Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.900exploits catalogados
35.840CVEs com exploração pública
24.695testados em laboratório
22.600 exploits
Referência
CVE-2019-15943
vphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or de
23RISCO
abrir
Referência
CVE-2014-8826
LaunchServices in Apple OS X before 10.10.2 does not properly handle file-type metadata, which allows attackers to bypas
23RISCO
abrir
Referência
CVE-2018-7736
In Z-BlogPHP 1.5.1.1740, cmd.php has XSS via the ZC_BLOG_SUBNAME parameter or ZC_UPLOAD_FILETYPE parameter. NOTE: the so
23RISCO
abrir
Referência
CVE-2018-7736
In Z-BlogPHP 1.5.1.1740, cmd.php has XSS via the ZC_BLOG_SUBNAME parameter or ZC_UPLOAD_FILETYPE parameter. NOTE: the so
23RISCO
abrir
Referência
CVE-2012-1614
Coppermine Photo Gallery before 1.5.20 allows remote attackers to obtain sensitive information via (1) a direct request
23RISCO
abrir
Referência
CVE-2012-1614
Coppermine Photo Gallery before 1.5.20 allows remote attackers to obtain sensitive information via (1) a direct request
23RISCO
abrir
Referência
CVE-2017-17055
Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site
23RISCO
abrir
Referência
CVE-2017-17055
Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site
23RISCO
abrir
Referência
CVE-2018-25120
D-Link DNS-343 ShareCenter <= 1.05 Command Injection via /goform/Mail_Test
48RISCO
abrir
Referência
CVE-2018-25120
D-Link DNS-343 ShareCenter <= 1.05 Command Injection via /goform/Mail_Test
48RISCO
abrir
Referência
CVE-2009-3148
Multiple SQL injection vulnerabilities in PortalXP Teacher Edition 1.2 allow remote attackers to execute arbitrary SQL c
23RISCO
abrir
Referência
CVE-2018-25120
D-Link DNS-343 ShareCenter <= 1.05 Command Injection via /goform/Mail_Test
48RISCO
abrir
Referência
CVE-2011-2757
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remot
50RISCO
abrir
ReferênciaVexDay Proof
Axigen 2.0.0b1 - Remote Denial of Service (1)
CVE-2007-0886doslinux
Heap-based buffer underflow in axigen 1.2.6 through 2.0.0b1 allows remote attackers to cause a denial of service (applic
23RISCO
abrir
Referência
CVE-2009-5109
Stack-based buffer overflow in Mini-Stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long e
50RISCO
abrir
Referência
CVE-2013-7409
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RISCO
abrir
Referência
CVE-2013-7409
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RISCO
abrir
ReferênciaVexDay Proof
AGTC MyShop 3.2 - Insecure Cookie Handling
CVE-2009-1549webappsphp
AGTC MyShop 3.2b allows remote attackers to bypass authentication and obtain administrative access setting the log_accep
23RISCO
abrir
Referência
CVE-2007-2482
Directory traversal vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, when reg
23RISCO
abrir
Referência
CVE-2019-9650
An XSS issue was discovered in upcoming_events.php in the Upcoming Events plugin before 1.33 for MyBB via a crafted name
23RISCO
abrir
Referência
CVE-2019-9650
An XSS issue was discovered in upcoming_events.php in the Upcoming Events plugin before 1.33 for MyBB via a crafted name
23RISCO
abrir
ReferênciaVexDay Proof
asg-sentry 7.0.0 - Multiple Vulnerabilities
CVE-2008-1322dosmultiple
The File Check Utility (fcheck.exe) in ASG-Sentry Network Manager 7.0.0 and earlier allows remote attackers to cause a d
23RISCO
abrir
Referência
CVE-2009-3196
Cross-site scripting (XSS) vulnerability in index.php in JCE-Tech PHP Video Script allows remote attackers to inject arb
23RISCO
abrir
Referência
CVE-2016-3963
Siemens SCALANCE S613 allows remote attackers to cause a denial of service (web-server outage) via traffic to TCP port 4
23RISCO
abrir
Referência
CVE-2016-6896
Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPre
35RISCO
abrir
Referência
CVE-2010-4617
Directory traversal vulnerability in the JotLoader (com_jotloader) component 2.2.1 for Joomla! allows remote attackers t
38RISCO
abrir
Referência
CVE-2016-10034
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.
35RISCO
abrir
Referência
CVE-2010-4617
Directory traversal vulnerability in the JotLoader (com_jotloader) component 2.2.1 for Joomla! allows remote attackers t
38RISCO
abrir
ReferênciaVexDay Proof
V-Webmail 1.6.4 - 'pear_dir' Remote File Inclusion
CVE-2006-2665webappsphp
PHP remote file inclusion vulnerability in includes/mailaccess/pop3/core.php in V-Webmail 1.3 allows remote attackers to
23RISCO
abrir
Referência
CVE-2019-3999
Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, u
38RISCO
abrir
anteriorpágina 605 / 754próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.