Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.772exploits catalogados
35.760CVEs com exploração pública
24.695testados em laboratório
22.492 exploits
Referência
CVE-2010-4409
Integer overflow in the NumberFormatter::getSymbol (aka numfmt_get_symbol) function in PHP 5.3.3 and earlier allows cont
28RISCO
abrir
ReferênciaVexDay Proof
Microsoft Internet Explorer 6.0.2900 SP2 - CSS Attribute Denial of Service
CVE-2006-7031MEDIUMdoswindows
Microsoft Internet Explorer 6.0.2900 SP2 and earlier allows remote attackers to cause a denial of service (crash) via a
38RISCO
abrir
ReferênciaVexDay Proof
Lotus Domino R6 Webmail - Remote Password Hash Dumper
CVE-2007-0977remotewindows
IBM Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores HTTPPassword hashes from names.n
43RISCO
abrir
ReferênciaVexDay Proof
VideoLAN VLC Media Player 0.8.6d - 'httpd_FileCallBack' Remote Format String
CVE-2007-6682remotewindows
Format string vulnerability in the httpd_FileCallBack function (network/httpd.c) in VideoLAN VLC 0.8.6d allows remote at
28RISCO
abrir
Referência
CVE-2018-15142
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent
28RISCO
abrir
Referência
CVE-2019-3921
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via
28RISCO
abrir
Referência
CVE-2015-5130
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RISCO
abrir
Referência
CVE-2023-30803
Sangfor Next-Gen Application Firewall Authentication Bypass
53RISCO
abrir
Referência
CVE-2018-15137
CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml)
28RISCO
abrir
Referência
CVE-2017-2988
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable memory corruption vulnerability when performing g
28RISCO
abrir
Referência
CVE-2022-4120
Stop Spammers Security < 2022.6 - Unauthenticated PHP Object Injection
53RISCO
abrir
Referência
CVE-2016-2207
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS
28RISCO
abrir
Referência
CVE-2018-6546
plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming
28RISCO
abrir
ReferênciaVexDay Proof
OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH (Ruby)
CVE-2008-0166remotelinux
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that ge
45RISCO
abrir
Referência
CVE-2009-2553
Multiple SQL injection vulnerabilities in comments.php in Super Simple Blog Script 2.5.4, when magic_quotes_gpc is disab
23RISCO
abrir
Referência
CVE-2021-24274
Ultimate Maps by Supsystic < 1.2.5 - Reflected Cross-Site scripting (XSS)
43RISCO
abrir
Referência
CVE-2015-2279
cgi_test.cgi in AirLive BU-2015 with firmware 1.03.18, BU-3026 with firmware 1.43, and MD-3025 with firmware 1.81 allows
28RISCO
abrir
Referência
CVE-2015-2279
cgi_test.cgi in AirLive BU-2015 with firmware 1.03.18, BU-3026 with firmware 1.43, and MD-3025 with firmware 1.81 allows
28RISCO
abrir
Referência
CVE-2016-4176
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632
28RISCO
abrir
Referência
CVE-2022-4395
Membership For WooCommerce < 2.1.7 - Unauthenticated Arbitrary File Upload
53RISCO
abrir
Referência
CVE-2008-0232
Multiple SQL injection vulnerabilities in Zero CMS 1.0 Alpha allow remote attackers to execute arbitrary SQL commands vi
23RISCO
abrir
Referência
CVE-2017-5404
A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and
28RISCO
abrir
Referência
CVE-2018-7669
An issue was discovered in Sitecore Sitecore.NET 8.1 rev. 151207 Hotfix 141178-1 and above. The 'Log Viewer' application
28RISCO
abrir
Referência
CVE-2016-3373
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S
28RISCO
abrir
Referência
CVE-2014-0749
Stack-based buffer overflow in lib/Libdis/disrsi_.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Reso
28RISCO
abrir
Referência
PHP-Fusion 9.03.00 - 'Edit Profile' Remote Code Execution (Metasploit)
CVE-2019-12099remotephp
In PHP-Fusion 9.03.00, edit_profile.php allows remote authenticated users to execute arbitrary code because includes/dyn
28RISCO
abrir
Referência
CVE-2010-0757
Unrestricted file upload vulnerability in index.php/Attach in WikyBlog 1.7.3rc2 allows remote authenticated users to exe
23RISCO
abrir
Referência
Wordpress Plugin - Membership For WooCommerce < v2.1.7 - Arbitrary File Upload to Shell (Unauthenticated)
CVE-2022-4395CRITICALwebappsphp
Membership For WooCommerce < 2.1.7 - Unauthenticated Arbitrary File Upload
53RISCO
abrir
Referência
CVE-2016-8581
A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5
43RISCO
abrir
Referência
CVE-2010-0763
SQL injection vulnerability in index.php in CommodityRentals Vacation Rental Software allows remote attackers to execute
23RISCO
abrir
anteriorpágina 535 / 750próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.