Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
22.573 exploits
ReferênciaVexDay Proof
YourFreeWorld Classifieds - 'category' SQL Injection
CVE-2008-3755webappsphp
SQL injection vulnerability in view.php in YourFreeWorld Classifieds Script allows remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
YourFreeWorld Viral Marketing - SQL Injection
CVE-2008-3756webappsphp
SQL injection vulnerability in tr.php in YourFreeWorld Viral Marketing Script allows remote attackers to execute arbitra
23RISCO
abrir
ReferênciaVexDay Proof
VMware Workstation 6.5.1 - 'hcmon.sys 6.0.0.45731' Local Denial of Service
CVE-2008-3761doswindows
hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VM
23RISCO
abrir
Referência
CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
ReferênciaVexDay Proof
PHP Live Helper 2.0.1 - Multiple Vulnerabilities
CVE-2008-3762webappsphp
SQL injection vulnerability in onlinestatus_html.php in Turnkey PHP Live Helper 2.0.1 and earlier allows remote attacker
23RISCO
abrir
Referência
CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
Referência
CVE-2008-3765
SQL injection vulnerability in code.php in Quick Poll Script allows remote attackers to execute arbitrary SQL commands v
23RISCO
abrir
Referência
CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
Referência
CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
Referência
CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
Referência
CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
Referência
CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
Referência
CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
Referência
CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
Referência
CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
ReferênciaVexDay Proof
Quick Poll Script - 'id' SQL Injection
CVE-2008-3765webappsphp
SQL injection vulnerability in code.php in Quick Poll Script allows remote attackers to execute arbitrary SQL commands v
23RISCO
abrir
ReferênciaVexDay Proof
SunShop Shopping Cart 4.1.4 - 'id' SQL Injection
CVE-2008-3768webappsphp
Multiple SQL injection vulnerabilities in class.ajax.php in Turnkey Web Tools SunShop Shopping Cart before 4.1.5 allow r
23RISCO
abrir
ReferênciaVexDay Proof
Angel Lms 7.1 - 'default.asp?id' SQL Injection
CVE-2007-1250webappsasp
SQL injection vulnerability in section/default.asp in ANGEL Learning Management Suite (LMS) 7.1 allows remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
Pars4U Videosharing 1.0 - Cross-Site Scripting / Blind SQL Injection
CVE-2008-3772webappsphp
SQL injection vulnerability in categories_portal.php in Pars4u Videosharing 1 allows remote attackers to execute arbitra
23RISCO
abrir
ReferênciaVexDay Proof
WEBBDOMAIN Quiz 1.02 - Authentication Bypass
CVE-2008-6626webappsphp
SQL injection vulnerability in getin.php in WEBBDOMAIN Quiz 1.02 and earlier allows remote attackers to execute arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
MercuryBoard 1.1.5 - 'login.php' Blind SQL Injection
CVE-2008-6632webappsphp
SQL injection vulnerability in func/login.php in MercuryBoard 1.1.5 and earlier allows remote attackers to execute arbit
23RISCO
abrir
Referência
CVE-2019-19781
CVE-2019-19781CRITICALsob ataqueransomware
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISCO
abrir
Referência
CVE-2022-24716
Path traversal in Icinga Web 2
78RISCO
abrir
Referência
CVE-2018-15708
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP r
60RISCO
abrir
Referência
CVE-2018-15708
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP r
60RISCO
abrir
Referência
CVE-2017-5521
CVE-2017-5521HIGHsob ataque
An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R
100RISCO
abrir
Referência
CVE-2021-44228
CVE-2021-44228CRITICALsob ataqueransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISCO
abrir
Referência
CVE-2014-4977
Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute
60RISCO
abrir
ReferênciaVexDay Proof
Matterdaddy Market 1.1 - 'index.php' Multiple SQL Injections
CVE-2008-3783webappsphp
Multiple SQL injection vulnerabilities in index.php in Matterdaddy Market 1.1, when magic_quotes_gpc is disabled, allow
23RISCO
abrir
ReferênciaVexDay Proof
VideoLAN VLC Media Player 0.8.6i - Mms Protocol Handling Heap Overflow (PoC)
CVE-2008-3794dosmultiple
Integer signedness error in the mms_ReceiveCommand function in modules/access/mms/mmstu.c in VLC Media Player 0.8.6i all
28RISCO
abrir
anteriorpágina 20 / 753próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.