Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.589exploits catalogados
34.508CVEs com exploração pública
24.695testados em laboratório
21.554 exploits
Referência
CVE-2014-4311
Epicor Enterprise 7.4 before FS74SP6_HotfixTL054181 allows attackers to obtain the (1) Database Connection and (2) E-mai
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component Flash Image Gallery - Remote File Inclusion
CVE-2007-5309webappsphp
PHP remote file inclusion vulnerability in admin.wmtgallery.php in the webmaster-tips.net Flash Image Gallery (com_wmtga
23RISCO
abrir
ReferênciaVexDay Proof
Myspace Clone Script - 'index.php' Remote File Inclusion
CVE-2007-6057webappsphp
PHP remote file inclusion vulnerability in index.php in datecomm Social Networking Script (aka Myspace Clone Script) all
23RISCO
abrir
ReferênciaVexDay Proof
TUTOS 1.3 - 'cmd.php' Remote Command Execution
CVE-2008-0148webappsphp
TUTOS 1.3 does not restrict access to php/admin/cmd.php, which allows remote attackers to execute arbitrary shell comman
23RISCO
abrir
ReferênciaVexDay Proof
asg-sentry 7.0.0 - Multiple Vulnerabilities
CVE-2008-1320dosmultiple
Multiple buffer overflows in ASG-Sentry Network Manager 7.0.0 and earlier allow remote attackers to execute arbitrary co
28RISCO
abrir
ReferênciaVexDay Proof
Getleft 1.2 - Remote Buffer Overflow (PoC)
CVE-2008-6897dosmultiple
Multiple buffer overflows in Getleft.exe in Andres Garcia Getleft 1.2 allow remote attackers to cause a denial of servic
23RISCO
abrir
Referência
CVE-2023-0232
ShopLentor < 2.5.4 - PHP Object Injection
48RISCO
abrir
Referência
CVE-2014-7226
The file comment feature in Rejetto HTTP File Server (hfs) 2.3c and earlier allows remote attackers to execute arbitrary
23RISCO
abrir
Referência
CVE-2014-7226
The file comment feature in Rejetto HTTP File Server (hfs) 2.3c and earlier allows remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
Ottoman CMS 1.1.3 - '?default_path=' Remote File Inclusion (1)
CVE-2006-2767webappsphp
PHP remote file inclusion vulnerability in Ottoman 1.1.2, when register_globals is enabled, allows remote attackers to e
23RISCO
abrir
Referência
CVE-2021-34684
Hitachi Vantara Pentaho Business Analytics through 9.1 allows an unauthenticated user to execute arbitrary SQL queries o
48RISCO
abrir
Referência
CVE-2017-5496
Sawmill Enterprise 8.7.9 allows remote attackers to gain login access by leveraging knowledge of a password hash.
23RISCO
abrir
Referência
CVE-2017-5496
Sawmill Enterprise 8.7.9 allows remote attackers to gain login access by leveraging knowledge of a password hash.
23RISCO
abrir
Referência
CVE-2010-0974
Multiple SQL injection vulnerabilities in PHPCityPortal allow remote attackers to execute arbitrary SQL commands via the
23RISCO
abrir
Referência
CVE-2010-0974
Multiple SQL injection vulnerabilities in PHPCityPortal allow remote attackers to execute arbitrary SQL commands via the
23RISCO
abrir
Referência
CVE-2013-7280
Buffer overflow in HansoTools Hanso Player 2.1.0, 2.5.0, and earlier allows remote attackers to cause a denial of servic
23RISCO
abrir
Referência
CVE-2013-7280
Buffer overflow in HansoTools Hanso Player 2.1.0, 2.5.0, and earlier allows remote attackers to cause a denial of servic
23RISCO
abrir
ReferênciaVexDay Proof
jetAudio 7.x - '.m3u' Local Overwrite (SEH)
CVE-2007-5487localwindows
Stack-based buffer overflow in COWON America jetAudio Basic 7.0.3 allows user-assisted remote attackers to execute arbit
23RISCO
abrir
ReferênciaVexDay Proof
Debian OpenSSH - (Authenticated) Remote SELinux Privilege Escalation
CVE-2008-3234remotelinux
sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain ac
23RISCO
abrir
ReferênciaVexDay Proof
Discuz! 6.x/7.x - Remote Code Execution
CVE-2008-6958webappsphp
wap/index.php in Crossday Discuz! Board 6.x and 7.x allows remote authenticated users to execute arbitrary PHP code via
23RISCO
abrir
Referência
CVE-2021-28142
CITSmart before 9.1.2.28 mishandles the "filtro de autocomplete."
23RISCO
abrir
Referência
CVE-2017-16780
The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration fi
23RISCO
abrir
Referência
CVE-2010-4709
Heap-based buffer overflow in Automated Solutions Modbus/TCP Master OPC Server before 3.0.2 allows remote attackers to c
28RISCO
abrir
Referência
CVE-2017-17738
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) allows renaming and modifying files via /tools
23RISCO
abrir
Referência
CVE-2019-19740
Octeth Oempro 4.7 and 4.8 allow SQL injection. The parameter CampaignID in Campaign.Get is vulnerable.
23RISCO
abrir
Referência
CVE-2009-4863
Stack-based buffer overflow in UltraPlayer Media Player 2.112 allows remote attackers to execute arbitrary code via a lo
23RISCO
abrir
Referência
CVE-2018-19914
DomainMOD through 4.11.01 has XSS via the assets/add/dns.php Profile Name or notes field.
38RISCO
abrir
Referência
CVE-2019-8375
The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products
28RISCO
abrir
Referência
CVE-2021-46360
Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrar
23RISCO
abrir
Referência
CVE-2010-2311
Stack-based buffer overflow in Power Tab Editor 1.7 build 80 allows user-assisted remote attackers to execute arbitrary
23RISCO
abrir
anteriorpágina 207 / 719próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.