Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.137exploits catalogados
35.961CVEs com exploração pública
24.695testados em laboratório
22.657 exploits
Referência
CVE-2018-0832
The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Window
23RISCO
abrir
ReferênciaVexDay Proof
PHP Photo Gallery 1.0 - 'photo_id' SQL Injection
CVE-2008-1711webappsphp
Terong PHP Photo Gallery (aka Advanced Web Photo Gallery) 1.0 stores passwords in cleartext in a MySQL database, which a
23RISCO
abrir
Referência
CVE-2018-0894
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Serve
23RISCO
abrir
Referência
CVE-2018-11442
A CSRF issue was discovered in EasyService Billing 1.0, which was triggered via a quotation-new3-new2.php?add=true&id= U
23RISCO
abrir
Referência
CVE-2020-15149
Account takeover in NodeBB
48RISCO
abrir
Referência
CVE-2012-2437
cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to ge
23RISCO
abrir
Referência
CVE-2019-1170
Windows NTFS Elevation of Privilege Vulnerability
41RISCO
abrir
Referência
CVE-2013-0803
A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arb
60RISCO
abrir
Referência
CVE-2010-1740
SQL injection vulnerability in newsletter.php in GuppY 4.5.18 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Referência
CVE-2010-1740
SQL injection vulnerability in newsletter.php in GuppY 4.5.18 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Referência
CVE-2017-14618
Cross-site scripting (XSS) vulnerability in inc/PMF/Faq.php in phpMyFAQ through 2.9.8 allows remote attackers to inject
23RISCO
abrir
ReferênciaVexDay Proof
Cartweaver 3 - 'prodId' Blind SQL Injection
CVE-2008-2918webappsphp
SQL injection vulnerability in details.php in Application Dynamics Cartweaver 3.0 allows remote attackers to execute arb
23RISCO
abrir
Referência
CVE-2019-0555
An elevation of privilege vulnerability exists in the Microsoft XmlDocument class that could allow an attacker to escape
23RISCO
abrir
ReferênciaVexDay Proof
WebAlbum 2.02pl - COOKIE[skin2] Remote Code Execution
CVE-2006-1480webappsphp
Directory traversal vulnerability in start.php in WebAlbum 2.02 allows remote attackers to include arbitrary files and e
23RISCO
abrir
ReferênciaVexDay Proof
PHP Ticket 0.71 - 'search.php' SQL Injection
CVE-2006-1481webappsphp
SQL injection vulnerability in search.php in PHP Ticket 0.71 allows remote authenticated users to execute arbitrary SQL
23RISCO
abrir
Referência
CVE-2013-0803
A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arb
60RISCO
abrir
ReferênciaVexDay Proof
iWare Pro 5.0.4 - 'chat_panel.php' Remote Code Execution
CVE-2006-5837webappsphp
Static code injection vulnerability in chat_panel.php in the SimpleChat 1.0.0 module for iWare Professional CMS allows r
23RISCO
abrir
ReferênciaVexDay Proof
TorrentFlux 2.2 - 'downloaddetails.php' Local File Disclosure
CVE-2006-6598webappsphp
Directory traversal vulnerability in viewnfo.php in (1) TorrentFlux before 2.2 and (2) torrentflux-b4rt before 2.1-b4rt-
23RISCO
abrir
ReferênciaVexDay Proof
NewsCMSLite - 'newsCMS.mdb' Remote Password Disclosure
CVE-2007-0091webappsasp
newsCMSlite stores sensitive information under the web root with insufficient access control, which allows remote attack
23RISCO
abrir
ReferênciaVexDay Proof
Pakupaku CMS 0.4 - Arbitrary File Upload / Local File Inclusion
CVE-2007-4640webappsphp
Unrestricted file upload vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to upload an
23RISCO
abrir
Referência
CVE-2010-2860
The EMC Celerra Network Attached Storage (NAS) appliance accepts external network traffic to IP addresses intended for a
23RISCO
abrir
Referência
CVE-2015-4137
SQL injection vulnerability in related.php in Milw0rm Clone Script 1.0 allows remote attackers to execute arbitrary SQL
23RISCO
abrir
Referência
CVE-2015-4137
SQL injection vulnerability in related.php in Milw0rm Clone Script 1.0 allows remote attackers to execute arbitrary SQL
23RISCO
abrir
Referência
CVE-2012-1027
Cross-site scripting (XSS) vulnerability in account-closed.tcl in ]project-open[ (aka ]po[) 3.4.x, 3.5.0.1-2, and possib
23RISCO
abrir
Referência
CVE-2018-1204
Dell EMC Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, an
23RISCO
abrir
ReferênciaVexDay Proof
Apache Tomcat < 6.0.18 - 'utf8' Directory Traversal (PoC)
CVE-2008-2938remotemultiple
Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16,
60RISCO
abrir
Referência
CVE-2015-1400
SQL injection vulnerability in search.php in NPDS Revolution 13 allows remote attackers to execute arbitrary SQL command
23RISCO
abrir
ReferênciaVexDay Proof
Cahier de texte 2.2 - Bypass General Access Protection
CVE-2006-6849webappsphp
administration/index.php in Cahier de texte (CDT) 2.2 does not properly exit when authentication fails, which allows rem
23RISCO
abrir
ReferênciaVexDay Proof
Shop-Script FREE 2.0 - Remote Command Execution
CVE-2007-4933webappsphp
Direct static code injection vulnerability in includes/admin/sub/conf_appearence.php in Shop-Script FREE 2.0 and earlier
23RISCO
abrir
ReferênciaVexDay Proof
iziContents rc6 - Local/Remote File Inclusion
CVE-2007-5055webappsphp
Multiple directory traversal vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to include and exec
23RISCO
abrir
anteriorpágina 630 / 756próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.