Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
22.936 exploits
Referência
CVE-2019-12347
In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description fiel
35RISCO
abrir
Referência
CVE-2018-0780
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtai
35RISCO
abrir
Referência
CVE-2014-7187
Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers t
35RISCO
abrir
Referência
CVE-2014-7187
Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers t
35RISCO
abrir
ReferênciaVexDay Proof
PHPWebGallery 1.3.4 - Cross-Site Scripting / Local File Inclusion
CVE-2008-4591webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in admin/include/isadmin.inc.php in PhpWebGallery 1.3.4 allow remote
23RISCO
abrir
Referência
CVE-2018-6605
SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, get
50RISCO
abrir
Referência
CVE-2015-7243
Buffer overflow in Boxoft WAV to MP3 Converter allows remote attackers to cause a denial of service (crash) and possibly
50RISCO
abrir
ReferênciaVexDay Proof
Sports Clubs Web Panel 0.0.1 - 'p' Local File Inclusion
CVE-2008-4592webappsphp
Directory traversal vulnerability in index.php in Sports Clubs Web Panel 0.0.1 allows remote attackers to include and ex
23RISCO
abrir
ReferênciaVexDay Proof
EasyMail - ActiveX 'emmailstore.dll 6.5.0.3' Remote Buffer Overflow
CVE-2008-6447remotewindows
Buffer overflow in emmailstore.dll 6.5.0.3 in the QuikSoft EasyMail MailStore ActiveX control allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
IBM Domino Web Access 7.0 Upload Module - 'inotes6.dll' Remote Buffer Overflow
CVE-2007-4474remotewindows
Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, in
50RISCO
abrir
Referência
CVE-2015-7243
Buffer overflow in Boxoft WAV to MP3 Converter allows remote attackers to cause a denial of service (crash) and possibly
50RISCO
abrir
Referência
CVE-2015-7243
Buffer overflow in Boxoft WAV to MP3 Converter allows remote attackers to cause a denial of service (crash) and possibly
50RISCO
abrir
Referência
CVE-2015-7243
Buffer overflow in Boxoft WAV to MP3 Converter allows remote attackers to cause a denial of service (crash) and possibly
50RISCO
abrir
Referência
CVE-2019-6111
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses wh
45RISCO
abrir
Referência
CVE-2009-2485
Stack-based buffer overflow in HT-MP3Player 1.0 allows remote attackers to execute arbitrary code via a long string in a
50RISCO
abrir
Referência
CVE-2017-8618
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server
35RISCO
abrir
Referência
CVE-2012-4177
The web browser plugin for Ubisoft Uplay PC before 2.0.4 allows remote attackers to execute arbitrary programs via the -
50RISCO
abrir
Referência
CVE-2025-2746
CVE-2025-2746CRITICALsob ataque
Kentico Xperience <= 13.0.172 Staging Sync Server Digest Password Authentication Bypass
100RISCO
abrir
Referência
CVE-2025-2746
CVE-2025-2746CRITICALsob ataque
Kentico Xperience <= 13.0.172 Staging Sync Server Digest Password Authentication Bypass
100RISCO
abrir
ReferênciaVexDay Proof
IBM Domino Web Access Upload Module - Overwrite (SEH)
CVE-2007-4474remotewindows
Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, in
50RISCO
abrir
ReferênciaVexDay Proof
iGaming CMS 2.0 Alpha 1 - 'search.php' SQL Injection
CVE-2008-4603webappsphp
SQL injection vulnerability in search.php in iGaming CMS 2.0 Alpha 1 allows remote attackers to execute arbitrary SQL co
23RISCO
abrir
Referência
CVE-2022-30075
In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote
35RISCO
abrir
ReferênciaVexDay Proof
CafeEngine - Multiple SQL Injections
CVE-2008-4605webappsphp
SQL injection vulnerability in CafeEngine allows remote attackers to execute arbitrary SQL commands via the id parameter
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component EventList 0.8 - 'did' SQL Injection
CVE-2007-4509webappsphp
SQL injection vulnerability in index.php in the EventList component (com_eventlist) 0.8 and earlier for Joomla! allows r
23RISCO
abrir
ReferênciaVexDay Proof
HP Virtual Rooms WebHPVCInstall Control - Remote Buffer Overflow
CVE-2008-0437remotewindows
Multiple buffer overflows in the WebHPVCInstall.HPVirtualRooms14 ActiveX control in HPVirtualRooms14.dll 1.0.0.100, as u
35RISCO
abrir
ReferênciaVexDay Proof
Diesel Job Site - 'job_id' Blind SQL Injection
CVE-2008-6467webappsphp
SQL injection vulnerability in jobs/jobseekers/job-info.php in Diesel Job Site allows remote attackers to execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
fungamez rc1 - Authentication Bypass / Local File Inclusion
CVE-2009-1487webappsphp
SQL injection vulnerability in pages/login.php in FunGamez RC1 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component com_iJoomla_rss - Blind SQL Injection
CVE-2009-2099webappsphp
SQL injection vulnerability in the iJoomla RSS Feeder (com_ijoomla_rss) component for Joomla! allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
PortalApp 4.0 - SQL Injection / Cross-Site Scripting / Authentication Bypass
CVE-2008-4614webappsasp
PortalApp 4.0 does not require authentication for (1) forums.asp and (2) content.asp, which allows remote attackers to c
23RISCO
abrir
ReferênciaVexDay Proof
phpFastNews 1.0.0 - Insecure Cookie Handling
CVE-2008-4622webappsphp
The isLoggedIn function in fastnews-code.php in phpFastNews 1.0.0 allows remote attackers to bypass authentication and g
23RISCO
abrir
anteriorpágina 64 / 765próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.