Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
22.573 exploits
ReferênciaVexDay Proof
Acoustica Beatcraft 1.02 Build 19 - '.bcproj' Local Buffer Overflow
CVE-2008-4087localwindows
Stack-based buffer overflow in Acoustica Beatcraft 1.02 Build 19 allows user-assisted attackers to cause a denial of ser
23RISCO
abrir
ReferênciaVexDay Proof
Yourownbux 3.1/3.2 Beta - SQL Injection
CVE-2008-4093webappsphp
SQL injection vulnerability in memberstats.php in YourOwnBux 3.1 and 3.2 beta, when magic_quotes_gpc is disabled, allows
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Windows - 'WRITE_ANDX' SMB Command Handling Kernel Denial of Service (Metasploit)
CVE-2008-4114doswindows
srv.sys in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1
50RISCO
abrir
ReferênciaVexDay Proof
Zeeways ZeeJobsite 2.0 - Arbitrary File Upload
CVE-2008-6913webappsphp
Unrestricted file upload vulnerability in editresume_next.php in Zeeways ZEEJOBSITE 2.0 allows remote authenticated user
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component Content 1.0.0 - 'itemID' SQL Injection
CVE-2008-6923webappsphp
SQL injection vulnerability in the content component (com_content) 1.0.0 for Joomla! allows remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
Nokia e90/n82 (s60v3) - Remote Denial of Service
CVE-2008-4135doshardware
Symbian OS S60 3rd edition on the Nokia E90 Communicator 07.40.1.2 Ra-6 and Nseries N82 allows remote attackers to cause
23RISCO
abrir
ReferênciaVexDay Proof
The Personal FTP Server 6.0f - RETR Denial of Service
CVE-2008-4136doswindows
Michael Roth Software Personal FTP Server (PFT) 6.0f allows remote attackers to cause a denial of service (service crash
23RISCO
abrir
ReferênciaVexDay Proof
X10media Mp3 Search Engine 1.5.5 - Remote File Inclusion
CVE-2008-4141webappsphp
Multiple PHP remote file inclusion vulnerabilities in x10Media x10 Automatic MP3 Script 1.5.5 allow remote attackers to
23RISCO
abrir
Referência
CVE-2018-1000115
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vuln
60RISCO
abrir
Referência
CVE-2018-1000115
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vuln
60RISCO
abrir
ReferênciaVexDay Proof
E-PHP CMS - 'article.php' SQL Injection
CVE-2008-4142webappsphp
SQL injection vulnerability in article.php in E-Php CMS allows remote attackers to execute arbitrary SQL commands via th
23RISCO
abrir
ReferênciaVexDay Proof
addalink 4 - 'category_id' SQL Injection
CVE-2008-4145webappsphp
SQL injection vulnerability in user_read_links.php in Addalink 1.0 beta 4 and earlier, when magic_quotes_gpc is disabled
23RISCO
abrir
Referência
CVE-2012-2109
SQL injection vulnerability in wp-load.php in the BuddyPress plugin 1.5.x before 1.5.5 of WordPress allows remote attack
23RISCO
abrir
Referência
CVE-2024-13161
CVE-2024-13161CRITICALsob ataque
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
100RISCO
abrir
Referência
CVE-2020-8193
CVE-2020-8193MEDIUMsob ataque
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14
100RISCO
abrir
Referência
CVE-2020-3243
Multiple Vulnerabilities in Cisco UCS Director and Cisco UCS Director Express for Big Data
85RISCO
abrir
ReferênciaVexDay Proof
Diesel Joke Site - 'picture_category.php' SQL Injection
CVE-2008-4150webappsphp
SQL injection vulnerability in picture_category.php in Diesel Joke Site allows remote attackers to execute arbitrary SQL
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component mosmedia 1.0.8 - Remote File Inclusion
CVE-2007-2043webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia (com_mosmedia) 1.08 and earlier
23RISCO
abrir
Referência
CVE-2022-37042
CVE-2022-37042CRITICALsob ataqueransomware
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts fi
100RISCO
abrir
Referência
CVE-2019-7192
CVE-2019-7192CRITICALsob ataqueransomware
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix the
100RISCO
abrir
Referência
CVE-2012-2115
SQL injection vulnerability in interface/login/validateUser.php in OpenEMR 4.1.0 and possibly earlier allows remote atta
23RISCO
abrir
Referência
CVE-2012-2122
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x befor
60RISCO
abrir
Referência
CVE-2021-20837
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RISCO
abrir
Referência
CVE-2021-20837
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RISCO
abrir
ReferênciaVexDay Proof
CYASK 3.x - 'neturl' Local File Disclosure
CVE-2008-4151webappsphp
Directory traversal vulnerability in collect.php in CYASK 3.x allows remote attackers to read arbitrary files via a .. (
23RISCO
abrir
Referência
CVE-2020-35729
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
60RISCO
abrir
Referência
CVE-2017-17411
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authe
60RISCO
abrir
ReferênciaVexDay Proof
CustomCMS 4.0 - 'print.php' SQL Injection
CVE-2008-4156webappsphp
SQL injection vulnerability in print.php in CustomCms (CCMS) Gaming Portal 4.0, when magic_quotes_gpc is disabled, allow
23RISCO
abrir
ReferênciaVexDay Proof
Zanfi CMS lite / Jaw Portal free - 'page' SQL Injection
CVE-2008-4159webappsphp
SQL injection vulnerability in index.php in Jaw Portal and Zanfi CMS lite and allows remote attackers to execute arbitra
23RISCO
abrir
ReferênciaVexDay Proof
Collabtive 0.4.8 - Cross-Site Scripting / Authentication Bypass / Arbitrary File Upload
CVE-2008-6947webappsphp
Collabtive 0.4.8 allows remote attackers to bypass authentication and create new users, including administrators, via un
23RISCO
abrir
anteriorpágina 12 / 753próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.