Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
20.003 exploits
Referência
CVE-2016-6602
ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependen
50RISCO
abrir
Referência
CVE-2006-3890
Stack-based buffer overflow in the Sky Software FileView ActiveX control, as used in WinZip 10 before build 7245 and in
28RISCO
abrir
Referência
CVE-2019-3025
Vulnerability in the Oracle Hospitality RES 3700 component of Oracle Food and Beverage Applications. The supported versi
28RISCO
abrir
Referência
CVE-2010-5323
Directory traversal vulnerability in UploadServlet in the Remote Management component in Novell ZENworks Configuration M
28RISCO
abrir
Referência
CVE-2015-2825
Unrestricted file upload vulnerability in sam-ajax-admin.php in the Simple Ads Manager plugin before 2.5.96 for WordPres
28RISCO
abrir
Referência
CVE-2015-2825
Unrestricted file upload vulnerability in sam-ajax-admin.php in the Simple Ads Manager plugin before 2.5.96 for WordPres
28RISCO
abrir
Referência
CVE-2011-2505
libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4
28RISCO
abrir
Referência
CVE-2011-0420
The grapheme_extract function in the Internationalization extension (Intl) for ICU for PHP 5.3.5 allows context-dependen
28RISCO
abrir
Referência
CVE-2007-2586
The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers
28RISCO
abrir
Referência
Apple CFNetwork - HTTP Response Denial of Service
The _CFNetConnectionWillEnqueueRequests function in CFNetwork 129.19 on Apple Mac OS X 10.4 through 10.4.10 allows remot
28RISCO
abrir
Referência
CVE-2025-34040
Seeyon Zhiyuan OA System Path Traversal File Upload
68RISCO
abrir
Referência
Zhiyuan OA - arbitrary file upload leading
Seeyon Zhiyuan OA System Path Traversal File Upload
68RISCO
abrir
Referência
CVE-2011-3496
service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary commands via shell me
28RISCO
abrir
Referência
CVE-2014-8722
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<user
28RISCO
abrir
Referência
CVE-2019-7193
CVE-2019-7193CRITICALsob ataqueransomware
This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the
83RISCO
abrir
Referência
CVE-2011-2443
Multiple buffer overflows in Adobe Photoshop Elements 8.0 and earlier allow remote attackers to cause a denial of servic
28RISCO
abrir
Referência
CVE-2016-0165
CVE-2016-0165HIGHsob ataque
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, W
76RISCO
abrir
Referência
Sahi Pro 8.0.0 - Remote Command Execution
_s_/sprm/_s_/dyn/Player_setScriptFile in Sahi Pro 8.0.0 allows command execution. It allows one to run ".sah" scripts vi
28RISCO
abrir
Referência
CVE-2017-2547
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
28RISCO
abrir
Referência
SHTTPD 1.34 - 'POST' Remote Buffer Overflow
Stack-based buffer overflow in Sergey Lyubka Simple HTTPD (shttpd) 1.34 allows remote attackers to execute arbitrary cod
50RISCO
abrir
Referência
CVE-2017-16944
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial
35RISCO
abrir
Referência
CVE-2024-11972
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
75RISCO
abrir
Referência
CVE-2018-11742
NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.
28RISCO
abrir
Referência
CVE-2018-11742
NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.
28RISCO
abrir
Referência
CVE-2010-1081
Directory traversal vulnerability in the Community Polls (com_communitypolls) component 1.5.2, and possibly earlier, for
43RISCO
abrir
Referência
CVE-2019-9648
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exis
28RISCO
abrir
Referência
Core FTP Server FTP / SFTP Server v2 Build 674 - 'SIZE' Directory Traversal
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exis
28RISCO
abrir
Referência
CVE-2021-45901
The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending
28RISCO
abrir
Referência
CVE-2019-15637
Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to informat
46RISCO
abrir
Referência
CVE-2010-2682
Directory traversal vulnerability in the Realtyna Translator (com_realtyna) component 1.0.15 for Joomla! allows remote a
43RISCO
abrir
anteriorpágina 128 / 667próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.