Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.698exploits catalogados
35.718CVEs com exploração pública
24.695testados em laboratório
22.429 exploits
Referência
CVE-2016-10073
The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the emai
60RISCO
abrir
Referência
CVE-2016-10073
The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the emai
60RISCO
abrir
Referência
CVE-2021-25094
Tatsu < 3.3.12 - Unauthenticated RCE
60RISCO
abrir
ReferênciaVexDay Proof
phosheezy 2.0 - Remote Command Execution
CVE-2009-0251webappsphp
Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to
23RISCO
abrir
ReferênciaVexDay Proof
Flax Article Manager 1.1 - 'cat_id' SQL Injection
CVE-2009-0284webappsphp
SQL injection vulnerability in category.php in Flax Article Manager 1.1 allows remote attackers to execute arbitrary SQL
23RISCO
abrir
Referência
CVE-2010-2075
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RISCO
abrir
ReferênciaVexDay Proof
OpenGoo 1.1 - Local File Inclusion
CVE-2009-0286webappsphp
Directory traversal vulnerability in upgrade/index.php in OpenGoo 1.1, when register_globals is enabled and magic_quotes
23RISCO
abrir
Referência
CVE-2013-5311
Multiple SQL injection vulnerabilities in Vastal I-Tech phpVID 1.2.3 allow remote attackers to execute arbitrary SQL com
23RISCO
abrir
Referência
CVE-2023-5702
Viessmann Vitogate 300 direct request
38RISCO
abrir
ReferênciaVexDay Proof
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
CVE-2009-0335webappsphp
Cross-site scripting (XSS) vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to inject arbitrar
23RISCO
abrir
Referência
CVE-2020-8163
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the
60RISCO
abrir
ReferênciaVexDay Proof
ProFTPd - 'mod_mysql' Authentication Bypass
CVE-2009-0542remotemultiple
SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL co
45RISCO
abrir
Referência
CVE-2019-7194
CVE-2019-7194CRITICALsob ataqueransomware
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fi
100RISCO
abrir
Referência
CVE-2019-14470
cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has X
60RISCO
abrir
Referência
CVE-2020-7980
Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to th
60RISCO
abrir
Referência
CVE-2018-16763
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISCO
abrir
Referência
CVE-2019-0539
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RISCO
abrir
ReferênciaVexDay Proof
Simple PHP NewsLetter 1.5 - Local File Inclusion
CVE-2009-0340webappsphp
Multiple directory traversal vulnerabilities in Simple PHP Newsletter 1.5 allow remote attackers to read arbitrary files
23RISCO
abrir
Referência
CVE-2011-0276
HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.secu
60RISCO
abrir
Referência
CVE-2010-1297
CVE-2010-1297HIGHsob ataque
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrob
100RISCO
abrir
Referência
CVE-2015-6128
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandle library loading, which allo
60RISCO
abrir
ReferênciaVexDay Proof
WinFTP Server 2.3.0 - 'LIST' (Authenticated) Remote Buffer Overflow
CVE-2009-0351remotewindows
Stack-based buffer overflow in WFTPSRV.exe in WinFTP 2.3.0 allows remote authenticated users to execute arbitrary code v
23RISCO
abrir
Referência
CVE-2018-6789
CVE-2018-6789CRITICALsob ataqueransomware
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISCO
abrir
Referência
CVE-2018-6789
CVE-2018-6789CRITICALsob ataqueransomware
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISCO
abrir
Referência
CVE-2023-39362
Authenticated command injection in SNMP options of a Device
63RISCO
abrir
ReferênciaVexDay Proof
Persism CMS 0.9.2 - system[path] Remote File Inclusion
CVE-2007-2545webappsphp
Multiple PHP remote file inclusion vulnerabilities in Persism CMS 0.9.2 and earlier allow remote attackers to execute ar
35RISCO
abrir
Referência
CVE-2013-4212
Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute
60RISCO
abrir
Referência
CVE-2014-7862
The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote at
60RISCO
abrir
Referência
CVE-2017-10974
Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: th
60RISCO
abrir
Referência
CVE-2022-31704
The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely
85RISCO
abrir
anteriorpágina 509 / 748próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.