Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.866exploits catalogados
35.812CVEs com exploração pública
24.695testados em laboratório
22.573 exploits
Referência
CVE-2017-15965
The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in
23RISCO
abrir
Referência
CVE-2011-4715
Directory traversal vulnerability in cgi-bin/koha/mainpage.pl in Koha 3.4 before 3.4.7 and 3.6 before 3.6.1, and LibLime
23RISCO
abrir
Referência
CVE-2010-1719
Directory traversal vulnerability in the MT Fire Eagle (com_mtfireeagle) component 1.2 for Joomla! allows remote attacke
38RISCO
abrir
Referência
CVE-2010-1719
Directory traversal vulnerability in the MT Fire Eagle (com_mtfireeagle) component 1.2 for Joomla! allows remote attacke
38RISCO
abrir
ReferênciaVexDay Proof
WEBInsta CMS 0.3.1 - 'templates_dir' Remote File Inclusion
CVE-2006-4196webappsphp
PHP remote file inclusion vulnerability in index.php in WEBInsta CMS 0.3.1 and possibly earlier allows remote attackers
23RISCO
abrir
Referência
CVE-2010-3856
ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use
43RISCO
abrir
ReferênciaVexDay Proof
Linksys SPA941 - '\377' Character Remote Denial of Service
CVE-2007-2270doshardware
The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) cha
23RISCO
abrir
ReferênciaVexDay Proof
PHP 5.2.3 'Tidy' Extension - Local Buffer Overflow
CVE-2007-3294localwindows
Multiple buffer overflows in libtidy, as used in the Tidy extension for PHP 5.2.3 and possibly other products, allow con
23RISCO
abrir
ReferênciaVexDay Proof
Ultra Crypto Component - 'CryptoX.dll 2.0' Remote Buffer Overflow
CVE-2007-4903remotewindows
Multiple buffer overflows in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Component allo
23RISCO
abrir
Referência
CVE-2020-8644
CVE-2020-8644CRITICALsob ataque
PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.
100RISCO
abrir
Referência
CVE-2010-1179
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash)
23RISCO
abrir
Referência
CVE-2014-9000
Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows
23RISCO
abrir
Referência
CVE-2018-7653
In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter.
38RISCO
abrir
Referência
CVE-2018-7653
In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter.
38RISCO
abrir
Referência
CVE-2009-4991
Cross-site scripting (XSS) vulnerability in users/resume_register.php in Omnistar Recruiting allows remote attackers to
23RISCO
abrir
Referência
CVE-2015-7894
The DCMProvider service in Samsung LibQjpeg on a Samsung SM-G925V device running build number LRX22G.G925VVRU1AOE2 allow
23RISCO
abrir
Referência
CVE-2009-2533
rmserver in RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allows remote attackers to cause a denial of
23RISCO
abrir
Referência
CVE-2017-17058
The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/wooco
46RISCO
abrir
Referência
CVE-2017-17058
The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/wooco
46RISCO
abrir
Referência
CVE-2013-1599
A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firm
35RISCO
abrir
Referência
CVE-2017-4914
VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of th
23RISCO
abrir
Referência
CVE-2013-1599
A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firm
35RISCO
abrir
Referência
CVE-2016-5678
NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows re
23RISCO
abrir
Referência
CVE-2021-26828
CVE-2021-26828HIGHsob ataque
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and exe
83RISCO
abrir
Referência
CVE-2020-25494
Xinuos (formerly SCO) Openserver v5 and v6 allows attackers to execute arbitrary commands via shell metacharacters in ou
35RISCO
abrir
Referência
CVE-2012-6500
Directory traversal vulnerability in download.lib.php in Pragyan CMS 3.0 and earlier allows remote attackers to read arb
23RISCO
abrir
Referência
CVE-2009-5109
Stack-based buffer overflow in Mini-Stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long e
50RISCO
abrir
Referência
CVE-2004-2116
Directory traversal vulnerability in Tiny Server 1.1 allows remote attackers to read or download arbitrary files via a .
23RISCO
abrir
Referência
CVE-2009-5109
Stack-based buffer overflow in Mini-Stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long e
50RISCO
abrir
Referência
CVE-2009-2550
Stack-based buffer overflow in Hamster Audio Player 0.3a allows remote attackers to execute arbitrary code via a long st
23RISCO
abrir
anteriorpágina 586 / 753próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.