Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.772exploits catalogados
35.760CVEs com exploração pública
24.695testados em laboratório
22.523 exploits
Referência
CVE-2014-8272
The IPMI 1.5 functionality in Dell iDRAC6 modular before 3.65, iDRAC6 monolithic before 1.98, and iDRAC7 before 1.57.57
28RISCO
abrir
Referência
CVE-2019-6110
In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-T
38RISCO
abrir
Referência
CVE-2020-9283
golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the
28RISCO
abrir
Referência
CVE-2009-4544
Cross-site scripting (XSS) vulnerability in kbase/kbase.php in Cromosoft Technologies Facil Helpdesk 2.3 Lite allows rem
23RISCO
abrir
Referência
CVE-2016-2209
Buffer overflow in Dec2SS.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec
28RISCO
abrir
Referência
CVE-2019-1003029
CVE-2019-1003029CRITICALsob ataque
A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/
100RISCO
abrir
Referência
CVE-2011-1866
Buffer overflow in omniinet.exe in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allows remot
28RISCO
abrir
Referência1
Exploit for EasyNAS version 1.1.0. The vulnerability exploited is a command injection flaw, which requires authentication.
EasyNAS backup.pl system os command injection
38RISCO
abrir
Referência
CVE-2020-25213
CVE-2020-25213CRITICALsob ataque
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISCO
abrir
Referência
CVE-2012-5612
Heap-based buffer overflow in Oracle MySQL 5.5.19 and other versions through 5.5.28, and MariaDB 5.5.28a and possibly ot
28RISCO
abrir
Referência
CVE-2015-4664
An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers t
28RISCO
abrir
Referência
CVE-2015-4664
An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers t
28RISCO
abrir
Referência
CVE-2009-2394
SQL injection vulnerability in cat.php in SMSPages 1.0 in Mr.Saphp Arabic Script Mobile (aka Messages Library) 2.0 allow
23RISCO
abrir
Referência
CVE-2017-1000112
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE
43RISCO
abrir
Referência
CVE-2016-4201
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro
28RISCO
abrir
Referência
CVE-2015-9266
Ubiquiti airOS HTTP(S) unauthenticated arbitrary file upload
85RISCO
abrir
Referência
CVE-2015-9266
Ubiquiti airOS HTTP(S) unauthenticated arbitrary file upload
85RISCO
abrir
Referência
CVE-2024-7332
TOTOLINK CP450 Telnet Service product.ini hard-coded password
68RISCO
abrir
Referência
CVE-2018-9022
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to exec
28RISCO
abrir
Referência
CVE-2014-8768
Multiple Integer underflows in the geonet_print function in tcpdump 4.5.0 through 4.6.2, when in verbose mode, allow rem
28RISCO
abrir
Referência
CVE-2014-8768
Multiple Integer underflows in the geonet_print function in tcpdump 4.5.0 through 4.6.2, when in verbose mode, allow rem
28RISCO
abrir
Referência
CVE-2017-3068
Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the Advanced V
28RISCO
abrir
Referência
CVE-2018-13416
In Universal Media Server (UMS) 7.1.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML Extern
28RISCO
abrir
Referência
CVE-2021-24946
Modern Events Calendar < 6.1.5 - Unauthenticated Blind SQL Injection
60RISCO
abrir
Referência
CVE-2018-6006
SQL Injection exists in the JS Autoz 1.0.9 component for Joomla! via the vtype, pre, or prs parameter.
28RISCO
abrir
Referência
CVE-2018-5726
MASTER IPCAMERA01 3.3.4.2103 devices allow remote attackers to obtain sensitive information via a crafted HTTP request,
28RISCO
abrir
Referência
CVE-2018-5726
MASTER IPCAMERA01 3.3.4.2103 devices allow remote attackers to obtain sensitive information via a crafted HTTP request,
28RISCO
abrir
Referência
CVE-2019-0573
An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations,
28RISCO
abrir
Referência
CVE-2023-4548
SPA-Cart eCommerce CMS GET Parameter search sql injection
38RISCO
abrir
Referência
CVE-2020-24881
SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.
60RISCO
abrir
anteriorpágina 543 / 751próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.