Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.445exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
21.497 exploits
Referência
CVE-2010-1726
SQL injection vulnerability in offers_buy.php in EC21 Clone 3.0 allows remote attackers to execute arbitrary SQL command
23RISCO
abrir
Referência
CVE-2009-4549
Stack-based buffer overflow in A2 Media Player Pro 2.51 allows remote attackers to execute arbitrary code via a long str
23RISCO
abrir
Referência
CVE-2014-5200
SQL injection vulnerability in game_play.php in the FB Gorilla plugin for WordPress allows remote attackers to execute a
23RISCO
abrir
Referência
CVE-2013-4098
ServerAdmin/ErrorViewer.jsp in DS3 Authentication Server allow remote attackers to inject arbitrary error-page text via
23RISCO
abrir
Referência
CVE-2012-5347
TinyWebGallery 1.8.3 allows remote attackers to execute arbitrary code via shell metacharacters in the command parameter
23RISCO
abrir
Referência
CVE-2018-1002000
There is blind SQL injection in WordPress Arigato Autoresponder and Newsletter v2.5.1.8 These vulnerabilities require ad
23RISCO
abrir
Referência
CVE-2023-1826
SourceCodester Online Computer and Laptop Store index.php unrestricted upload
33RISCO
abrir
Referência
CVE-2018-17784
Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthentic
23RISCO
abrir
ReferênciaVexDay Proof
PrecisionID Barcode ActiveX 1.9 - Arbitrary File Overwrite
CVE-2007-2755remotewindows
The PrecisionID Barcode 1.9 ActiveX control in PrecisionID_Barcode.dll, when Internet Explorer 6 is used, allows remote
23RISCO
abrir
ReferênciaVexDay Proof
Airsensor M520 - HTTPd Remote Denial of Service / Buffer Overflow (PoC)
CVE-2007-5036doshardware
Multiple buffer overflows in the AirDefense Airsensor M520 with firmware 4.3.1.1 and 4.4.1.4 allow remote authenticated
23RISCO
abrir
ReferênciaVexDay Proof
IPSwitch IMail Server 8.0x - Remote Heap Overflow
CVE-2007-5094remotewindows
Heap-based buffer overflow in iaspam.dll in the SMTP Server in Ipswitch IMail Server 8.01 through 8.11 allows remote att
23RISCO
abrir
ReferênciaVexDay Proof
Grabit 1.7.2 Beta 3 - '.nzb' Local Buffer Overflow (SEH)
CVE-2009-1586localwindows
Stack-based buffer overflow in the NZB importer feature in GrabIt 1.7.2 Beta 3 and earlier allows remote attackers to ex
23RISCO
abrir
Referência
CVE-2011-4899
wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not ensure that the specifie
23RISCO
abrir
Referência
CVE-2019-0730
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RISCO
abrir
Referência
CVE-2010-1726
SQL injection vulnerability in offers_buy.php in EC21 Clone 3.0 allows remote attackers to execute arbitrary SQL command
23RISCO
abrir
Referência
CVE-2019-0730
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RISCO
abrir
Referência
CVE-2019-0731
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RISCO
abrir
Referência
CVE-2010-4233
The Linux installation on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1
23RISCO
abrir
Referência
CVE-2019-14749
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the ex
23RISCO
abrir
Referência
CVE-2017-6803
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly
23RISCO
abrir
Referência
CVE-2017-6803
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly
23RISCO
abrir
Referência
CVE-2010-1727
SQL injection vulnerability in type.asp in JobPost 1.0 allows remote attackers to execute arbitrary SQL commands via the
23RISCO
abrir
Referência
CVE-2017-8665
The Xamarin.iOS update component on systems running macOS allows an attacker to run arbitrary code as root, aka "Xamarin
23RISCO
abrir
Referência
CVE-2024-25736
An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can restart the device via a /d
41RISCO
abrir
Referência
CVE-2013-5755
config/.htpasswd in Yealink IP Phone SIP-T38G has a hardcoded password of (1) user (s7C9Cx.rLsWFA) for the user account,
23RISCO
abrir
Referência
CVE-2014-5380
Grand MA 300 allows retrieval of the access PIN from sniffed data.
23RISCO
abrir
ReferênciaVexDay Proof
PA168 Chipset IP Phones - Weak Session Management
CVE-2007-0528remotehardware
The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and ear
23RISCO
abrir
ReferênciaVexDay Proof
Remote Display Dev kit 1.2.1.0 - 'RControl.dll' Denial of Service
CVE-2007-2623doswindows
Multiple buffer overflows in RControl.dll in Remote Display Dev kit 1.2.1.0 allow remote attackers to cause a denial of
23RISCO
abrir
ReferênciaVexDay Proof
EB Design Pty Ltd - 'EBCRYPT.dll 2.0' Multiple Remote Vulnerabilities
CVE-2007-5111remotewindows
A certain ActiveX control in EBCRYPT.DLL 2.0 in EB Design ebCrypt allows remote attackers to cause a denial of service (
23RISCO
abrir
ReferênciaVexDay Proof
NEPT Image Uploader 1.0 - Arbitrary File Upload
CVE-2008-6822webappsphp
Unrestricted file upload vulnerability in uploadp.php in New Earth Programming Team (NEPT) imgupload (aka Image Uploader
23RISCO
abrir
anteriorpágina 162 / 717próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.