Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.057exploits catalogados
36.288CVEs com exploração pública
24.695testados em laboratório
22.910 exploits
ReferênciaVexDay Proof
Mobius 1.4.4.1 - SQL Injection
CVE-2008-3420webappsphp
Multiple SQL injection vulnerabilities in Mobius for Mimsy XG 1 1.4.4.1 and earlier allow remote attackers to execute ar
23RISCO
abrir
ReferênciaVexDay Proof
phpMyRealty 2.0.0 - 'location' SQL Injection
CVE-2008-3445webappsphp
SQL injection vulnerability in index.php in phpMyRealty (PMR) 2.0.0 allows remote attackers to execute arbitrary SQL com
23RISCO
abrir
ReferênciaVexDay Proof
IPNPro3 < 1.44 - Admin Password Changing
CVE-2008-5568webappsphp
Cross-site request forgery (CSRF) vulnerability in admin/settings.php in IPN Pro 3 1.44 and earlier allows remote attack
23RISCO
abrir
ReferênciaVexDay Proof
AdaptCMS Lite 1.4 - Cross-Site Scripting / Remote File Inclusion
CVE-2009-0526webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AdaptCMS Lite 1.4 allow remote attackers to inject a
23RISCO
abrir
Referência
CVE-2010-4417
Unspecified vulnerability in the Services for Beehive component in Oracle Fusion Middleware 2.0.1.0, 2.0.1.1, 2.0.1.2, 2
60RISCO
abrir
Referência
CVE-2014-7205
Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for t
60RISCO
abrir
ReferênciaVexDay Proof
LetterIt 2 - 'Language' Local File Inclusion
CVE-2008-3446webappsphp
Directory traversal vulnerability in inc/wysiwyg.php in LetterIt 2 allows remote attackers to include and execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
F-PROT AntiVirus 6.2.1.4252 - Malformed Archive Infinite Loop Denial of Service
CVE-2008-3447dosmultiple
The scanning engine in F-Prot Antivirus 6.2.1 4252 allows remote attackers to cause a denial of service (infinite loop)
23RISCO
abrir
ReferênciaVexDay Proof
eNdonesia 8.4 (Calendar Module) - SQL Injection
CVE-2008-3452webappsphp
SQL injection vulnerability in the Calendar module in eNdonesia 8.4 allows remote attackers to execute arbitrary SQL com
23RISCO
abrir
ReferênciaVexDay Proof
PHP Hosting Directory 2.0 - Insecure Cookie Handling
CVE-2008-3454webappsphp
JnSHosts PHP Hosting Directory 2.0 allows remote attackers to bypass authentication and gain administrative access by se
23RISCO
abrir
ReferênciaVexDay Proof
WebMaster Marketplace - SQL Injection
CVE-2008-5574webappsphp
SQL injection vulnerability in member.php in Webmaster Marketplace allows remote attackers to execute arbitrary SQL comm
23RISCO
abrir
Referência
CVE-2021-1732
CVE-2021-1732HIGHsob ataqueransomware
Windows Win32k Elevation of Privilege Vulnerability
100RISCO
abrir
Referência
CVE-2021-1732
CVE-2021-1732HIGHsob ataqueransomware
Windows Win32k Elevation of Privilege Vulnerability
100RISCO
abrir
Referência
CVE-2014-5301
Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 t
60RISCO
abrir
Referência
CVE-2017-0070
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling object
45RISCO
abrir
Referência34
CVE-2024-23108: Fortinet FortiSIEM Unauthenticated 2nd Order Command Injection
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
85RISCO
abrir
ReferênciaVexDay Proof
PHP Hosting Directory 2.0 - Remote File Inclusion
CVE-2008-3455webappsphp
PHP remote file inclusion vulnerability in include/admin.php in JnSHosts PHP Hosting Directory 2.0 allows remote attacke
23RISCO
abrir
ReferênciaVexDay Proof
Vistered Little 1.6a - 'skin' Remote File Disclosure
CVE-2007-2934webappsphp
Directory traversal vulnerability in skins/common.css.php in Vistered Little 1.6a allows remote attackers to read arbitr
23RISCO
abrir
Referência
CVE-2008-5585
Multiple PHP remote file inclusion vulnerabilities in lcxBBportal 0.1 Alpha 2 allow remote attackers to execute arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Windows Server 2000 SP4 (Advanced Server) - Message Queue (MS07-065)
CVE-2007-3039remotewindows
Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Window
50RISCO
abrir
Referência
CVE-2012-0217
The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and
50RISCO
abrir
Referência
CVE-2012-3873
Multiple SQL injection vulnerabilities in Open Constructor 3.12.0 allow remote authenticated users to execute arbitrary
23RISCO
abrir
Referência
CVE-2017-12478
It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of
60RISCO
abrir
Referência
CVE-2017-12478
It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of
60RISCO
abrir
ReferênciaVexDay Proof
Anzio Web Print Object 3.2.30 - ActiveX Buffer Overflow
CVE-2008-3480remotewindows
Stack-based buffer overflow in the Anzio Web Print Object (WePO) ActiveX control 3.2.19 and 3.2.24, as used in Anzio Pri
28RISCO
abrir
Referência
CVE-2019-16113
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RISCO
abrir
ReferênciaVexDay Proof
eStoreAff 0.1 - 'cid' SQL Injection
CVE-2008-3484webappsphp
SQL injection vulnerability in eStoreAff 0.1 allows remote attackers to execute arbitrary SQL commands via the cid param
23RISCO
abrir
Referência
CVE-2019-9851
LibreLogo global-event script execution
60RISCO
abrir
ReferênciaVexDay Proof
TROforum 0.1 - 'admin.php?site_url' Remote File Inclusion
CVE-2007-2937webappsphp
PHP remote file inclusion vulnerability in admin/admin.php in TROforum 0.1 allows remote attackers to execute arbitrary
35RISCO
abrir
ReferênciaVexDay Proof
ASPThai.Net WebBoard 6.0 - SQL Injection
CVE-2009-0703webappsphp
SQL injection vulnerability in bview.asp in ASPThai.Net Webboard 6.0 allows remote attackers to execute arbitrary SQL co
23RISCO
abrir
anteriorpágina 37 / 764próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.