Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.445exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
21.497 exploits
Referência
CVE-2009-4656
Stack-based buffer overflow in E-Soft DJ Studio Pro 4.2 including 4.2.2.7.5, and 5.x including 5.1.4.3.1, allows user-as
50RISCO
abrir
ReferênciaVexDay Proof
Torbstoff News 4 - 'pfad' Remote File Inclusion
CVE-2006-4045webappsphp
PHP remote file inclusion vulnerability in news.php in Torbstoff News 4 allows remote attackers to execute arbitrary PHP
23RISCO
abrir
ReferênciaVexDay Proof
awrate.com Message Board 1.0 - 'search.php' Remote File Inclusion
CVE-2006-6368webappsphp
PHP remote file inclusion vulnerability in login.php.inc in awrate 1.0 allows remote attackers to execute arbitrary PHP
23RISCO
abrir
ReferênciaVexDay Proof
SasCam WebCam Server 2.6.5 - ActiveX Remote Buffer Overflow
CVE-2008-6898remotewindows
Buffer overflow in the XHTTP Module 4.1.0.0 in the ActiveX control for SaschArt SasCam Webcam Server 2.6.5 allows remote
50RISCO
abrir
ReferênciaVexDay Proof
Dokuwiki 2009-02-14 - Temporary/Remote File Inclusion
CVE-2009-1960webappsphp
inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote att
28RISCO
abrir
Referência
CVE-2014-3085
systest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote auth
23RISCO
abrir
Referência
CVE-2014-3085
systest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote auth
23RISCO
abrir
Referência
CVE-2015-0514
EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 might allow remote attackers to obtain cleartext data-cen
23RISCO
abrir
Referência
CVE-2009-5067
Directory traversal vulnerability in html2ps before 1.0b6 allows remote attackers to read arbitrary files via a .. (dot
23RISCO
abrir
Referência
CVE-2014-3740
Cross-site scripting (XSS) vulnerability in SpiceWorks before 7.2.00195 allows remote authenticated users to inject arbi
23RISCO
abrir
Referência
CVE-2016-7185
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
23RISCO
abrir
ReferênciaVexDay Proof
EnjoySAP ActiveX rfcguisink.rfcguisink.1 - Remote Heap Overflow (PoC)
CVE-2007-3606doswindows
Heap-based buffer overflow in the rfcguisink.rfcguisink.1 ActiveX control in the EnjoySAP SAP GUI, on systems using ASCI
23RISCO
abrir
Referência
CVE-2011-2963
TCPUploadServer.exe in Progea Movicon 11.2 before Build 1084 does not require authentication for critical functions, whi
23RISCO
abrir
Referência
CVE-2014-4306
Directory traversal vulnerability in logs-x.php in WebTitan before 4.04 allows remote attackers to read arbitrary files
23RISCO
abrir
ReferênciaVexDay Proof
jspwiki 2.4.104/2.5.139 - Multiple Vulnerabilities
CVE-2008-1231webappsjsp
Directory traversal vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to include and exec
23RISCO
abrir
Referência
CVE-2013-1807
PHP-Fusion before 7.02.06 stores backup files with predictable filenames in an unrestricted directory under the web docu
23RISCO
abrir
Referência
CVE-2018-18955
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RISCO
abrir
Referência
CVE-2011-5002
Multiple stack-based buffer overflows in Final Draft 8 before 8.02 allow remote attackers to execute arbitrary code via
23RISCO
abrir
Referência
CVE-2017-15920
In Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver contains a NULL pointer
23RISCO
abrir
Referência
CVE-2017-15920
In Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver contains a NULL pointer
23RISCO
abrir
ReferênciaVexDay Proof
PHP iCalendar 2.21 - 'cookie' Remote Code Execution
CVE-2006-1292webappsphp
Directory traversal vulnerability in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier allows remote attackers to in
23RISCO
abrir
Referência
CVE-2013-2225
inc/ticket.class.php in GLPI 0.83.9 and earlier allows remote attackers to unserialize arbitrary PHP objects via the _pr
23RISCO
abrir
Referência
CVE-2010-0375
SQL injection vulnerability in product_list.php in JCE-Tech PHP Calendars, downloaded 2010-01-11, allows remote attacker
23RISCO
abrir
Referência
CVE-2014-4874
BMC Track-It! 11.3.0.355 allows remote authenticated users to read arbitrary files by visiting the TrackItWeb/Attachment
23RISCO
abrir
ReferênciaVexDay Proof
NetWin Surgemail 3.8k4-4 - IMAP (Authenticated) Remote LIST Universal
CVE-2008-1498remotewindows
Stack-based buffer overflow in the IMAP service in NetWin Surgemail 3.8k4-4 and earlier allows remote authenticated user
23RISCO
abrir
Referência
CVE-2020-7384
Client-Side Command Injection in Rapid7 Metasploit
68RISCO
abrir
Referência
CVE-2018-10258
A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to
23RISCO
abrir
Referência
CVE-2018-10258
A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to
23RISCO
abrir
Referência
CVE-2017-6549
Session hijack vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W
23RISCO
abrir
Referência
CVE-2020-11803
An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter jaction when interacting with th
23RISCO
abrir
anteriorpágina 164 / 717próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.