Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.772exploits catalogados
35.760CVEs com exploração pública
24.695testados em laboratório
22.523 exploits
Referência
CVE-2010-1495
Directory traversal vulnerability in the Matamko (com_matamko) component 1.01 for Joomla! allows remote attackers to rea
43RISCO
abrir
Referência
CVE-2010-1495
Directory traversal vulnerability in the Matamko (com_matamko) component 1.01 for Joomla! allows remote attackers to rea
43RISCO
abrir
Referência
CVE-2017-1000375
NetBSD maps the run-time link-editor ld.so directly below the stack region, even if ASLR is enabled, this allows attacke
28RISCO
abrir
Referência
CVE-2012-0985
Multiple buffer overflows in the Wireless Manager ActiveX control 4.0.0.0 in WifiMan.dll in Sony VAIO PC Wireless LAN Wi
28RISCO
abrir
Referência
CVE-2018-4243
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
28RISCO
abrir
Referência
CVE-2017-5465
An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for other
28RISCO
abrir
Referência
CVE-2021-46419
An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system fil
60RISCO
abrir
Referência
CVE-2010-4409
Integer overflow in the NumberFormatter::getSymbol (aka numfmt_get_symbol) function in PHP 5.3.3 and earlier allows cont
28RISCO
abrir
ReferênciaVexDay Proof
Microsoft Internet Explorer 6.0.2900 SP2 - CSS Attribute Denial of Service
CVE-2006-7031MEDIUMdoswindows
Microsoft Internet Explorer 6.0.2900 SP2 and earlier allows remote attackers to cause a denial of service (crash) via a
38RISCO
abrir
ReferênciaVexDay Proof
Lotus Domino R6 Webmail - Remote Password Hash Dumper
CVE-2007-0977remotewindows
IBM Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores HTTPPassword hashes from names.n
43RISCO
abrir
ReferênciaVexDay Proof
VideoLAN VLC Media Player 0.8.6d - 'httpd_FileCallBack' Remote Format String
CVE-2007-6682remotewindows
Format string vulnerability in the httpd_FileCallBack function (network/httpd.c) in VideoLAN VLC 0.8.6d allows remote at
28RISCO
abrir
Referência
CVE-2018-15142
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent
28RISCO
abrir
Referência
CVE-2019-3921
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via
28RISCO
abrir
Referência
CVE-2015-5130
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RISCO
abrir
Referência
CVE-2023-30803
Sangfor Next-Gen Application Firewall Authentication Bypass
53RISCO
abrir
Referência
CVE-2018-15137
CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml)
28RISCO
abrir
Referência
CVE-2017-2988
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable memory corruption vulnerability when performing g
28RISCO
abrir
Referência
CVE-2022-4120
Stop Spammers Security < 2022.6 - Unauthenticated PHP Object Injection
53RISCO
abrir
Referência
CVE-2016-2207
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS
28RISCO
abrir
Referência
CVE-2018-6546
plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming
28RISCO
abrir
ReferênciaVexDay Proof
OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH (Ruby)
CVE-2008-0166remotelinux
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that ge
45RISCO
abrir
Referência
CVE-2009-2553
Multiple SQL injection vulnerabilities in comments.php in Super Simple Blog Script 2.5.4, when magic_quotes_gpc is disab
23RISCO
abrir
Referência
CVE-2017-12945
Insufficient validation of user-supplied input for the Solstice Pod before 2.8.4 networking configuration enables authen
28RISCO
abrir
Referência
CVE-2018-7573
An issue was discovered in FTPShell Client 6.7. A remote FTP server can send 400 characters of 'F' in conjunction with t
50RISCO
abrir
Referência
CVE-2018-7573
An issue was discovered in FTPShell Client 6.7. A remote FTP server can send 400 characters of 'F' in conjunction with t
50RISCO
abrir
Referência
CVE-2016-1077
Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acro
28RISCO
abrir
Referência
CVE-2017-7240
An issue was discovered on Miele Professional PST10 devices. The corresponding embedded webserver "PST10 WebServer" typi
28RISCO
abrir
Referência
CVE-2023-26602
ASUS ASMB8 iKVM firmware through 1.14.51 allows remote attackers to execute arbitrary code by using SNMP to create exten
28RISCO
abrir
Referência
CVE-2013-5045
Microsoft Internet Explorer 10 and 11 allows local users to bypass the Protected Mode protection mechanism, and conseque
43RISCO
abrir
Referência
CVE-2007-6681
Stack-based buffer overflow in modules/demux/subtitle.c in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitr
28RISCO
abrir
anteriorpágina 540 / 751próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.