Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
22.573 exploits
Referência
CVE-2011-5003
Stack-based buffer overflow in the Phonetic Indexer (AvidPhoneticIndexer.exe) in Avid Media Composer 5.5.3 and earlier a
50RISCO
abrir
Referência
CVE-2011-5165
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RISCO
abrir
ReferênciaVexDay Proof
Microsoft Windows XP/2003 - IGMP v3 Denial of Service (MS06-007) (1)
CVE-2006-0021doswindows
Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang)
35RISCO
abrir
ReferênciaVexDay Proof
WordPress Plugin mygallery 1.4b4 - Remote File Inclusion
CVE-2007-2426webappsphp
PHP remote file inclusion vulnerability in myfunctions/mygallerybrowser.php in the myGallery 1.4b4 and earlier plugin fo
35RISCO
abrir
ReferênciaVexDay Proof
The Recipe Script 5 - Authentication Bypass / Database Backup
CVE-2009-1662webappsphp
Multiple SQL injection vulnerabilities in admin/login.php in Wright Way Services Recipe Script 5 allow remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
XOOPS Module cjay content 3 - Remote File Inclusion
CVE-2007-3220webappsphp
PHP remote file inclusion vulnerability in admin/editor2/spaw_control.class.php in the Cjay Content 3 module for XOOPS a
35RISCO
abrir
ReferênciaVexDay Proof
PHPNews 0.93 - 'format_menue' Remote File Inclusion
CVE-2007-4232webappsphp
PHP remote file inclusion vulnerability in admin/inc/change_action.php in Andreas Robertz PHPNews 0.93 allows remote att
35RISCO
abrir
Referência
CVE-2009-3209
SQL injection vulnerability in remove.php in PHP eMail Manager 3.3.0 allows remote attackers to execute arbitrary SQL co
23RISCO
abrir
Referência
CVE-2014-3888
Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM V
50RISCO
abrir
Referência
CVE-2014-3888
Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM V
50RISCO
abrir
ReferênciaVexDay Proof
Social Groupie - 'id' SQL Injection
CVE-2008-6358webappsphp
SQL injection vulnerability in group_index.php in Social Groupie allows remote attackers to execute arbitrary SQL comman
23RISCO
abrir
ReferênciaVexDay Proof
DesignWorks Professional 4.3.1 - '.CCT' File Local Stack Buffer Overflow (PoC)
CVE-2008-6363doswindows
Stack-based buffer overflow in DesignWorks Professional 4.3.1 and 5.0.7 allows remote attackers to execute arbitrary cod
23RISCO
abrir
Referência
CVE-2017-6622
A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote a
35RISCO
abrir
Referência
CVE-2008-6364
SQL injection vulnerability in logon_process.jsp in Ad Server Solutions Banner Exchange Solution Java allows remote atta
23RISCO
abrir
Referência
CVE-2023-28503
Authentication bypass in UniRPC's udadmin service
75RISCO
abrir
Referência
CVE-2018-8384
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RISCO
abrir
ReferênciaVexDay Proof
my-colex 1.4.2 - Authentication Bypass / SQL Injection / Cross-Site Scripting
CVE-2009-1809webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in myColex 1.4.2 allow remote attackers to inject arbitrary web scri
23RISCO
abrir
Referência
CVE-2019-6447
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISCO
abrir
ReferênciaVexDay Proof
CHILKAT ASP String - 'CkString.dll 1.1 SaveToFile()' Insecure Method
CVE-2007-4252remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in CkString.dll 1.1 and earlier in CHILKAT ASP String
23RISCO
abrir
Referência
CVE-2013-0135
Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL command
23RISCO
abrir
Referência
WordPress Core 5.8.2 - 'WP_Query' SQL Injection
CVE-2022-21661HIGHwebappsphp
SQL injection in WordPress
78RISCO
abrir
Referência
CVE-2015-5477
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RISCO
abrir
ReferênciaVexDay Proof
Active Web Helpdesk 2 - 'categoryId' Blind SQL Injection
CVE-2008-6380webappsphp
SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL
23RISCO
abrir
Referência
CVE-2009-4660
Stack-based buffer overflow in the AntServer Module (AntServer.exe) in BigAnt IM Server 2.50 allows remote attackers to
50RISCO
abrir
Referência
CVE-2015-1793
The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly
50RISCO
abrir
ReferênciaVexDay Proof
Quick Tree View .NET 3.1 - Database Disclosure
CVE-2008-6387webappsphp
Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows
23RISCO
abrir
Referência
CVE-2025-34152
Shenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via Time Parameter
75RISCO
abrir
Referência
CVE-2016-1209
The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via
50RISCO
abrir
Referência
CVE-2017-8835
SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw
50RISCO
abrir
Referência
CVE-2015-3306
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISCO
abrir
anteriorpágina 13 / 753próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.