Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
22.573 exploits
Referência
CVE-2008-4844
Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet
50RISCO
abrir
Referência
CVE-2008-4844
Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet
50RISCO
abrir
Referência
CVE-2018-0934
ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution,
35RISCO
abrir
Referência
CVE-2022-1388
CVE-2022-1388CRITICALsob ataqueransomware
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir
Referência
CVE-2016-7240
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
35RISCO
abrir
Referência
CVE-2012-6096
Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga
50RISCO
abrir
Referência
CVE-2012-6096
Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga
50RISCO
abrir
Referência
CVE-2022-1388
CVE-2022-1388CRITICALsob ataqueransomware
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISCO
abrir
Referência
CVE-2013-2347
The Backup Client Service (OmniInet.exe) in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary
50RISCO
abrir
ReferênciaVexDay Proof
WEBBDOMAIN WebShop 1.02 - SQL Injection / Cross-Site Scripting
CVE-2008-6268webappsphp
SQL injection vulnerability in detail.php in WEBBDOMAIN Multi Languages WebShop Online 1.02 allows remote attackers to e
23RISCO
abrir
Referência
CVE-2011-5010
apps/a3/cfg_ethping.cgi in the Ctek SkyRouter 4200 and 4300 allows remote attackers to execute arbitrary commands via sh
50RISCO
abrir
Referência
CVE-2012-6529
Multiple SQL injection vulnerabilities in Marinet CMS allow remote attackers to execute arbitrary SQL commands via the i
23RISCO
abrir
Referência
CVE-2017-14496
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-su
35RISCO
abrir
ReferênciaVexDay Proof
Acc Real Estate 4.0 - Insecure Cookie Handling
CVE-2008-6293webappsphp
admin/Index.php in Acc Real Estate 4.0 allows remote attackers to bypass authentication and gain administrative access b
23RISCO
abrir
Referência
CVE-2019-12181
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
50RISCO
abrir
Referência
CVE-2015-2295
Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before
35RISCO
abrir
Referência
CVE-2015-2295
Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before
35RISCO
abrir
Referência
CVE-2013-6194
Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a
50RISCO
abrir
Referência
CVE-2015-8351
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_includ
35RISCO
abrir
Referência
CVE-2015-8351
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_includ
35RISCO
abrir
ReferênciaVexDay Proof
VUPlayer 2.44 - '.m3u' UNC Name Buffer Overflow
CVE-2006-6251localwindows
Stack-based buffer overflow in VUPlayer 2.44 and earlier allows remote attackers to execute arbitrary code via a long st
50RISCO
abrir
ReferênciaVexDay Proof
Aigaion 1.3.3 - 'topic topic_id' SQL Injection
CVE-2007-3683webappsphp
SQL injection vulnerability in pagetopic.php in Aigaion 1.3.3 and earlier allows remote attackers to execute arbitrary S
23RISCO
abrir
Referência
CVE-2023-30806
Sangfor Next-Gen Application Firewall PHPSESSID Command Injection
60RISCO
abrir
Referência
CVE-2023-30805
Sangfor Next-Gen Application Firewall Login Un Param Command Injection
60RISCO
abrir
ReferênciaVexDay Proof
Free Directory Script 1.1.1 - 'API_HOME_DIR' Remote File Inclusion
CVE-2008-6305webappsphp
PHP remote file inclusion vulnerability in init.php in Free Directory Script 1.1.1, when register_globals is enabled, al
23RISCO
abrir
Referência
CVE-2017-14147
An issue was discovered on FiberHome User End Routers Bearing Model Number AN1020-25 which could allow an attacker to ea
35RISCO
abrir
Referência
CVE-2017-14147
An issue was discovered on FiberHome User End Routers Bearing Model Number AN1020-25 which could allow an attacker to ea
35RISCO
abrir
Referência
CVE-2010-4279
The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which al
50RISCO
abrir
Referência
CVE-2010-4279
The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which al
50RISCO
abrir
ReferênciaVexDay Proof
E-topbiz Link Back Checker 1 - Insecure Cookie Handling
CVE-2008-6307webappsphp
E-topbiz Link Back Checker 1 allows remote attackers to bypass authentication and gain administrative access by setting
23RISCO
abrir
anteriorpágina 58 / 753próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.