Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.449exploits catalogados
35.552CVEs com exploração pública
24.695testados em laboratório
22.367 exploits
Referência
CVE-2026-19006
mf-yang openclaw-cn Ggateway Exec Approval Flow bash-tools.exec.ts authorization
33RISCO
abrir
ReferênciaVexDay Proof
BIND 9.x - Remote DNS Cache Poisoning
CVE-2008-1447remotemultiple
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windo
60RISCO
abrir
ReferênciaVexDay Proof
RunCMS Module section - 'artid' SQL Injection
CVE-2008-1462webappsphp
SQL injection vulnerability in the sections (Section) module in RunCMS allows remote attackers to execute arbitrary SQL
23RISCO
abrir
ReferênciaVexDay Proof
Home FTP Server 1.4.5 - Remote Denial of Service
CVE-2008-1478doswindows
Home FTP Server 1.4.5.89 allows remote attackers to cause a denial of service (crash) by opening a FTP passive mode conn
23RISCO
abrir
ReferênciaVexDay Proof
SunOS 5.10 Sun Cluster - 'rpc.metad' Denial of Service (PoC)
CVE-2008-1480dossolaris
rpc.metad in Sun Solaris 10 allows remote attackers to cause a denial of service (daemon crash) via a malformed RPC requ
23RISCO
abrir
ReferênciaVexDay Proof
ASUS DPC Proxy 2.0.0.16/19 - Remote Buffer Overflow
CVE-2008-1491remotewindows
Stack-based buffer overflow in the DPC Proxy server (DpcProxy.exe) in ASUS Remote Console (aka ARC or ASMB3) 2.0.0.19 an
60RISCO
abrir
ReferênciaVexDay Proof
PEEL CMS 3.x - Admin Hash Extraction / Arbitrary File Upload
CVE-2008-1495webappsphp
Unrestricted file upload vulnerability in administrer/produits.php in PEEL, possibly 3.x and earlier, allows remote auth
23RISCO
abrir
ReferênciaVexDay Proof
NetWin Surgemail 3.8k4-4 - IMAP (Authenticated) Remote LIST Universal
CVE-2008-1498remotewindows
Stack-based buffer overflow in the IMAP service in NetWin Surgemail 3.8k4-4 and earlier allows remote authenticated user
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component custompages 1.1 - Remote File Inclusion
CVE-2008-1505webappsphp
PHP remote file inclusion vulnerability in the SSTREAMTV custompages (com_custompages) 1.1 and earlier component for Joo
35RISCO
abrir
ReferênciaVexDay Proof
Danneo CMS 0.5.1 - Blind SQL Injection
CVE-2008-1513webappsphp
SQL injection vulnerability in index.php in Danneo CMS 0.5.1 and earlier, when the Referers statistics option is enabled
23RISCO
abrir
ReferênciaVexDay Proof
PHP-Nuke Platinum 7.6.b.5 - 'dynamic_titles.php' SQL Injection
CVE-2008-1539webappsphp
SQL injection vulnerability in includes/dynamic_titles.php in PHP-Nuke Platinum 7.6.b.5 allows remote attackers to execu
23RISCO
abrir
ReferênciaVexDay Proof
RunCMS Module Photo 3.02 - 'cid' SQL Injection
CVE-2008-1551webappsphp
SQL injection vulnerability in viewcat.php in the Photo 3.02 module for RunCMS allows remote attackers to execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
TopperMod 2.0 - SQL Injection
CVE-2008-1554webappsphp
SQL injection vulnerability in account/index.php in TopperMod 2.0, when magic_quotes_gpc is disabled, allows remote atta
23RISCO
abrir
ReferênciaVexDay Proof
MPlayer 1.0 rc2 - 'sdpplin_parse()' Array Indexing Buffer Overflow (PoC)
CVE-2008-1558doslinux
Uncontrolled array index in the sdpplin_parse function in stream/realrtsp/sdpplin.c in MPlayer 1.0 rc2 allows remote att
28RISCO
abrir
Referência
CVE-2026-67623
Mistral Vibe < 2.23.3 Arbitrary Command Execution via git fsmonitor Hook
41RISCO
abrir
Referência
CVE-2026-67623
Mistral Vibe < 2.23.3 Arbitrary Command Execution via git fsmonitor Hook
41RISCO
abrir
Referência
CVE-2026-66747
ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant
48RISCO
abrir
ReferênciaVexDay Proof
PostNuke 0.764 - Blind SQL Injection
CVE-2008-1591webappsphp
The pnVarPrepForStore function in PostNuke 0.764 and earlier skips input sanitization when magic_quotes_runtime is enabl
23RISCO
abrir
Referência
CVE-2026-67599
ClearOS 7.9 OS Command Injection via Log Viewer filter parameter
41RISCO
abrir
ReferênciaVexDay Proof
PhpBlock a8.4 - 'PATH_TO_CODE' Remote File Inclusion
CVE-2008-1776webappsphp
PHP remote file inclusion vulnerability in modules/basicfog/basicfogfactory.class.php in PhpBlock A8.4 allows remote att
28RISCO
abrir
ReferênciaVexDay Proof
Prozilla Forum Service - 'forum' SQL Injection
CVE-2008-1789webappsphp
SQL injection vulnerability in forum.php in Prozilla Forum allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
ReferênciaVexDay Proof
rdesktop 1.5.0 - 'process_redirect_pdu()' BSS Overflow (PoC)
CVE-2008-1802doslinux
Buffer overflow in the process_redirect_pdu (rdp.c) function in rdesktop 1.5.0 allows remote attackers to execute arbitr
28RISCO
abrir
ReferênciaVexDay Proof
724CMS 4.01 Enterprise - 'index.php' SQL Injection
CVE-2008-1858webappsphp
SQL injection vulnerability in index.php in 724Networks 724CMS 4.01 and earlier allows remote attackers to execute arbit
23RISCO
abrir
ReferênciaVexDay Proof
iScripts Socialware - 'id' SQL Injection
CVE-2008-1859webappsphp
SQL injection vulnerability in events.php in iScripts SocialWare allows remote attackers to execute arbitrary SQL comman
23RISCO
abrir
ReferênciaVexDay Proof
Blog PixelMotion - 'categorie' SQL Injection
CVE-2008-1867webappsphp
SQL injection vulnerability in Blog Pixel Motion (aka Blog PixelMotion) allows remote attackers to execute arbitrary SQL
23RISCO
abrir
ReferênciaVexDay Proof
PIGMy-SQL 1.4.1 - 'getdata.php' Blind SQL Injection
CVE-2008-1870webappsphp
SQL injection vulnerability in getdata.php in PIGMy-SQL 1.4.1 and earlier allows remote attackers to execute arbitrary S
23RISCO
abrir
ReferênciaVexDay Proof
Comdev News Publisher 4.1.2 - SQL Injection
CVE-2008-1872webappsphp
SQL injection vulnerability in home.news.php in Comdev News Publisher 4.1.2 allows remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
Xine-Lib 1.1.12 - NSF demuxer Stack Overflow (PoC)
CVE-2008-1878doslinux
Stack-based buffer overflow in the demux_nsf_send_chunk function in src/demuxers/demux_nsf.c in xine-lib 1.1.12 and earl
28RISCO
abrir
ReferênciaVexDay Proof
CDNetworks Nefficient Download - 'NeffyLauncher.dll' Code Execution
CVE-2008-1886remotewindows
The NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficient Download uses weak cryptography for
23RISCO
abrir
ReferênciaVexDay Proof
Carbon Communities 2.4 - Multiple Vulnerabilities
CVE-2008-1896webappsasp
Multiple cross-site scripting (XSS) vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to inje
23RISCO
abrir
anteriorpágina 468 / 746próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.