Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.724exploits catalogados
35.724CVEs com exploração pública
24.695testados em laboratório
22.492 exploits
Referência
CVE-2013-3906
CVE-2013-3906HIGHsob ataque
GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compati
100RISCO
abrir
Referência
CVE-2017-14491
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execut
45RISCO
abrir
Referência
CVE-2017-14491
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execut
45RISCO
abrir
Referência
CVE-2017-2741
A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmwa
60RISCO
abrir
Referência
CVE-2017-2741
A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmwa
60RISCO
abrir
Referência
CVE-2023-38950
CVE-2023-38950HIGHsob ataque
A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbit
100RISCO
abrir
Referência
CVE-2019-8449
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate username
60RISCO
abrir
Referência
CVE-2015-6132
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
60RISCO
abrir
ReferênciaVexDay Proof
PHPBandManager 0.8 - 'index.php?pg' Remote File Inclusion
CVE-2007-2341webappsphp
PHP remote file inclusion vulnerability in suite/index.php in phpBandManager 0.8 allows remote attackers to execute arbi
23RISCO
abrir
Referência
CVE-2018-17463
CVE-2018-17463HIGHsob ataque
Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbit
100RISCO
abrir
Referência
rConfig 3.9.4 - 'search.crud.php' Remote Command Injection
CVE-2020-10879webappsphp
rConfig before 3.9.5 allows command injection by sending a crafted GET request to lib/crud/search.crud.php since the nod
45RISCO
abrir
Referência
CVE-2009-2265
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RISCO
abrir
ReferênciaVexDay Proof
VUPlayer 2.49 - '.asx' HREF Local Buffer Overflow (1)
CVE-2009-0174localwindows
Stack-based buffer overflow in VUPlayer 2.49 allows remote attackers to execute arbitrary code via a long .asf URI in th
28RISCO
abrir
Referência
CVE-2020-11023
CVE-2020-11023MEDIUMsob ataque
Potential XSS vulnerability in jQuery
85RISCO
abrir
ReferênciaVexDay Proof
VUPlayer 2.49 - '.asx' HREF Local Buffer Overflow (2)
CVE-2009-0174localwindows
Stack-based buffer overflow in VUPlayer 2.49 allows remote attackers to execute arbitrary code via a long .asf URI in th
28RISCO
abrir
Referência
CVE-2019-1620
Cisco Data Center Network Manager Arbitrary File Upload and Remote Code Execution Vulnerability
85RISCO
abrir
Referência
CVE-2019-1620
Cisco Data Center Network Manager Arbitrary File Upload and Remote Code Execution Vulnerability
85RISCO
abrir
ReferênciaVexDay Proof
Free Download Manager 2.5/3.0 - Authorisation Stack Buffer Overflow (PoC)
CVE-2009-0183doswindows
Stack-based buffer overflow in Remote Control Server in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allo
50RISCO
abrir
Referência
CVE-2015-3035
CVE-2015-3035HIGHsob ataque
Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before
100RISCO
abrir
Referência
CVE-2023-25690
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
70RISCO
abrir
Referência
CVE-2023-2796
EventON < 2.1.2 - Unauthenticated Event Access
50RISCO
abrir
Referência
CVE-2023-5702
Viessmann Vitogate 300 direct request
38RISCO
abrir
ReferênciaVexDay Proof
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
CVE-2009-0335webappsphp
Cross-site scripting (XSS) vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to inject arbitrar
23RISCO
abrir
Referência
CVE-2020-8163
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the
60RISCO
abrir
ReferênciaVexDay Proof
ProFTPd - 'mod_mysql' Authentication Bypass
CVE-2009-0542remotemultiple
SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL co
45RISCO
abrir
ReferênciaVexDay Proof
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
CVE-2009-0336webappsphp
Katy Whitton BlogIt! stores sensitive information under the web root with insufficient access control, which allows remo
23RISCO
abrir
Referência
CVE-2018-17254
The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.
60RISCO
abrir
ReferênciaVexDay Proof
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
CVE-2009-0337webappsphp
SQL injection vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to execute arbitrary SQL comman
23RISCO
abrir
Referência
CVE-2018-10660
An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.
60RISCO
abrir
Referência
CVE-2015-6922
Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before
60RISCO
abrir
anteriorpágina 520 / 750próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.