Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.813exploits catalogados
35.788CVEs com exploração pública
24.695testados em laboratório
22.523 exploits
Referência
CVE-2020-9467
Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function.
28RISCO
abrir
Referência
CVE-2017-17876
Biometric Shift Employee Management System 3.0 allows remote attackers to bypass intended file-read restrictions via a u
23RISCO
abrir
Referência
CVE-2020-14461
Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI.
23RISCO
abrir
Referência
CVE-2022-26521
Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable
23RISCO
abrir
Referência
CVE-2016-10043
An issue was discovered in Radisys MRF Web Panel (SWMS) 9.0.1. The MSM_MACRO_NAME POST parameter in /swms/ms.cgi was dis
23RISCO
abrir
Referência
CVE-2012-1010
Unrestricted file upload vulnerability in actions.php in the AllWebMenus plugin before 1.1.8 for WordPress allows remote
23RISCO
abrir
Referência
CVE-2022-4063
InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE
63RISCO
abrir
ReferênciaVexDay Proof
Simple PHP Blog 0.4.7.1 - Remote Command Execution
CVE-2006-1243webappsphp
Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
Fundanemt 2.2.0 - 'spellcheck.php' Remote Code Execution
CVE-2007-2935webappsphp
core/spellcheck/spellcheck.php in Fundanemt before 2.2.0.1 allows remote attackers to execute arbitrary commands via she
23RISCO
abrir
Referência
CVE-2016-4309
Session fixation vulnerability in Symphony CMS 2.6.7, when session.use_only_cookies is disabled, allows remote attackers
23RISCO
abrir
Referência
CVE-2012-6050
The winbox service in MikroTik RouterOS 5.15 and earlier allows remote attackers to cause a denial of service (CPU consu
23RISCO
abrir
Referência
CVE-2009-2535
Mozilla Firefox before 2.0.0.19 and 3.x before 3.0.5, SeaMonkey, and Thunderbird allow remote attackers to cause a denia
23RISCO
abrir
Referência
CVE-2009-3705
PHP remote file inclusion vulnerability in debugger.php in Achievo before 1.4.0 allows remote attackers to execute arbit
23RISCO
abrir
Referência
CVE-2017-6553
Buffer Overflow in Quest One Identity Privilege Manager for Unix before 6.0.0.061 allows remote attackers to obtain full
50RISCO
abrir
ReferênciaVexDay Proof
WEBInsta CMS 0.3.1 - 'templates_dir' Remote File Inclusion
CVE-2006-4196webappsphp
PHP remote file inclusion vulnerability in index.php in WEBInsta CMS 0.3.1 and possibly earlier allows remote attackers
23RISCO
abrir
Referência
CVE-2013-7280
Buffer overflow in HansoTools Hanso Player 2.1.0, 2.5.0, and earlier allows remote attackers to cause a denial of servic
23RISCO
abrir
Referência
CVE-2017-15965
The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in
23RISCO
abrir
Referência
CVE-2011-4715
Directory traversal vulnerability in cgi-bin/koha/mainpage.pl in Koha 3.4 before 3.4.7 and 3.6 before 3.6.1, and LibLime
23RISCO
abrir
Referência
CVE-2010-1719
Directory traversal vulnerability in the MT Fire Eagle (com_mtfireeagle) component 1.2 for Joomla! allows remote attacke
38RISCO
abrir
Referência
CVE-2010-1719
Directory traversal vulnerability in the MT Fire Eagle (com_mtfireeagle) component 1.2 for Joomla! allows remote attacke
38RISCO
abrir
Referência
CVE-2010-3856
ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use
43RISCO
abrir
ReferênciaVexDay Proof
PNPHPBB2 < 1.2g - 'phpbb_root_path' Remote File Inclusion
CVE-2006-4968webappsphp
PHP remote file inclusion vulnerability in includes/functions_admin.php in PNphpBB 1.2g allows remote attackers to execu
23RISCO
abrir
ReferênciaVexDay Proof
Linksys SPA941 - '\377' Character Remote Denial of Service
CVE-2007-2270doshardware
The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) cha
23RISCO
abrir
ReferênciaVexDay Proof
PHP 5.2.3 'Tidy' Extension - Local Buffer Overflow
CVE-2007-3294localwindows
Multiple buffer overflows in libtidy, as used in the Tidy extension for PHP 5.2.3 and possibly other products, allow con
23RISCO
abrir
ReferênciaVexDay Proof
Ultra Crypto Component - 'CryptoX.dll 2.0' Remote Buffer Overflow
CVE-2007-4903remotewindows
Multiple buffer overflows in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Component allo
23RISCO
abrir
Referência
CVE-2009-3271
Apple Safari on iPhone OS 3.0.1 allows remote attackers to cause a denial of service (application crash) via a long tel:
23RISCO
abrir
Referência
CVE-2018-0833
The Microsoft Server Message Block 2.0 and 3.0 (SMBv2/SMBv3) client in Windows 8.1 and RT 8.1 and Windows Server 2012 R2
35RISCO
abrir
Referência
CVE-2016-0121
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
35RISCO
abrir
Referência
CVE-2011-1524
Cross-site scripting (XSS) vulnerability in the management login GUI page in Symantec LiveUpdate Administrator (LUA) bef
23RISCO
abrir
Referência
CVE-2021-29995
A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute
23RISCO
abrir
anteriorpágina 558 / 751próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.