Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.866exploits catalogados
35.812CVEs com exploração pública
24.695testados em laboratório
22.572 exploits
Referência
CVE-2012-5533
The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial o
28RISCO
abrir
Referência
CVE-2017-9125
The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of se
23RISCO
abrir
Referência
CVE-2019-1089
An elevation of privilege vulnerability exists in rpcss.dll when the RPC service Activation Kernel improperly handles an
23RISCO
abrir
Referência
CVE-2006-5763
Multiple PHP remote file inclusion vulnerabilities in Free File Hosting 1.1, and possibly earlier, when register_globals
23RISCO
abrir
Referência
CVE-2009-3253
Stack-based buffer overflow in TriceraSoft Swift Ultralite 1.032 allows remote attackers to cause a denial of service (c
23RISCO
abrir
Referência
CVE-2007-5229
Cross-site request forgery (CSRF) vulnerability in the FeedBurner FeedSmith 2.2 plugin for WordPress allows remote attac
23RISCO
abrir
Referência
CVE-2013-6114
Integer overflow in the OZDocument::parseElement function in Apple Motion 5.0.7 allows remote attackers to cause a denia
23RISCO
abrir
Referência
CVE-2015-2321
Cross-site scripting (XSS) vulnerability in the Job Manager plugin 0.7.22 and earlier for WordPress allows remote attack
23RISCO
abrir
ReferênciaVexDay Proof
Gravity Board X 2.0 Beta - SQL Injection / Cross-Site Scripting
CVE-2008-2996webappsphp
Multiple SQL injection vulnerabilities in index.php in Gravity Board X (GBX) 2.0 Beta, when magic_quotes_gpc is disabled
23RISCO
abrir
Referência
CVE-2015-2321
Cross-site scripting (XSS) vulnerability in the Job Manager plugin 0.7.22 and earlier for WordPress allows remote attack
23RISCO
abrir
ReferênciaVexDay Proof
Gravity Board X 2.0 Beta - SQL Injection / Cross-Site Scripting
CVE-2008-2997webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Gravity Board X (GBX) 2.0 Beta allows remote attackers to injec
23RISCO
abrir
ReferênciaVexDay Proof
AllMyGuests 0.3.0 - 'AMG_serverpath' Remote File Inclusion
CVE-2007-0172webappsphp
Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.3.0 and earlier allow remote attackers to execute ar
23RISCO
abrir
ReferênciaVexDay Proof
i.Scribe SMTP Client 2.00b - 'wscanf' Remote Format String (PoC)
CVE-2008-7074doswindows
Format string vulnerability in MemeCode Software i.Scribe 1.88 through 2.00 before Beta9 allows remote SMTP servers to c
23RISCO
abrir
ReferênciaVexDay Proof
MPLAB IDE 8.30 - '.mcp' Universal Overwrite (SEH)
CVE-2009-1674localwindows
Stack-based buffer overflow in Microchip MPLAB IDE 8.30 allows user-assisted remote attackers to execute arbitrary code
23RISCO
abrir
Referência
CVE-2010-1174
Cisco TFTP Server 1.1 allows remote attackers to cause a denial of service (daemon crash) via a crafted (1) read (aka RR
23RISCO
abrir
Referência
CVE-2021-42325
Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name.
28RISCO
abrir
Referência
CVE-2010-1296
Multiple buffer overflows in Adobe Photoshop CS4 before 11.0.2 allow user-assisted remote attackers to execute arbitrary
28RISCO
abrir
Referência
CVE-2017-8490
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RISCO
abrir
Referência
CVE-2026-18615
GL-iNet GL-MT3000 wg-server.so Native Plugin glc wg-server.generate_publickey command injection
48RISCO
abrir
Referência
CVE-2018-5315
The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php.
23RISCO
abrir
Referência
CVE-2018-5315
The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php.
23RISCO
abrir
Referência
CVE-2015-3314
SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5.
23RISCO
abrir
Referência
CVE-2015-3314
SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5.
23RISCO
abrir
Referência
CVE-2013-4092
The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows context-dependent att
23RISCO
abrir
Referência
CVE-2016-1247
The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS
23RISCO
abrir
Referência
CVE-2016-1247
The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS
23RISCO
abrir
Referência
CVE-2014-2559
Multiple cross-site request forgery (CSRF) vulnerabilities in twitget.php in the Twitget plugin before 3.3.3 for WordPre
23RISCO
abrir
Referência
CVE-2012-3414
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component beamospetition - SQL Injection
CVE-2008-3132webappsphp
SQL injection vulnerability in the beamospetition (com_beamospetition) component for Joomla! allows remote attackers to
23RISCO
abrir
Referência
CVE-2021-47964
Schlix CMS 2.2.6-6 Remote Code Execution via core.blockmanager
41RISCO
abrir
anteriorpágina 583 / 753próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.