Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.724exploits catalogados
35.724CVEs com exploração pública
24.695testados em laboratório
22.492 exploits
Referência
CVE-2009-2598
Multiple SQL injection vulnerabilities in Online Grades & Attendance 3.2.6 and earlier allow (1) remote attackers to exe
23RISCO
abrir
ReferênciaVexDay Proof
XGuestBook 2.0 - Authentication Bypass
CVE-2009-0810webappsphp
SQL injection vulnerability in login.php in xGuestbook 2.0 allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
Referência
CVE-2018-15811
CVE-2018-15811HIGHsob ataque
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.
100RISCO
abrir
Referência
CVE-2017-5715
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
55RISCO
abrir
Referência
CVE-2019-9978
CVE-2019-9978MEDIUMsob ataque
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISCO
abrir
ReferênciaVexDay Proof
GDL 4.x - 'node' SQL Injection
CVE-2009-0965webappsphp
SQL injection vulnerability in functions/browse.php in Ganesha Digital Library (GDL) 4.0 and 4.2 allows remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
WordPress Plugin fMoblog 2.1 - 'id' SQL Injection
CVE-2009-0968webappsphp
SQL injection vulnerability in fmoblog.php in the fMoblog plugin 2.1 for WordPress allows remote attackers to execute ar
23RISCO
abrir
ReferênciaVexDay Proof
Gretech GOM Encoder 1.0.0.11 - '.Subtitle' Buffer Overflow (PoC)
CVE-2009-1022doswindows
Heap-based buffer overflow in the Preview/ Set Segment function in Gretech GOMlab GOM Encoder 1.0.0.11 and earlier allow
23RISCO
abrir
ReferênciaVexDay Proof
Beerwin's PHPLinkAdmin 1.0 - Remote File Inclusion / SQL Injection
CVE-2009-1024webappsphp
Multiple SQL injection vulnerabilities in Beerwin PHPLinkAdmin 1.0 allow remote attackers to execute arbitrary SQL comma
23RISCO
abrir
Referência
CVE-2018-0824
CVE-2018-0824HIGHsob ataque
A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized
100RISCO
abrir
Referência
CVE-2014-5073
vmtadmin.cgi in VMTurbo Operations Manager before 4.6 build 28657 allows remote attackers to execute arbitrary commands
60RISCO
abrir
ReferênciaVexDay Proof
Beerwin's PHPLinkAdmin 1.0 - Remote File Inclusion / SQL Injection
CVE-2009-1025webappsphp
PHP remote file inclusion vulnerability in linkadmin.php in Beerwin PHPLinkAdmin 1.0 allows remote attackers to execute
28RISCO
abrir
ReferênciaVexDay Proof
Kim Websites 1.0 - Authentication Bypass
CVE-2009-1026webappsphp
Multiple SQL injection vulnerabilities in login.php in Kim Websites 1.0 allow remote attackers to execute arbitrary SQL
23RISCO
abrir
ReferênciaVexDay Proof
POP Peeper 3.4.0.0 - Date Remote Buffer Overflow
CVE-2009-1029remotewindows
Stack-based buffer overflow in POP Peeper 3.4.0.0 and earlier allows remote POP3 servers to execute arbitrary code via a
50RISCO
abrir
ReferênciaVexDay Proof
RhinoSoft Serv-U FTP Server 7.4.0.1 - 'MKD' Create Arbitrary Directories
CVE-2009-1031remotewindows
Directory traversal vulnerability in the FTP server in Rhino Software Serv-U File Server 7.0.0.1 through 7.4.0.1 allows
28RISCO
abrir
ReferênciaVexDay Proof
Ace-FTP Client 1.24a - Remote Buffer Overflow (PoC)
CVE-2007-3161doswindows
Buffer overflow in Ace-FTP Client 1.24a allows user-assisted, remote FTP servers to execute arbitrary code via a long re
23RISCO
abrir
ReferênciaVexDay Proof
YAP 1.1.1 - Blind SQL Injection / SQL Injection
CVE-2009-1038webappsphp
Multiple SQL injection vulnerabilities in YAP Blog 1.1.1 allow remote attackers to execute arbitrary SQL commands via th
23RISCO
abrir
ReferênciaVexDay Proof
Moodle < 1.6.9/1.7.7/1.8.9/1.9.5 - File Disclosure
CVE-2009-1171webappsphp
The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+, 1.8 before 1.8.9, and 1.9 before 1.9.5 allows user-assist
23RISCO
abrir
Referência
CVE-2018-7251
An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contain
60RISCO
abrir
Referência
CVE-2019-1429
CVE-2019-1429HIGHsob ataque
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RISCO
abrir
Referência
CVE-2014-3914
Directory traversal vulnerability in the Admin Center for Tivoli Storage Manager (TSM) in Rocket ServerGraph 1.2 allows
60RISCO
abrir
Referência
CVE-2017-6316
CVE-2017-6316CRITICALsob ataque
Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as r
100RISCO
abrir
Referência
CVE-2017-6316
CVE-2017-6316CRITICALsob ataque
Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as r
100RISCO
abrir
Referência
CVE-2022-20699
CVE-2022-20699CRITICALsob ataque
Cisco Small Business RV Series Routers Vulnerabilities
100RISCO
abrir
Referência
CVE-2017-15889
Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authe
60RISCO
abrir
ReferênciaVexDay Proof
Blue Eye CMS 1.0.0 - Remote Cookie SQL Injection
CVE-2009-0883webappsphp
SQL injection vulnerability in Blue Eye CMS 1.0.0 and earlier, when magic_quotes_gpc is disabled, allows remote attacker
23RISCO
abrir
Referência
CVE-2021-25296
CVE-2021-25296HIGHsob ataque
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi
100RISCO
abrir
Referência
CVE-2021-25296
CVE-2021-25296HIGHsob ataque
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi
100RISCO
abrir
Referência
CVE-2021-39327
BulletProof Security <= 5.1 Sensitive Information Disclosure
70RISCO
abrir
Referência
CVE-2016-1560
ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and
60RISCO
abrir
anteriorpágina 518 / 750próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.