Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
22.573 exploits
Referência
CVE-2009-2477
js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1
50RISCO
abrir
ReferênciaVexDay Proof
Joomla! / Mambo Component SWmenu 4.0 - Remote File Inclusion
CVE-2007-1699webappsphp
Multiple PHP remote file inclusion vulnerabilities in the SWmenu (com_swmenupro and com_swmenufree) 4.0 component for Ma
28RISCO
abrir
ReferênciaVexDay Proof
Fastpublish CMS 1.9999 - config[fsBase] Remote File Inclusion
CVE-2007-6325webappsphp
PHP remote file inclusion vulnerability in adminbereich/designconfig.php in Fastpublish CMS 1.9999 allows remote attacke
28RISCO
abrir
ReferênciaVexDay Proof
jetAudio 7.0.5 - '.asx' Remote Stack Overflow (PoC)
CVE-2008-0747doswindows
Stack-based buffer overflow in COWON America jetAudio 7.0.5 and earlier allows user-assisted remote attackers to execute
23RISCO
abrir
Referência
CVE-2017-2536
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
28RISCO
abrir
Referência
CVE-2017-9811
The kluser is able to interact with the kav4fs-control binary in Kaspersky Anti-Virus for Linux File Server before Maint
28RISCO
abrir
Referência
CVE-2017-9811
The kluser is able to interact with the kav4fs-control binary in Kaspersky Anti-Virus for Linux File Server before Maint
28RISCO
abrir
Referência
CVE-2009-4827
Cross-site request forgery (CSRF) vulnerability in admin.php in Mail Manager Pro allows remote attackers to hijack the a
23RISCO
abrir
Referência
CVE-2019-7272
Optergy Proton/Enterprise devices allow Username Disclosure.
28RISCO
abrir
Referência
CVE-2023-37569
OS Command Injection Vulnerability in Emagic Data Center Management Suite
53RISCO
abrir
Referência
CVE-2018-20221
Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserializ
28RISCO
abrir
Referência
CVE-2018-20221
Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserializ
28RISCO
abrir
Referência
CVE-2014-5081
sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass
28RISCO
abrir
Referência
CVE-2020-36911
Covenant 0.5 - Remote Code Execution (RCE)
53RISCO
abrir
Referência
CVE-2020-36911
Covenant 0.5 - Remote Code Execution (RCE)
53RISCO
abrir
Referência
CVE-2020-36911
Covenant 0.5 - Remote Code Execution (RCE)
53RISCO
abrir
Referência
CVE-2013-1596
An Authentication Bypass Vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via specially crafted RTSP pac
28RISCO
abrir
Referência
CVE-2022-29593
relay_cgi.cgi on Dingtian DT-R002 2CH relay devices with firmware 3.1.276A allows an attacker to replay HTTP post reques
38RISCO
abrir
ReferênciaVexDay Proof
docpile:we 0.2.2 - 'INIT_PATH' Remote File Inclusion
CVE-2006-4075webappsphp
Multiple PHP remote file inclusion vulnerabilities in Wim Fleischhauer docpile: wim's edition (docpile:we) 0.2.2 and ear
28RISCO
abrir
ReferênciaVexDay Proof
GdPicture Pro - ActiveX 'gdpicture4s.ocx' File Overwrite / Exec
CVE-2008-4453remotewindows
The GdPicture (1) Light Imaging Toolkit 4.7.1 GdPicture4S.Imaging ActiveX control (gdpicture4s.ocx) 4.7.0.1 and (2) Pro
28RISCO
abrir
ReferênciaVexDay Proof
Mozilla Firefox XSL - Parsing Remote Memory Corruption (PoC) (1)
CVE-2009-1169dosmultiple
The txMozillaXSLTProcessor::TransformToDoc function in Mozilla Firefox before 3.0.8 and SeaMonkey before 1.1.16 allows r
28RISCO
abrir
ReferênciaVexDay Proof
Pagode 0.5.8 - 'navigator_ok.php?asolute' Remote File Disclosure
CVE-2007-2200webappsphp
Directory traversal vulnerability in navigator/navigator_ok.php in Pagode 0.5.8 allows remote attackers to read and poss
28RISCO
abrir
Referência
CVE-2009-2479
Mozilla Firefox 3.0.x, 3.5, and 3.5.1 on Windows allows remote attackers to cause a denial of service (uncaught exceptio
28RISCO
abrir
ReferênciaVexDay Proof
Sun jre1.6.0_X - isInstalled.dnsResolve Function Overflow
CVE-2007-5019dosmultiple
Buffer overflow in the Sun Java Web Start ActiveX control in Java Runtime Environment (JRE) 1.6.0_X allows remote attack
28RISCO
abrir
ReferênciaVexDay Proof
Linux Kernel 2.6.21.1 - IPv6 Jumbo Bug Remote Denial of Service
CVE-2008-0352doslinux
The Linux kernel 2.6.20 through 2.6.21.1 allows remote attackers to cause a denial of service (panic) via a certain IPv6
28RISCO
abrir
ReferênciaVexDay Proof
sflog! 0.96 - Remote File Disclosure
CVE-2008-0703webappsphp
Multiple directory traversal vulnerabilities in sflog! 0.96 allow remote attackers to read arbitrary files via a .. (dot
23RISCO
abrir
Referência
CVE-2018-9118
exports/download.php in the 99 Robots WP Background Takeover Advertisements plugin before 4.1.5 for WordPress has Direct
50RISCO
abrir
Referência
CVE-2009-4828
Cross-site request forgery (CSRF) vulnerability in administration/admins.php in Ad Manager Pro (aka AdManagerPro) 3.0 al
23RISCO
abrir
Referência
CVE-2017-11855
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Window
35RISCO
abrir
Referência
CVE-2013-0232
includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitra
50RISCO
abrir
anteriorpágina 60 / 753próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.