Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.836exploits catalogados
35.811CVEs com exploração pública
24.695testados em laboratório
22.549 exploits
Referência
CVE-2011-2523
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
ReferênciaVexDay Proof
study planner (studiewijzer) 0.15 - Remote File Inclusion
CVE-2007-1628webappsphp
Multiple PHP remote file inclusion vulnerabilities in Study planner (Studiewijzer) 0.15 and earlier, when register_globa
23RISCO
abrir
ReferênciaVexDay Proof
PHPRaider 1.0.7 - 'PHPbb3.functions.php' Remote File Inclusion
CVE-2008-2481webappsphp
PHP remote file inclusion vulnerability in authentication/phpbb3/phpbb3.functions.php in phpRaider 1.0.7 and 1.0.7a, whe
23RISCO
abrir
ReferênciaVexDay Proof
Dana IRC 1.3 - Remote Buffer Overflow (PoC)
CVE-2008-2922doswindows
Stack-based buffer overflow in artegic Dana IRC client 1.3 and earlier allows remote attackers to cause a denial of serv
23RISCO
abrir
Referência
CVE-2023-54335
eXtplorer<= 2.1.14 - Authentication Bypass & Remote Code Execution (RCE)
48RISCO
abrir
Referência
CVE-2021-28242
SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive dat
23RISCO
abrir
Referência
CVE-2017-0300
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RISCO
abrir
Referência
CVE-2019-13623
In NSA Ghidra before 9.1, path traversal can occur in RestoreTask.java (from the package ghidra.app.plugin.core.archive)
23RISCO
abrir
Referência
CVE-2013-4868
Karotz API 12.07.19.00: Session Token Information Disclosure
23RISCO
abrir
Referência
CVE-2018-10188
phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_ope
23RISCO
abrir
Referência
CVE-2017-0100
A DCOM object in Helppane.exe in Microsoft Windows 7 SP1; Windows Server 2008 R2; Windows 8.1; Windows Server 2012 Gold
23RISCO
abrir
Referência
CVE-2022-4117
IWS - Geo Form Fields <= 1.0 - Unauthenticated SQLi
63RISCO
abrir
Referência
CVE-2017-4916
VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver. Succes
23RISCO
abrir
Referência
CVE-2014-9261
The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which
23RISCO
abrir
Referência
CVE-2014-9261
The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which
23RISCO
abrir
Referência
CVE-2010-3155
Untrusted search path vulnerability in Adobe ExtendScript Toolkit (ESTK) CS5 3.5.0.52 allows local users, and possibly r
28RISCO
abrir
Referência
CVE-2017-15014
OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design ga
23RISCO
abrir
Referência
CVE-2022-37255
TP-Link Tapo C310 1.3.0 devices allow access to the RTSP video feed via credentials of User --- and Password TPL07552646
41RISCO
abrir
ReferênciaVexDay Proof
Pluck CMS 4.5.3 - 'g_pcltar_lib_dir' Local File Inclusion
CVE-2008-6253webappsphp
Directory traversal vulnerability in data/inc/lib/pcltar.lib.php in Pluck 4.5.3, when register_globals is enabled, allow
23RISCO
abrir
Referência
CVE-2014-2090
Multiple cross-site scripting (XSS) vulnerabilities in ilias.php in ILIAS 4.4.1 allow remote authenticated users to inje
23RISCO
abrir
ReferênciaVexDay Proof
ICQ 6.5 - URL Search Hook (Windows Explorer) Remote Buffer Overflow (PoC)
CVE-2009-1915doswindows
Stack-based buffer overflow in the URL Search Hook (ICQToolBar.dll) in ICQ 6.5 allows remote attackers to cause a denial
23RISCO
abrir
Referência
CVE-2016-9566
base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root
23RISCO
abrir
Referência
CVE-2018-7704
SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read arbitrary e-mail messages via the option1
23RISCO
abrir
Referência
CVE-2026-18645
danpros HTMLy Admin Content Endpoint admin.php add_content path traversal
33RISCO
abrir
Referência
CVE-2026-18644
danpros HTMLy Delete Username Endpoint htmly.php unlink path traversal
33RISCO
abrir
Referência
CVE-2026-18641
Sangfor Operation and Maintenance Security Management System Login Endpoint portal_login com.sbr.fort.foreignDP.DpLoginController os command injection
33RISCO
abrir
Referência
CVE-2026-18632
langgenius dify Jinja2 jinja2_transformer.py jinja2.Template special elements used in a template engine
33RISCO
abrir
Referência
CVE-2011-5148
Multiple incomplete blacklist vulnerabilities in the Simple File Upload (mod_simplefileuploadv1.3) module before 1.3.5 f
23RISCO
abrir
Referência
CVE-2018-9128
DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068.
23RISCO
abrir
Referência
CVE-2018-9128
DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068.
23RISCO
abrir
anteriorpágina 576 / 752próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.