Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.866exploits catalogados
35.812CVEs com exploração pública
24.695testados em laboratório
22.573 exploits
Referência
CVE-2018-16517
asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a deni
23RISCO
abrir
Referência
CVE-2018-8817
Wampserver before 3.1.3 has CSRF in add_vhost.php.
23RISCO
abrir
Referência
CVE-2008-1247
The web interface on the Linksys WRT54g router with firmware 1.00.9 does not require credentials when invoking scripts,
23RISCO
abrir
Referência
CVE-2011-1974
NDISTAPI.sys in the NDISTAPI driver in Remote Access Service (RAS) in Microsoft Windows XP SP2 and SP3 and Windows Serve
23RISCO
abrir
ReferênciaVexDay Proof
VRNews 1.1.1 - 'admin.php' Remote Security Bypass
CVE-2007-3611webappsphp
admin.php in VRNews 1.1.1, and possibly other 1.x versions, does not require authentication, which allows remote attacke
23RISCO
abrir
Referência
CVE-2016-1755
The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to exe
23RISCO
abrir
Referência
CVE-2015-4591
eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remo
23RISCO
abrir
Referência
CVE-2009-2766
httpd.c in httpd in the management GUI in DD-WRT 24 sp1 does not require administrative authentication for programs unde
23RISCO
abrir
ReferênciaVexDay Proof
CMS-BRD - 'menuclick' SQL Injection
CVE-2008-2837webappsphp
SQL injection vulnerability in index.php in CMS-BRD allows remote attackers to execute arbitrary SQL commands via the me
23RISCO
abrir
Referência
CVE-2009-4453
Insecure method vulnerability in SoftCab Sound Converter ActiveX control (sndConverter.ocx) 1.2 allows remote attackers
23RISCO
abrir
Referência
CVE-2010-2313
Directory traversal vulnerability in index.php in Anodyne Productions SIMM Management System (SMS) 2.6.10, when magic_qu
23RISCO
abrir
Referência
CVE-2019-1476
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
23RISCO
abrir
Referência
CVE-2019-1152
Microsoft Graphics Remote Code Execution Vulnerability
46RISCO
abrir
Referência
CVE-2009-3714
Cross-site scripting (XSS) vulnerability in admin_login.php in MCshoutbox 1.1 allows remote attackers to inject arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
WebMatic 2.6 - 'index_album.php' Remote File Inclusion
CVE-2007-0839webappsphp
Multiple PHP remote file inclusion vulnerabilities in index/index_album.php in Valarsoft WebMatic 2.6 allow remote attac
23RISCO
abrir
Referência
CVE-2010-0832
pam_motd (aka the MOTD module) in libpam-modules before 1.1.0-2ubuntu1.1 in PAM on Ubuntu 9.10 and libpam-modules before
23RISCO
abrir
Referência
CVE-2017-13713
T&W WIFI Repeater BE126 allows remote authenticated users to execute arbitrary code via shell metacharacters in the user
23RISCO
abrir
Referência
CVE-2017-13713
T&W WIFI Repeater BE126 allows remote authenticated users to execute arbitrary code via shell metacharacters in the user
23RISCO
abrir
Referência
CVE-2017-2482
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RISCO
abrir
Referência
CVE-2016-0073
The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 160
23RISCO
abrir
Referência
CVE-2018-12095
A Reflected Cross-Site Scripting web vulnerability has been discovered in the OEcms v3.1 web-application. The vulnerabil
38RISCO
abrir
Referência
CVE-2013-5578
Buffer overflow in the ToDot method in the WINGRAPHVIZLib.NEATO ActiveX control in WinGraphviz.dll in StarUML allows rem
23RISCO
abrir
Referência
CVE-2023-29983
Cross Site Scripting vulnerability found in Maximilian Vogt cmaps v.8.0 allows a remote attacker to execute arbitrary co
33RISCO
abrir
Referência
CVE-2017-2447
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISCO
abrir
Referência
CVE-2017-9127
The quicktime_user_atoms_read_atom function in useratoms.c in libquicktime 1.2.4 allows remote attackers to cause a deni
23RISCO
abrir
Referência
CVE-2022-2941
WP-UserOnline <= 2.88.0 - Authenticated (Admin+) Stored Cross-Site Scripting
33RISCO
abrir
Referência
CVE-2016-7617
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Bluetooth"
23RISCO
abrir
Referência
CVE-2009-3752
SQL injection vulnerability in home.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands via the g
23RISCO
abrir
Referência
CVE-2015-10137
Website Contact Form With File Upload <= 1.3.4 - Arbitrary File Upload
63RISCO
abrir
ReferênciaVexDay Proof
Docebo 3.0.3 - Multiple Remote File Inclusions
CVE-2006-2576webappsphp
Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow
23RISCO
abrir
anteriorpágina 584 / 753próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.