Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
22.936 exploits
ReferênciaVexDay Proof
Ultimate WebBoard 3.00 - 'Category' SQL Injection
CVE-2008-4666webappsphp
SQL injection vulnerability in webboard.php in Ultimate Webboard 3.00 allows remote attackers to execute arbitrary SQL c
23RISCO
abrir
Referência
CVE-2013-0632
CVE-2013-0632CRITICALsob ataque
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and pos
100RISCO
abrir
ReferênciaVexDay Proof
Real Estate Manager 1.01 - 'cat_id' SQL Injection
CVE-2008-4674webappsphp
SQL injection vulnerability in realestate-index.php in Conkurent Real Estate Manager 1.01 allows remote attackers to exe
23RISCO
abrir
ReferênciaVexDay Proof
PHPcounter 1.3.2 - 'index.php' SQL Injection
CVE-2008-4675webappsphp
SQL injection vulnerability in index.php in PHPcounter 1.3.2 and earlier allows remote attackers to execute arbitrary SQ
23RISCO
abrir
ReferênciaVexDay Proof
Wireshark 1.0.x - '.ncf' Packet Capture Local Denial of Service
CVE-2008-4682dosmultiple
wtap.c in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application abort) via a
23RISCO
abrir
Referência
CVE-2010-1472
Directory traversal vulnerability in the Daily Horoscope (com_horoscope) component 1.5.0 for Joomla! allows remote attac
43RISCO
abrir
ReferênciaVexDay Proof
Kjtechforce mailman b1 - 'dest' Blind SQL Injection
CVE-2009-2164webappsphp
Multiple SQL injection vulnerabilities in Kjtechforce mailman beta1, when magic_quotes_gpc is disabled, allow remote att
23RISCO
abrir
Referência
CVE-2009-2308
Multiple SQL injection vulnerabilities in affiliates.php in the Affiliation (aka Affiliates) module 1.1.0 and earlier fo
23RISCO
abrir
Referência
CVE-2019-5825
CVE-2019-5825MEDIUMsob ataque
Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploi
90RISCO
abrir
Referência
CVE-2009-3334
SQL injection vulnerability in the Lhacky! Extensions Cave Joomla! Integrated Newsletters Component (aka JINC or com_jin
23RISCO
abrir
Referência
CVE-2017-8635
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Serve
35RISCO
abrir
ReferênciaVexDay Proof
Focus/SIS 1.0/2.2 - Remote File Inclusion
CVE-2007-4807webappsphp
Multiple PHP remote file inclusion vulnerabilities in Focus/SIS 2.2 allow remote attackers to execute arbitrary PHP code
23RISCO
abrir
Referência
CVE-2018-0935
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Se
35RISCO
abrir
Referência
CVE-2019-11708
CVE-2019-11708CRITICALsob ataque
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result
90RISCO
abrir
Referência
CVE-2019-7255
Linear eMerge E3-Series devices allow XSS.
50RISCO
abrir
ReferênciaVexDay Proof
Mantis Bug Tracker 1.1.3 - Remote Code Execution
CVE-2008-4687webappsphp
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort param
50RISCO
abrir
Referência
CVE-2019-8387
MASTER IPCAMERA01 3.3.4.2103 devices allow Remote Command Execution, related to the thttpd component.
35RISCO
abrir
Referência
CVE-2022-21882
CVE-2022-21882HIGHsob ataqueransomware
Win32k Elevation of Privilege Vulnerability
98RISCO
abrir
Referência
CVE-2014-7236
Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary
50RISCO
abrir
Referência
CVE-2014-4114
CVE-2014-4114HIGHsob ataque
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISCO
abrir
Referência
CVE-2018-17440
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves b
35RISCO
abrir
Referência
CVE-2017-13872
An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The is
50RISCO
abrir
Referência
CVE-2017-13872
An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The is
50RISCO
abrir
Referência
CVE-2015-3042
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457
35RISCO
abrir
Referência
CVE-2017-9798
Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user
60RISCO
abrir
ReferênciaVexDay Proof
Opera 9.60 - Persistent Cross-Site Scripting
CVE-2008-4696remotewindows
Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before 9.61 allows remote attackers to inject arbitrary w
50RISCO
abrir
ReferênciaVexDay Proof
Xitami Web Server 2.5c2 - LRWP Processing Format String (PoC)
CVE-2008-6519doswindows
Format string vulnerability in Xitami Web Server 2.2a through 2.5c2, and possibly other versions, allows remote attacker
23RISCO
abrir
Referência
CVE-2009-3343
SQL injection vulnerability in details.asp in HotWeb Rentals allows remote attackers to execute arbitrary SQL commands v
23RISCO
abrir
ReferênciaVexDay Proof
Peachtree Accounting 2004 - 'PAWWeb11.ocx' ActiveX Insecure Method
CVE-2008-4699remotewindows
Insecure method vulnerability in the ActiveX control (PAWWeb11.ocx) in Peachtree Accounting 2004 allows remote attackers
28RISCO
abrir
ReferênciaVexDay Proof
Vbgooglemap Hotspot Edition 1.0.3 - SQL Injection
CVE-2008-4706webappsphp
SQL injection vulnerability in VBGooglemap Hotspot Edition 1.0.3, a vBulletin module, allows remote attackers to execute
23RISCO
abrir
anteriorpágina 67 / 765próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.