Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.813exploits catalogados
35.788CVEs com exploração pública
24.695testados em laboratório
22.549 exploits
Referência
CVE-2017-7018
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISCO
abrir
ReferênciaVexDay Proof
BS.Player 2.27 Build 959 - '.srt' File Buffer Overflow (PoC)
CVE-2008-6583doswindows
Buffer overflow in BS.player 2.27 build 959 allows remote attackers to cause a denial of service (crash) and possibly ex
23RISCO
abrir
Referência
CVE-2019-16679
Gila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion.
23RISCO
abrir
ReferênciaVexDay Proof
EZContents CMS 2.0.3 - Multiple Local File Inclusions
CVE-2008-7054webappsphp
Multiple directory traversal vulnerabilities in ezContents 2.0.3 allow remote attackers to include and execute arbitrary
23RISCO
abrir
Referência
CVE-2009-3365
PHP remote file inclusion vulnerability in add-ons/modules/sysmanager/plugins/install.plugin.php in Aurora CMS 1.0.2 all
23RISCO
abrir
ReferênciaVexDay Proof
EasyMail MessagePrinter Object - 'emprint.dll 6.0.1.0' Remote Buffer Overflow
CVE-2007-5070remotewindows
Heap-based buffer overflow in the EasyMailMessagePrinter ActiveX control in emprint.DLL 6.0.1.0 in the Quiksoft EasyMail
23RISCO
abrir
ReferênciaVexDay Proof
Mcafee EPO 4.0 - 'FrameworkService.exe' Remote Denial of Service
CVE-2008-1855doswindows
FrameworkService.exe in McAfee Common Management Agent (CMA) 3.6.0.574 Patch 3 and earlier, as used by ePolicy Orchestra
23RISCO
abrir
Referência
CVE-2010-4935
SQL injection vulnerability in poll.php in Entrans 0.3.2 and earlier allows remote attackers to execute arbitrary SQL co
23RISCO
abrir
Referência
CVE-2010-4940
SQL injection vulnerability in index.php in WAnewsletter 2.1.2 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Referência
CVE-2015-7896
LibQJpeg in the Samsung Galaxy S6 before the October 2015 MR allows remote attackers to cause a denial of service (memor
23RISCO
abrir
Referência
CVE-2015-7896
LibQJpeg in the Samsung Galaxy S6 before the October 2015 MR allows remote attackers to cause a denial of service (memor
23RISCO
abrir
Referência
CVE-2010-4332
Pointter PHP Content Management System 1.0 allows remote attackers to bypass authentication and obtain administrative pr
23RISCO
abrir
Referência
CVE-2017-17097
gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords
23RISCO
abrir
Referência
CVE-2014-1637
Command School Student Management System 1.06.01 does not properly restrict access to sw/backup/backup_ray2.php, which a
23RISCO
abrir
Referência
CVE-2014-2399
Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 2.2.2 allows remote attacker
23RISCO
abrir
Referência
CVE-2011-3713
cFTP r80 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the
23RISCO
abrir
ReferênciaVexDay Proof
DFLabs PTK 1.0 - Local Command Execution
CVE-2008-6793webappsphp
The get_file_type function in lib/file_content.php in DFLabs PTK 0.1, 0.2, and 1.0 allows remote attackers to execute ar
23RISCO
abrir
ReferênciaVexDay Proof
Sun xVM VirtualBox < 1.6.4 - Privilege Escalation (PoC)
CVE-2008-3431HIGHsob ataquedosmultiple
The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communicat
71RISCO
abrir
Referência
CVE-2010-4975
SQL injection vulnerability in the Techjoomla SocialAds For JomSocial (com_socialads) component for Joomla! allows remot
23RISCO
abrir
Referência
CVE-2025-0798
MicroWorld eScan Antivirus Quarantine rtscanner os command injection
48RISCO
abrir
Referência
CVE-2008-6366
SQL injection vulnerability in logon.jsp in Ad Server Solutions Affiliate Software Java 4.0 allows remote attackers to e
23RISCO
abrir
Referência
CVE-2025-34117
Netcore / Netis Routers RCE via UDP Port 53413 Backdoor
68RISCO
abrir
Referência
CVE-2015-7248
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote attackers to discover usernames and password ha
23RISCO
abrir
Referência
CVE-2018-13980
The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclos
38RISCO
abrir
Referência
CVE-2018-13980
The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclos
38RISCO
abrir
Referência
CVE-2025-34117
Netcore / Netis Routers RCE via UDP Port 53413 Backdoor
68RISCO
abrir
Referência
CVE-2025-34117
Netcore / Netis Routers RCE via UDP Port 53413 Backdoor
68RISCO
abrir
Referência
CVE-2016-1594
Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request
23RISCO
abrir
Referência
CVE-2016-1594
Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request
23RISCO
abrir
Referência
CVE-2013-0249
Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/curl_sasl.c in curl and libcurl 7
28RISCO
abrir
anteriorpágina 564 / 752próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.