Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.589exploits catalogados
34.508CVEs com exploração pública
24.695testados em laboratório
21.554 exploits
ReferênciaVexDay Proof
AllMyLinks 0.5.0 - 'index.php' Remote File Inclusion
CVE-2007-0171webappsphp
PHP remote file inclusion vulnerability in index.php in AllMyLinks 0.5.0 and earlier allows remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
BaoFeng2 - 'mps.dll' ActiveX Multiple Remote Buffer Overflows (PoC)
CVE-2007-4816doswindows
Multiple buffer overflows in the BaoFeng2 storm ActiveX control in Mps.dll allow remote attackers to have an unknown imp
23RISCO
abrir
ReferênciaVexDay Proof
dBpowerAMP Audio Player 2 - '.m3u' Remote Buffer Overflow
CVE-2008-0661remotewindows
Buffer overflow in dBpowerAMP Audio Player Release 2 allows remote attackers to execute arbitrary code via a .M3U file w
23RISCO
abrir
ReferênciaVexDay Proof
Versant Object Database 7.0.1.3 - Commands Execution
CVE-2008-1319remotewindows
Untrusted search path and argument injection vulnerability in the VersantD service in Versant Object Database 7.0.1.3 an
23RISCO
abrir
ReferênciaVexDay Proof
CMS Made Simple 1.2.4 Module FileManager - Arbitrary File Upload
CVE-2008-2267webappsphp
Incomplete blacklist vulnerability in javaUpload.php in Postlet in the FileManager module in CMS Made Simple 1.2.4 and e
23RISCO
abrir
ReferênciaVexDay Proof
Yerba SACphp 6.3 - Local File Inclusion
CVE-2008-4486webappsphp
Directory traversal vulnerability in index.php in SAC.php (SACphp), as used in Yerba 6.3 and earlier, allows remote atta
23RISCO
abrir
ReferênciaVexDay Proof
mxCamArchive 2.2 - Bypass Configuration Download
CVE-2008-6956webappsphp
Static code injection vulnerability in admin/admin.php in mxCamArchive 2.2 allows remote authenticated administrators to
23RISCO
abrir
Referência
CVE-2010-1299
Multiple PHP remote file inclusion vulnerabilities in DynPG CMS 4.1.0, and possibly earlier, when magic_quotes_gpc is di
28RISCO
abrir
Referência
CVE-2017-13855
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISCO
abrir
Referência
CVE-2016-9488
ManageEngine Applications Manager versions 12 and 13 suffer from remote SQL injection vulnerabilities
23RISCO
abrir
Referência
CVE-2016-9488
ManageEngine Applications Manager versions 12 and 13 suffer from remote SQL injection vulnerabilities
23RISCO
abrir
Referência
CVE-2015-3325
SQL injection vulnerability in forum.php in the WP Symposium plugin before 15.4 for WordPress allows remote attackers to
23RISCO
abrir
Referência
CVE-2017-16952
KMPlayer 4.2.2.4 allows remote attackers to cause a denial of service via a crafted NSV file.
23RISCO
abrir
Referência
CVE-2019-3759
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 cont
33RISCO
abrir
Referência
CVE-2014-4613
Cross-site request forgery (CSRF) vulnerability in the administration panel in Piwigo before 2.6.2 allows remote attacke
23RISCO
abrir
Referência
CVE-2014-4613
Cross-site request forgery (CSRF) vulnerability in the administration panel in Piwigo before 2.6.2 allows remote attacke
23RISCO
abrir
ReferênciaVexDay Proof
Magic CMS 4.2.747 - 'mysave.php' Remote File Inclusion
CVE-2007-1393webappsphp
PHP remote file inclusion vulnerability in mysave.php in Magic CMS 4.2.747 allows remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
Amber Script 1.0 - 'show_content.php?id' Local File Inclusion
CVE-2007-6129webappsphp
Directory traversal vulnerability in scripts/include/show_content.php in Amber Script 1.0 allows remote attackers to inc
23RISCO
abrir
ReferênciaVexDay Proof
XOOPS mod_gallery Zend_Hash_key + Extract - Remote File Inclusion
CVE-2008-0138webappsphp
PHP remote file inclusion vulnerability in xoopsgallery/init_basic.php in the mod_gallery module for XOOPS, when registe
23RISCO
abrir
ReferênciaVexDay Proof
FlashBlog 0.31b - Arbitrary File Upload
CVE-2008-2574webappsphp
Unrestricted file upload vulnerability in admin/Editor/imgupload.php in FlashBlog 0.31 beta allows remote attackers to e
23RISCO
abrir
ReferênciaVexDay Proof
NUVICO DVR NVDV4 / PdvrAtl Module 'PdvrAtl.DLL 1.0.1.25' - Remote Buffer Overflow
CVE-2008-4547remotewindows
Heap-based buffer overflow in the PdvrAtl.PdvrOcx.1 ActiveX control (pdvratl.dll) in DVRHOST Web CMS OCX 1.0.1.25 allows
28RISCO
abrir
Referência
CVE-2010-4278
operation/agentes/networkmap.php in Pandora FMS before 3.1.1 allows remote authenticated users to execute arbitrary comm
28RISCO
abrir
Referência
CVE-2017-9812
The reportId parameter of the getReportStatus action method can be abused in the web interface in Kaspersky Anti-Virus f
28RISCO
abrir
Referência
CVE-2017-9812
The reportId parameter of the getReportStatus action method can be abused in the web interface in Kaspersky Anti-Virus f
28RISCO
abrir
Referência
CVE-2009-2764
Microsoft Internet Explorer 8.0.7100.0 on Windows 7 RC on the x64 platform allows remote attackers to cause a denial of
28RISCO
abrir
ReferênciaVexDay Proof
Simplog 0.9.2 - 's' Remote Command Execution
CVE-2006-1776webappsphp
PHP remote file inclusion vulnerability in doc/index.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote atta
28RISCO
abrir
ReferênciaVexDay Proof
Simplog 0.9.2 - 's' Remote Command Execution
CVE-2006-1779webappsphp
Cross-site scripting (XSS) vulnerability in login.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attacke
23RISCO
abrir
Referência
CVE-2018-14418
In Msvod Cms v10, SQL Injection exists via an images/lists?cid= URI.
23RISCO
abrir
Referência
CVE-2015-3325
SQL injection vulnerability in forum.php in the WP Symposium plugin before 15.4 for WordPress allows remote attackers to
23RISCO
abrir
Referência
CVE-2017-16953
connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to mo
28RISCO
abrir
anteriorpágina 212 / 719próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.