Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.620exploits catalogados
35.647CVEs com exploração pública
24.695testados em laboratório
22.429 exploits
ReferênciaVexDay Proof
Kim Websites 1.0 - Authentication Bypass
CVE-2009-1026webappsphp
Multiple SQL injection vulnerabilities in login.php in Kim Websites 1.0 allow remote attackers to execute arbitrary SQL
23RISCO
abrir
ReferênciaVexDay Proof
POP Peeper 3.4.0.0 - Date Remote Buffer Overflow
CVE-2009-1029remotewindows
Stack-based buffer overflow in POP Peeper 3.4.0.0 and earlier allows remote POP3 servers to execute arbitrary code via a
50RISCO
abrir
ReferênciaVexDay Proof
RhinoSoft Serv-U FTP Server 7.4.0.1 - 'MKD' Create Arbitrary Directories
CVE-2009-1031remotewindows
Directory traversal vulnerability in the FTP server in Rhino Software Serv-U File Server 7.0.0.1 through 7.4.0.1 allows
28RISCO
abrir
ReferênciaVexDay Proof
Ace-FTP Client 1.24a - Remote Buffer Overflow (PoC)
CVE-2007-3161doswindows
Buffer overflow in Ace-FTP Client 1.24a allows user-assisted, remote FTP servers to execute arbitrary code via a long re
23RISCO
abrir
ReferênciaVexDay Proof
YAP 1.1.1 - Blind SQL Injection / SQL Injection
CVE-2009-1038webappsphp
Multiple SQL injection vulnerabilities in YAP Blog 1.1.1 allow remote attackers to execute arbitrary SQL commands via th
23RISCO
abrir
ReferênciaVexDay Proof
Moodle < 1.6.9/1.7.7/1.8.9/1.9.5 - File Disclosure
CVE-2009-1171webappsphp
The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+, 1.8 before 1.8.9, and 1.9 before 1.9.5 allows user-assist
23RISCO
abrir
ReferênciaVexDay Proof
WebFileExplorer 3.1 - Authentication Bypass
CVE-2009-1314webappsphp
body.asp in Web File Explorer 3.1 allows remote attackers to create arbitrary files and execute arbitrary code via the s
28RISCO
abrir
ReferênciaVexDay Proof
Mini-stream Ripper 3.0.1.1 - '.m3u' Universal Stack Overflow
CVE-2009-1325localwindows
Stack-based buffer overflow in Mini-stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long U
23RISCO
abrir
ReferênciaVexDay Proof
RM Downloader - '.m3u' Local Stack Overflow (PoC)
CVE-2009-1326doswindows
Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RISCO
abrir
ReferênciaVexDay Proof
WM Downloader 3.0.0.9 - '.m3u' Universal Stack Overflow
CVE-2009-1327localwindows
Stack-based buffer overflow in Mini-stream WM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RISCO
abrir
Referência
CVE-2014-4880
Buffer overflow in Hikvision DVR DS-7204 Firmware 2.2.10 build 131009, and other models and versions, allows remote atta
60RISCO
abrir
Referência
CVE-2025-34299
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RISCO
abrir
ReferênciaVexDay Proof
Mini-stream RM-MP3 Converter 3.0.0.7 - '.m3u' Local Stack Overflow (PoC)
CVE-2009-1328doswindows
Stack-based buffer overflow in Mini-stream RM-MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary code vi
23RISCO
abrir
ReferênciaVexDay Proof
Mini-stream RM-MP3 Converter 3.0.0.7 - '.m3u' Local Stack Overflow
CVE-2009-1328localwindows
Stack-based buffer overflow in Mini-stream RM-MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary code vi
23RISCO
abrir
Referência
CVE-2019-11231
An issue was discovered in GetSimple CMS through 3.3.15. insufficient input sanitation in the theme-edit.php file allows
60RISCO
abrir
Referência
CVE-2016-7241
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of
45RISCO
abrir
Referência
CVE-2018-20434
LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to htm
60RISCO
abrir
Referência
CVE-2018-20434
LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to htm
60RISCO
abrir
ReferênciaVexDay Proof
Oracle APEX 3.2 - Unprivileged DB users can see APEX Password hashes
CVE-2009-0981localmultiple
Unspecified vulnerability in the Application Express component in Oracle Database 11.1.0.7 allows remote authenticated u
23RISCO
abrir
Referência
CVE-2016-3247
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of
45RISCO
abrir
Referência
CVE-2019-19985
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file downloa
70RISCO
abrir
ReferênciaVexDay Proof
DeluxeBB 1.3 - 'qorder' SQL Injection
CVE-2009-1033webappsphp
SQL injection vulnerability in misc.php in DeluxeBB 1.3 and earlier allows remote attackers to execute arbitrary SQL com
23RISCO
abrir
Referência
CVE-2018-18323
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/
60RISCO
abrir
Referência
CVE-2013-6117
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive informatio
50RISCO
abrir
Referência
CVE-2019-9978
CVE-2019-9978MEDIUMsob ataque
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir
Referência
CVE-2014-8686
CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-
50RISCO
abrir
Referência
CVE-2017-6736
CVE-2017-6736HIGHsob ataque
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabiliti
93RISCO
abrir
Referência
CVE-2021-21220
CVE-2021-21220HIGHsob ataque
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to po
98RISCO
abrir
Referência
CVE-2021-21220
CVE-2021-21220HIGHsob ataque
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to po
98RISCO
abrir
Referência
CVE-2022-28810
CVE-2022-28810MEDIUMsob ataque
Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary
100RISCO
abrir
anteriorpágina 508 / 748próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.