Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.445exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
20.025 exploits
Referência
CVE-2018-8619
A remote code execution vulnerability exists when the Internet Explorer VBScript execution policy does not properly rest
35RISCO
abrir
Referência
CVE-2011-2522
Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x befo
28RISCO
abrir
Referência
CVE-2018-12706
DIGISOL DG-BR4000NG devices have a Buffer Overflow via a long Authorization HTTP header.
28RISCO
abrir
Referência
CVE-2017-0263
CVE-2017-0263HIGHsob ataque
The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
76RISCO
abrir
Referência
CVE-2017-17999
SQL injection vulnerability in RISE Ultimate Project Manager 1.9 allows remote attackers to execute arbitrary SQL comman
23RISCO
abrir
Referência
PHP < 4.4.5/5.2.1 - 'shmop' Local Code Execution
The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspo
28RISCO
abrir
Referência
CVE-2017-5972
The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie protection mechanism for the case of a fa
28RISCO
abrir
Referência
PHP < 4.4.5/5.2.1 - 'shmop' SSL RSA Private-Key Disclosure
The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspo
28RISCO
abrir
Referência
AtomixMP3 < 2.3 - '.m3u' Local Buffer Overflow
Stack-based buffer overflow in AtomixMP3 2.3 and earlier allows remote attackers to execute arbitrary code via a long pa
28RISCO
abrir
Referência
CVE-2014-2223
Unrestricted file upload vulnerability in plog-admin/plog-upload.php in Plogger 1.0 RC1 and earlier allows remote authen
28RISCO
abrir
Referência
CVE-2014-2223
Unrestricted file upload vulnerability in plog-admin/plog-upload.php in Plogger 1.0 RC1 and earlier allows remote authen
28RISCO
abrir
Referência
CVE-2015-7245
Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remot
50RISCO
abrir
Referência
ActualAnalyzer - 'ant' Cookie Command Execution (Metasploit)
Actual Analyzer through 2014-08-29 allows code execution via shell metacharacters because untrusted input is used for pa
68RISCO
abrir
Referência
CVE-2018-20523
Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider
28RISCO
abrir
Referência
CA Internet Security Suite 2008 - 'SaveToFile()' File Corruption (PoC)
Directory traversal vulnerability in the UmxEventCli.CachedAuditDataList.1 (aka UmxEventCliLib) ActiveX control in UmxEv
28RISCO
abrir
Referência
Sugar Suite Open Source 4.2 - 'OptimisticLock' Command Execution
Sugar Suite Open Source (SugarCRM) 4.2 and earlier, when register_globals is enabled, does not protect critical variable
28RISCO
abrir
Referência
CVE-2018-19043
The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file renaming (specifying a "from" and "to" filename)
28RISCO
abrir
Referência
CVE-2018-19042
The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the di
28RISCO
abrir
Referência
CVE-2017-17417
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu
23RISCO
abrir
Referência
CVE-2021-34370
Accela Civic Platform through 20.1 allows ssoAdapter/logoutAction.do successURL XSS. NOTE: the vendor states "there are
38RISCO
abrir
Referência
CVE-2009-4427
Directory traversal vulnerability in cmd.php in phpLDAPadmin 1.1.0.5 allows remote attackers to include and execute arbi
23RISCO
abrir
Referência
KsIRC 1.3.12 - 'PRIVMSG' Remote Buffer Overflow (PoC)
KsIRC 1.3.12 allows remote attackers to cause a denial of service (crash) via a long PRIVMSG string when connecting to a
23RISCO
abrir
Referência
asg-sentry 7.0.0 - Multiple Vulnerabilities
The File Check Utility (fcheck.exe) in ASG-Sentry Network Manager 7.0.0 and earlier allows remote attackers to cause a d
23RISCO
abrir
Referência
CVE-2021-42580
Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/adm
23RISCO
abrir
Referência
CVE-2016-1464
Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to execute arbitrary code
23RISCO
abrir
Referência
CVE-2018-17961
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving err
23RISCO
abrir
Referência
CVE-2013-6283
VideoLAN VLC Media Player 2.0.8 and earlier allows remote attackers to cause a denial of service (crash) and possibly ex
23RISCO
abrir
Referência
CVE-2014-5109
SQL injection vulnerability in maint/modules/endpointcfg/endpoint_generic.php in Fonality trixbox allows remote attacker
23RISCO
abrir
Referência
PHP Simple Shop 2.0 - 'abs_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools PHP Simple Shop 2.0 and earlier allow remote att
28RISCO
abrir
Referência
NES Game and NES System c108122 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in NES Game and NES System c108122 and earlier allow remote attackers
28RISCO
abrir
anteriorpágina 156 / 668próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.