Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
20.003 exploits
Referência
CVE-2015-7039
Buffer overflow in libc in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows rem
28RISCO
abrir
Referência
CVE-2021-33990
Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The
53RISCO
abrir
Referência
EDraw Office Viewer Component - Denial of Service
Buffer overflow in a certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and
28RISCO
abrir
Referência
CVE-2011-1525
Heap-based buffer overflow in rvrender.dll in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.2, and R
28RISCO
abrir
Referência
CVE-2010-1597
Stack-based buffer overflow in zgtips.dll in ZipGenius 6.3.1.2552 allows user-assisted remote attackers to execute arbit
28RISCO
abrir
Referência
CVE-2014-9014
Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin b
28RISCO
abrir
Referência
CVE-2020-28687
The edit profile functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upl
28RISCO
abrir
Referência
CVE-2020-28688
The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to uplo
28RISCO
abrir
Referência
CVE-2013-5758
cgi-bin/cgiServer.exx in Yealink VoIP Phone SIP-T38G allows remote authenticated users to execute arbitrary commands by
28RISCO
abrir
Referência
CVE-2013-5758
cgi-bin/cgiServer.exx in Yealink VoIP Phone SIP-T38G allows remote authenticated users to execute arbitrary commands by
28RISCO
abrir
Referência
CVE-2013-5758
cgi-bin/cgiServer.exx in Yealink VoIP Phone SIP-T38G allows remote authenticated users to execute arbitrary commands by
28RISCO
abrir
Referência
CVE-2013-5758
cgi-bin/cgiServer.exx in Yealink VoIP Phone SIP-T38G allows remote authenticated users to execute arbitrary commands by
28RISCO
abrir
Referência
CVE-2017-17739
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has directory traversal via the /storage.html
28RISCO
abrir
Referência
CVE-2010-1981
Directory traversal vulnerability in the Fabrik (com_fabrik) component 2.0 for Joomla! allows remote attackers to read a
43RISCO
abrir
Referência
CVE-2010-1981
Directory traversal vulnerability in the Fabrik (com_fabrik) component 2.0 for Joomla! allows remote attackers to read a
43RISCO
abrir
Referência
CVE-2023-0159
Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCE
50RISCO
abrir
Referência
Backup Exec System Recovery Manager 7.0.1 - Arbitrary File Upload
Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, a
28RISCO
abrir
Referência
CVE-2013-10069
D-Link Devices Unauthenticated RCE
68RISCO
abrir
Referência
CVE-2013-10069
D-Link Devices Unauthenticated RCE
68RISCO
abrir
Referência
CVE-2013-10069
D-Link Devices Unauthenticated RCE
68RISCO
abrir
Referência
CVE-2020-3118
CVE-2020-3118HIGHsob ataque
Cisco IOS XR Software Cisco Discovery Protocol Format String Vulnerability
76RISCO
abrir
Referência
AspWebCalendar 2008 - Arbitrary File Upload
Unrestricted file upload vulnerability in calendar_admin.asp in Full Revolution aspWebCalendar 2008 allows remote attack
28RISCO
abrir
Referência
CVE-2015-6912
Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary shell commands via shell metacharact
28RISCO
abrir
Referência
Pixaria Gallery 1.x - 'class.Smarty.php' Remote File Inclusion
PHP remote file inclusion vulnerability in resources/includes/class.Smarty.php in Pixaria Gallery before 1.4.3 allows re
28RISCO
abrir
Referência
CVE-2019-17132
vBulletin through 5.5.4 mishandles custom avatars.
28RISCO
abrir
Referência
VideoLAN VLC Media Player 0.8.6e - Subtitle Parsing Local Buffer Overflow
Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle.c) in VLC 0.8.6e allows remote attackers to
28RISCO
abrir
Referência
EgyPlus 7ml 1.0.1 - Authentication Bypass
cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier sends a redirect to the web browser but does not exit whe
53RISCO
abrir
Referência
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to obtain login access via a request to hosting/a
28RISCO
abrir
Referência
WIMAX SWC-5100W Firmware V(1.11.0.1 :1.9.9.4) - Authenticated RCE
SeowonIntech SWC 5100W WIMAX Bootloader 1.18.19.0, HW 0.0.7.0, and FW 1.11.0.1, 1.9.9.4 are vulnerable to OS Command Inj
46RISCO
abrir
Referência
CVE-2018-8468
An elevation of privilege vulnerability exists when Windows, allowing a sandbox escape, aka "Windows Elevation of Privil
28RISCO
abrir
anteriorpágina 141 / 667próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.