Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
22.936 exploits
Referência
CVE-2018-3639
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addres
45RISCO
abrir
Referência
CVE-2018-8770
Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via generate.php, controllers/getConfigTest.php, contro
50RISCO
abrir
ReferênciaVexDay Proof
TorrentTrader Classic 1.04 - Blind SQL Injection
CVE-2008-4494webappsphp
SQL injection vulnerability in completed-advance.php in TorrentTrader Classic 1.08 and 1.04 and earlier allows remote at
23RISCO
abrir
Referência
CVE-2012-4333
Multiple stack-based buffer overflows in the BackupToAvi method in the (1) UMS_Ctrl 1.5.1.1 and (2) UMS_Ctrl_STW 2.0.1.0
50RISCO
abrir
Referência
CVE-2016-20017
CVE-2016-20017CRITICALsob ataque
D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as
100RISCO
abrir
Referência
CVE-2017-5941
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RISCO
abrir
Referência
CVE-2017-5941
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RISCO
abrir
ReferênciaVexDay Proof
Built2Go PHP Realestate 1.5 - 'event_detail.php' SQL Injection
CVE-2008-4497webappsphp
SQL injection vulnerability in event_detail.php in Built2Go Real Estate Listings 1.5 allows remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
Konqueror 3.5.9 - 'font color' Remote Crash
CVE-2008-4514doslinux
The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via a fo
23RISCO
abrir
Referência
CVE-2025-40553
SolarWinds Web Help Desk Deserialization of Untrusted Data Remote Code Execution Vulnerability
60RISCO
abrir
Referência
CVE-2017-15222
Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.
50RISCO
abrir
Referência
CVE-2017-15222
Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.
50RISCO
abrir
Referência
CVE-2016-3074
Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of
35RISCO
abrir
Referência
CVE-2008-4525
SQL injection vulnerability in index.php in AmpJuke 0.7.5 allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
Referência
CVE-2014-8657
The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH allows r
23RISCO
abrir
ReferênciaVexDay Proof
SOTEeSKLEP 3.5RC9 - 'file' Remote File Disclosure
CVE-2007-4369webappsphp
Directory traversal vulnerability in go/_files in SOTEeSKLEP before 4.0 allows remote attackers to read arbitrary files
23RISCO
abrir
ReferênciaVexDay Proof
Ol BookMarks Manager 0.7.5 - Local File Inclusion / Remote File Inclusion / SQL Injection
CVE-2008-6409webappsphp
SQL injection vulnerability in index.php in ol'bookmarks manager 0.7.5 allows remote attackers to execute arbitrary SQL
23RISCO
abrir
ReferênciaVexDay Proof
CoolPlayer Portable 2.19.1 - '.m3u' Local Buffer Overflow (2)
CVE-2009-1437localwindows
Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.6 and earlier allows rem
28RISCO
abrir
Referência
CVE-2019-17662
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RISCO
abrir
ReferênciaVexDay Proof
PHP-Fusion Mod recept - 'kat_id' SQL Injection
CVE-2008-4527webappsphp
SQL injection vulnerability in recept.php in the Recepies (Recept) module 1.1 for PHP-Fusion allows remote attackers to
23RISCO
abrir
Referência
CVE-2020-3250
Multiple Vulnerabilities in Cisco UCS Director and Cisco UCS Director Express for Big Data
75RISCO
abrir
Referência
CVE-2011-0257
Integer signedness error in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a deni
50RISCO
abrir
Referência
CVE-2014-10021
Unrestricted file upload vulnerability in UploadHandler.php in the WP Symposium plugin 14.11 for WordPress allows remote
50RISCO
abrir
ReferênciaVexDay Proof
pPIM 1.01 - 'notes.php' Local File Inclusion
CVE-2008-4528webappsphp
Directory traversal vulnerability in notes.php in Phlatline's Personal Information Manager (pPIM) 1.01 allows remote att
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component prayercenter 1.4.9 - 'id' SQL Injection
CVE-2008-6429webappsphp
SQL injection vulnerability in the PrayerCenter (com_prayercenter) component 1.4.9 and earlier for Joomla! allows remote
23RISCO
abrir
Referência
CVE-2019-5485
NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be inje
35RISCO
abrir
Referência
CVE-2017-11841
ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, versio
35RISCO
abrir
Referência
CVE-2017-11870
ChakraCore and Microsoft Edge in Windows 10 1703, 1709, and Windows Server, version 1709 allows an attacker to gain the
35RISCO
abrir
Referência
CVE-2016-3074
Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of
35RISCO
abrir
ReferênciaVexDay Proof
Elkagroup Image Gallery 1.0 - Arbitrary File Upload
CVE-2009-1446webappsphp
Unrestricted file upload vulnerability in upload.php in Elkagroup Image Gallery 1.0 allows remote authenticated users to
23RISCO
abrir
anteriorpágina 62 / 765próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.