênciaVexDay Proof
BP Blog 6.0 - 'id' Blind SQL Injection
CVE-2008-2554webappsasp
Multiple SQL injection vulnerabilities in BP Blog 6.0 allow remote attackers to execute arbitrary SQL commands via the (
23RISCO
abrir
ReferênciaVexDay Proof
Power Phlogger 2.2.5 - 'css_str' SQL Injection
CVE-2008-2562webappsphp
SQL injection vulnerability in edCss.php in PowerPhlogger 2.2.5 and earlier allows remote authenticated users to execute
23RISCO
abrir
Referência
CVE-2008-2565
Multiple SQL injection vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to execute arbitrary
23RISCO
abrir
Referência
CVE-2019-18818
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISCO
abrir
Referência
CVE-2019-18818
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISCO
abrir
ReferênciaVexDay Proof
Banner Management Script - 'id' SQL Injection
CVE-2008-3749webappsphp
SQL injection vulnerability in tr.php in YourFreeWorld Banner Management Script allows remote attackers to execute arbit
23RISCO
abrir
ReferênciaVexDay Proof
Angel Lms 7.1 - 'default.asp?id' SQL Injection
CVE-2007-1250webappsasp
SQL injection vulnerability in section/default.asp in ANGEL Learning Management Suite (LMS) 7.1 allows remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
WEBBDOMAIN Quiz 1.02 - Authentication Bypass
CVE-2008-6626webappsphp
SQL injection vulnerability in getin.php in WEBBDOMAIN Quiz 1.02 and earlier allows remote attackers to execute arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
MercuryBoard 1.1.5 - 'login.php' Blind SQL Injection
CVE-2008-6632webappsphp
SQL injection vulnerability in func/login.php in MercuryBoard 1.1.5 and earlier allows remote attackers to execute arbit
23RISCO
abrir
Referência
CVE-2008-2566
Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to inje
23RISCO
abrir
ReferênciaVexDay Proof
PHP-Address Book 3.1.5 - SQL Injection / Cross-Site Scripting
CVE-2008-2566webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to inje
23RISCO
abrir
anteriorpágina 10 / 758próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.