Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.533exploits catalogados
35.607CVEs com exploração pública
24.695testados em laboratório
22.407 exploits
Referência
CVE-2017-9769
A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpe
60RISCO
abrir
Referência
CVE-2017-9791
CVE-2017-9791CRITICALsob ataque
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RISCO
abrir
Referência
CVE-2017-9810
There are no Anti-CSRF tokens in any forms on the web interface in Kaspersky Anti-Virus for Linux File Server before Mai
23RISCO
abrir
Referência
CVE-2017-9810
There are no Anti-CSRF tokens in any forms on the web interface in Kaspersky Anti-Virus for Linux File Server before Mai
23RISCO
abrir
Referência
CVE-2017-9822
CVE-2017-9822HIGHsob ataqueransomware
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code e
100RISCO
abrir
Referência
CVE-2018-0296
CVE-2018-0296HIGHsob ataque
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RISCO
abrir
Referência
CVE-2018-0296
CVE-2018-0296HIGHsob ataque
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RISCO
abrir
Referência
CVE-2018-0710
Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authe
28RISCO
abrir
Referência
CVE-2018-0710
Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authe
28RISCO
abrir
Referência
CVE-2018-0748
The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and
23RISCO
abrir
Referência
CVE-2018-0752
The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709
23RISCO
abrir
Referência
CVE-2018-0823
The Named Pipe File System in Windows 10 version 1709 and Windows Server, version 1709 allows an elevation of privilege
23RISCO
abrir
Referência
CVE-2018-0838
Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remot
35RISCO
abrir
Referência
CVE-2018-0860
Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remot
35RISCO
abrir
Referência
CVE-2017-5753
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RISCO
abrir
Referência
CVE-2018-0895
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Serve
23RISCO
abrir
Referência
CVE-2018-0897
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Serve
23RISCO
abrir
Referência
CVE-2018-0970
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISCO
abrir
Referência
CVE-2018-0974
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISCO
abrir
Referência
CVE-2018-1000001
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RISCO
abrir
Referência
CVE-2018-1000001
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RISCO
abrir
Referência
CVE-2023-3219
EventON < 2.1.2 - Unauthenticated Post Access via IDOR
38RISCO
abrir
ReferênciaVexDay Proof
Flatnuke 3 - Remote Cookie Manipulation / Privilege Escalation
CVE-2007-5771webappsphp
Flatnuke 3 (aka FlatnuX) allows remote attackers to obtain administrative access via a myforum%00 cookie.
23RISCO
abrir
ReferênciaVexDay Proof
Flatnuke 3 - Remote Command Execution / Privilege Escalation
CVE-2007-5773webappsphp
Cross-site request forgery (CSRF) vulnerability in index.php in the File Manager module in Flatnuke 3 allows remote atta
23RISCO
abrir
ReferênciaVexDay Proof
emagiC CMS.Net 4.0 - 'emc.asp' SQL Injection
CVE-2007-5783webappsasp
SQL injection vulnerability in emc.asp in emagiC CMS.Net 4.0 allows remote attackers to execute arbitrary SQL commands v
23RISCO
abrir
ReferênciaVexDay Proof
GuppY 4.6.3 - 'index.php?selskin' Remote File Inclusion
CVE-2007-5845webappsphp
Directory traversal vulnerability in error.php in GuppY 4.6.3, 4.5.16, and earlier allows remote attackers to include an
23RISCO
abrir
ReferênciaVexDay Proof
ASP Message Board 2.2.1c - SQL Injection
CVE-2007-5887webappsasp
SQL injection vulnerability in boards/printer.asp in ASP Message Board 2.2.1c allows remote attackers to execute arbitra
23RISCO
abrir
ReferênciaVexDay Proof
jPORTAL 2 - 'mailer.php' SQL Injection
CVE-2007-5912webappsphp
SQL injection vulnerability in mailer.php in jPORTAL 2 allows remote attackers to execute arbitrary SQL commands via the
23RISCO
abrir
ReferênciaVexDay Proof
Adobe Shockwave - 'ShockwaveVersion()' Stack Overflow (PoC)
CVE-2007-5941doswindows
Stack-based buffer overflow in the SWCtl.SWCtl ActiveX control in Adobe Shockwave allows remote attackers to cause a den
35RISCO
abrir
ReferênciaVexDay Proof
vsftpd 2.0.5 - 'CWD' (Authenticated) Remote Memory Consumption
CVE-2007-5962doslinux
Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 throug
28RISCO
abrir
anteriorpágina 488 / 747próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.