Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.526exploits catalogados
34.478CVEs com exploração pública
24.695testados em laboratório
21.534 exploits
ReferênciaVexDay Proof
SmartSite CMS 1.0 - 'root' Remote File Inclusion
CVE-2006-3162webappsphp
PHP remote file inclusion vulnerability in include/inc_foot.php in SmartSiteCMS 1.0 and earlier allows remote attackers
23RISCO
abrir
Referência
CVE-2014-1637
Command School Student Management System 1.06.01 does not properly restrict access to sw/backup/backup_ray2.php, which a
23RISCO
abrir
ReferênciaVexDay Proof
GuppY 4.5.16 - Remote Command Execution
CVE-2007-0639webappsphp
Multiple static code injection vulnerabilities in error.php in GuppY 4.5.16 and earlier allow remote attackers to inject
23RISCO
abrir
ReferênciaVexDay Proof
Sun xVM VirtualBox < 1.6.4 - Privilege Escalation (PoC)
CVE-2008-3431HIGHsob ataquedosmultiple
The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communicat
71RISCO
abrir
ReferênciaVexDay Proof
DFLabs PTK 1.0 - Local Command Execution
CVE-2008-6793webappsphp
The get_file_type function in lib/file_content.php in DFLabs PTK 0.1, 0.2, and 1.0 allows remote attackers to execute ar
23RISCO
abrir
Referência
CVE-2014-2399
Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 2.2.2 allows remote attacker
23RISCO
abrir
Referência
CVE-2014-2399
Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 2.2.2 allows remote attacker
23RISCO
abrir
Referência
CVE-2011-3713
cFTP r80 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the
23RISCO
abrir
Referência
CVE-2011-3713
cFTP r80 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the
23RISCO
abrir
Referência
CVE-2017-0781
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RISCO
abrir
Referência
CVE-2010-2932
Buffer overflow in BarCodeWiz BarCode 3.29 ActiveX control (BarcodeWiz.dll) allows remote attackers to execute arbitrary
23RISCO
abrir
Referência
CVE-2009-3194
Cross-site scripting (XSS) vulnerability in index.php in JCE-Tech SearchFeed Script allows remote attackers to inject ar
23RISCO
abrir
Referência
CVE-2017-2464
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISCO
abrir
Referência
CVE-2021-22204
CVE-2021-22204MEDIUMsob ataque
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISCO
abrir
Referência
CVE-2010-2932
Buffer overflow in BarCodeWiz BarCode 3.29 ActiveX control (BarcodeWiz.dll) allows remote attackers to execute arbitrary
23RISCO
abrir
Referência
CVE-2021-22204
CVE-2021-22204MEDIUMsob ataque
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISCO
abrir
Referência
CVE-2021-22204
CVE-2021-22204MEDIUMsob ataque
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISCO
abrir
Referência
CVE-2009-0812
Stack-based buffer overflow in BreakPoint Software Hex Workshop 4.23, 6.0.1.4603, and other 6.x and earlier versions all
23RISCO
abrir
Referência
CVE-2009-3812
Heap-based buffer overflow in OtsAV DJ trial version 1.85.64.0, Radio trial version 1.85.64.0, TV trial version 1.85.64.
23RISCO
abrir
Referência
CVE-2009-3812
Heap-based buffer overflow in OtsAV DJ trial version 1.85.64.0, Radio trial version 1.85.64.0, TV trial version 1.85.64.
23RISCO
abrir
Referência
CVE-2018-6064
Type Confusion in the implementation of __defineGetter__ in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote
23RISCO
abrir
Referência
CVE-2023-5204
AI ChatBot <= 4.8.9 - Unauthenticated SQL Injection via qc_wpbo_search_response
63RISCO
abrir
Referência
CVE-2013-4093
The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote attackers to o
23RISCO
abrir
Referência
CVE-2016-1013
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows
28RISCO
abrir
ReferênciaVexDay Proof
News Rover 12.1 Rev 1 - Stack Overflow (1)
CVE-2007-1041localwindows
Multiple stack-based buffer overflows in S&H Computer Systems News Rover 12.1 Rev 1 allow remote attackers to execute ar
23RISCO
abrir
Referência
CVE-2016-0075
The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 160
23RISCO
abrir
Referência
CVE-2016-5309
The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP);
23RISCO
abrir
ReferênciaVexDay Proof
Hummingbird 13.0 - ActiveX Remote Buffer Overflow (PoC)
CVE-2008-4729doswindows
Stack-based buffer overflow in Hummingbird.XWebHostCtrl.1 ActiveX control (hclxweb.dll) in Hummingbird Xweb ActiveX Cont
23RISCO
abrir
Referência
CVE-2015-4683
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potenti
23RISCO
abrir
Referência
CVE-2015-4683
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potenti
23RISCO
abrir
anteriorpágina 180 / 718próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.