Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.526exploits catalogados
34.478CVEs com exploração pública
24.695testados em laboratório
21.534 exploits
ReferênciaVexDay Proof
Quantum Game Library 0.7.2c - Remote File Inclusion
CVE-2008-1069webappsphp
Multiple PHP remote file inclusion vulnerabilities in Quantum Game Library 0.7.2c allow remote attackers to execute arbi
28RISCO
abrir
ReferênciaVexDay Proof
HydraIrc 0.3.164 - Remote Denial of Service
CVE-2008-3578doswindows
HydraIRC 0.3.164 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and applicat
23RISCO
abrir
Referência
CVE-2017-6192
Buffer overflow in APNGDis 2.8 and earlier allows a remote attackers to cause denial of service and possibly execute arb
23RISCO
abrir
Referência
CVE-2017-6192
Buffer overflow in APNGDis 2.8 and earlier allows a remote attackers to cause denial of service and possibly execute arb
23RISCO
abrir
ReferênciaVexDay Proof
D-Link MPEG4 SHM Audio Control - 'VAPGDecoder.dll 1.7.0.5' Remote Buffer Overflow
CVE-2008-4771remotewindows
Stack-based buffer overflow in VATDecoder.VatCtrl.1 ActiveX control in (1) 4xem VatCtrl Class (VATDecoder.dll 1.0.0.27 a
23RISCO
abrir
ReferênciaVexDay Proof
Maxum Rumpus 6.0 - Multiple Remote Buffer Overflow Vulnerabilities
CVE-2008-7078doswindows
Multiple buffer overflows in Rumpus before 6.0.1 allow remote attackers to (1) cause a denial of service (segmentation f
23RISCO
abrir
ReferênciaVexDay Proof
Mini-stream Ripper - '.m3u' Local Stack Overflow (PoC)
CVE-2009-1325doswindows
Stack-based buffer overflow in Mini-stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long U
23RISCO
abrir
Referência
CVE-2010-0607
Cross-site scripting (XSS) vulnerability in Forms/status_statistics_1 in the Sterlite SAM300 AX Router allows remote att
23RISCO
abrir
Referência
CVE-2023-36346
POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parame
38RISCO
abrir
Referência
CVE-2010-0610
Multiple SQL injection vulnerabilities in the Photoblog (com_photoblog) component for Joomla! allow remote attackers to
23RISCO
abrir
Referência
CVE-2010-0610
Multiple SQL injection vulnerabilities in the Photoblog (com_photoblog) component for Joomla! allow remote attackers to
23RISCO
abrir
Referência
CVE-2010-0611
Multiple SQL injection vulnerabilities in adminlogin.php in Baal Systems 3.8 and earlier allow remote attackers to execu
23RISCO
abrir
Referência
CVE-2016-1001
Heap-based buffer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows an
28RISCO
abrir
Referência
CVE-2014-2994
Stack-based buffer overflow in Acunetix Web Vulnerability Scanner (WVS) 8 build 20120704 allows remote attackers to exec
28RISCO
abrir
Referência
CVE-2010-0611
Multiple SQL injection vulnerabilities in adminlogin.php in Baal Systems 3.8 and earlier allow remote attackers to execu
23RISCO
abrir
ReferênciaVexDay Proof
gCards 1.45 - Multiple Vulnerabilities
CVE-2006-1346webappsphp
Directory traversal vulnerability in inc/setLang.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
Pi3Web 2.0.3 - 'ISAPI' Remote Denial of Service
CVE-2008-6938doswindows
Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi
43RISCO
abrir
ReferênciaVexDay Proof
Mini-stream Ripper 3.0.1.1 - '.m3u' Universal Stack Overflow
CVE-2009-1325localwindows
Stack-based buffer overflow in Mini-stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long U
23RISCO
abrir
Referência
CVE-2015-2314
SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to execute arbitrary S
23RISCO
abrir
Referência
CVE-2010-4333
Pointter PHP Micro-Blogging Social Network 1.8 allows remote attackers to bypass authentication and obtain administrativ
23RISCO
abrir
Referência
CVE-2017-6351
The WePresent WiPG-1500 device with firmware 1.0.3.7 has a manufacturer account that has a hardcoded username / password
23RISCO
abrir
Referência
CVE-2014-2314
Directory traversal vulnerability in the Issue Collector plugin in Atlassian JIRA before 6.0.4 allows remote attackers t
43RISCO
abrir
Referência
CVE-2019-1913
Cisco Small Business 220 Series Smart Switches Remote Code Execution Vulnerabilities
53RISCO
abrir
Referência
CVE-2018-15152
Authentication bypass vulnerability in portal/account/register.php in versions of OpenEMR before 5.0.1.4 allows a remote
28RISCO
abrir
Referência
CVE-2023-30013
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/s
68RISCO
abrir
Referência
CVE-2017-16886
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact
23RISCO
abrir
Referência
CVE-2009-4531
httpdx 1.4.4 and earlier allows remote attackers to obtain the source code for a web page by appending a . (dot) charact
23RISCO
abrir
Referência
CVE-2014-5092
Status2k allows Remote Command Execution in admin/options/editpl.php.
23RISCO
abrir
Referência
CVE-2017-8652
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose in
28RISCO
abrir
Referência
CVE-2020-11804
An issue was discovered in Titan SpamTitan 7.07. Due to improper sanitization of the parameter quid, used in the page ma
23RISCO
abrir
anteriorpágina 181 / 718próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.