Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
20.003 exploits
Referência
CVE-2020-20277
There are multiple unauthenticated directory traversal vulnerabilities in different FTP commands in uftpd FTP server ver
28RISCO
abrir
Referência
CVE-2022-23046
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a su
28RISCO
abrir
Referência
CVE-2012-0896
Absolute path traversal vulnerability in download.php in the Count Per Day module before 3.1.1 for WordPress allows remo
43RISCO
abrir
Referência
CVE-2012-0896
Absolute path traversal vulnerability in download.php in the Count Per Day module before 3.1.1 for WordPress allows remo
43RISCO
abrir
Referência
Aztek Forum 4.00 - Cross-Site Scripting / SQL Injection
Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a long login value in a register form, which
23RISCO
abrir
Referência
CVE-2016-3216
GDI32.dll in the Graphics component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, W
28RISCO
abrir
Referência
Microsoft Office 2003 - '.PPT' Local Buffer Overflow (PoC)
PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record
28RISCO
abrir
Referência
Microsoft Word 2007 - Multiple Vulnerabilities
Buffer overflow in wwlib.dll in Microsoft Word 2007 allows remote attackers to cause a denial of service (application cr
28RISCO
abrir
Referência
CVE-2022-31854
Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin
50RISCO
abrir
Referência
CVE-2020-35948
An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated atta
53RISCO
abrir
Referência
CVE-2012-5863
Sinapsi eSolar OS Command Injection
53RISCO
abrir
Referência
CVE-2018-19864
NUUO NVRmini2 Network Video Recorder firmware through 3.9.1 allows remote attackers to execute arbitrary code or cause a
28RISCO
abrir
Referência
CVE-2022-3038
CVE-2022-3038HIGHsob ataque
Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially explo
76RISCO
abrir
Referência
CVE-2017-3061
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the SWF parser
28RISCO
abrir
Referência
CVE-2017-3076
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the MPEG-4 AVC
28RISCO
abrir
Referência
CVE-2019-13577
SnmpAdm.exe in MAPLE WBT SNMP Administrator v2.0.195.15 has an Unauthenticated Remote Buffer Overflow via a long string
28RISCO
abrir
Referência
Joomla! Component OnlineFlashQuiz 1.0.2 - Remote File Inclusion
PHP remote file inclusion vulnerability in quiz/common/db_config.inc.php in the Online FlashQuiz (com_onlineflashquiz) 1
28RISCO
abrir
Referência
Dragoon 0.1 - 'root' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/header.inc.php in Dragoon 0.1 allows remote attackers to execute arb
28RISCO
abrir
Referência
PhpBlock a8.4 - 'PATH_TO_CODE' Remote File Inclusion
PHP remote file inclusion vulnerability in modules/basicfog/basicfogfactory.class.php in PhpBlock A8.4 allows remote att
28RISCO
abrir
Referência
VMware - COM API ActiveX Remote Buffer Overflow (PoC)
Buffer overflow in a certain ActiveX control in the COM API in VMware Workstation 5.5.x before 5.5.8 build 108000, VMwar
28RISCO
abrir
Referência
Surgemail 39e-1 - (Authenticated) IMAP Remote Buffer Overflow (Denial of Service) (PoC)
Buffer overflow in the IMAP service in NetWin Surgemail 3.9e, and possibly other versions before 3.9g2, allows remote au
28RISCO
abrir
Referência
CVE-2017-15367
Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access
28RISCO
abrir
Referência
Joomla! Component Recly!Competitions 1.0.0 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in the Recly!Competitions (com_competitions) component 1.0 for Joomla
28RISCO
abrir
Referência
CVE-2021-46418
An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts.
43RISCO
abrir
Referência
CVE-2018-4934
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerability. Successful expl
28RISCO
abrir
Referência
CVE-2008-2789
SQL injection vulnerability in pages/index.php in BASIC-CMS allows remote attackers to execute arbitrary SQL commands vi
43RISCO
abrir
Referência
Basic-CMS - SQL Injection
SQL injection vulnerability in pages/index.php in BASIC-CMS allows remote attackers to execute arbitrary SQL commands vi
43RISCO
abrir
Referência
CVE-2011-1938
Stack-based buffer overflow in the socket_connect function in ext/sockets/sockets.c in PHP 5.3.3 through 5.3.6 might all
28RISCO
abrir
Referência
CVE-2017-17640
Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country pa
23RISCO
abrir
Referência
CVE-2018-19126
PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to execute arbitrary code via a file u
28RISCO
abrir
anteriorpágina 113 / 667próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.